Which role is required to manage groups and policies in Falcon?
Correct Answer: B
Explanation The Falcon Host Administrator role is required to manage groups and policies in Falcon. This role allows users to create, edit and delete groups and policies, as well as assign them to hosts. The other roles do not have this capability. Reference: [CrowdStrike Falcon User Guide], page 17.
Question 3
What are custom alerts based on?
Correct Answer: A
Question 4
Once an exclusion is saved, what can be edited in the future?
Correct Answer: B
Question 5
Which statement is TRUE regarding disabling detections on a host?
Correct Answer: B
Explanation The statement that is true regarding disabling detections on a host is that hosts with detections disabled will not alert on anything until detections are enabled again. As explained in question 127, disabling detections for a host will stop the sensor from sending any detection or prevention events to the Falcon console, and remove any existing events for that host from the console. This means that the host will not alert on anything, including blocklisted hashes, machine learning detections, or indicator of attack (IOA)-based detections. The host will remain in this state until detections are enabled again1. References: 1: Falcon Administrator Learning Path | Infographic | CrowdStrike