A financial institution is deploying the Falcon sensor to a fleet of Linux servers running a mix of CentOS 7 and Rocky Linux 9. The deployment script fails on the Rocky Linux 9 servers with an error indicating an unsupported kernel. The CentOS 7 servers install successfully. What is the most likely cause of this issue?
Answer and explanation
Correct answer: B
CrowdStrike regularly updates the Falcon sensor to support new operating system versions and kernels. A common cause for installation failure on a newer OS version, when it succeeds on an older one, is that the installer package being used does not yet support the newer kernel. The administrator should download the latest sensor version from the Falcon UI and use it for the Rocky Linux 9 deployment.
Question 2
An administrator is designing a host group structure for a large enterprise with distinct business units (e.g., Finance, Engineering, Marketing) and environments (e.g., Production, Staging, Development). The goal is to apply tailored prevention policies based on both business unit and environment. Which host grouping strategy is most effective and scalable?
Answer and explanation
Correct answer: C
Dynamic host groups are the most scalable and manageable solution. By leveraging criteria like Active Directory Organizational Units (OUs), hostname prefixes/suffixes, or sensor tags, hosts can be automatically placed into the correct group upon installation. This ensures the correct policies are applied immediately without manual intervention, reducing administrative overhead and the risk of misconfiguration.
Question 3
Multiple answers
A security analyst needs to create a custom IOA rule to detect a specific LOLBAS (Living Off the Land Binary and Script) technique where PowerShell is used to download a file from a remote server and then execute it. The rule should only trigger if the command line contains both 'DownloadString' and 'IEX' (Invoke-Expression). Which TWO of the following regular expressions would be most effective when used in the Command Line field of the custom IOA rule? (Select TWO)
Answer and explanation
Correct answers: A, B
To ensure the rule triggers regardless of the order in which 'DownloadString' and 'IEX' appear in the command line, two separate regex patterns are needed. '.*DownloadString.IEX.' matches cases where 'DownloadString' appears first, and '.*IEX.DownloadString.' matches cases where 'IEX' appears first. Using both covers the necessary permutations for this detection logic.
Question 4
A global retail company wants to automate its initial response to high-severity ransomware detections. The Security Operations Center (SOC) team has defined a specific workflow they want to implement using Falcon Fusion.
The desired workflow is as follows: When a high-severity detection with a tactic of 'Ransomware' occurs, the system should immediately contain the affected host to prevent lateral movement. Simultaneously, a high-priority ticket should be created in their Jira instance with details of the detection, and a notification should be sent to the #soc-alerts Slack channel. The workflow should only apply to hosts in the 'Production Servers' group.
Which sequence of components in a Falcon Fusion workflow would correctly implement this requirement?
Answer and explanation
Correct answer: A
This option correctly defines the workflow. The trigger is a new detection. The condition correctly filters for only the specified detections (High severity, Ransomware tactic, in the 'Production Servers' group). The actions (Contain, Jira, Slack) are the required response steps. This structure ensures the automation is precise and executes all required steps.
Question 5
True or False: To uninstall the Falcon sensor from a Windows host via the command line when uninstall protection is enabled, an administrator must first retrieve a unique, time-sensitive maintenance token from the Falcon UI and use it as a parameter in the uninstall command.
Answer and explanation
Correct answer: A
This statement is true. When uninstall protection is enabled in the Sensor Update Policy, a maintenance token is required to perform administrative actions like uninstalling or manually upgrading the sensor. This token must be generated from the Host Management page for the specific host and is required to prevent unauthorized removal of the sensor.
Question 6
An administrator is managing a large number of custom IOCs. To improve performance and reduce clutter, they decide to set an expiration date for IOCs related to a specific, now-remediated campaign. What happens when a custom IOC reaches its expiration date?
Answer and explanation
Correct answer: A
When an IOC's expiration date is reached, it is automatically disabled, meaning it will no longer generate detections on endpoints. However, it is not immediately deleted. The IOC remains in the system in a disabled state for a retention period (typically 90 days), after which it is permanently removed. This allows for auditing and potential re-activation if needed.
Question 7
A new Falcon administrator is reviewing the available audit logs to understand user activity within the console. Which audit log should they consult to find a record of users who have used Real-Time Response (RTR) to connect to a host and the specific commands they executed during their session?
Answer and explanation
Correct answer: C
The Real-Time Response Audit Log is specifically designed to capture all RTR activity. It provides a detailed record of which user initiated a session on which host, the start and end times of the session, and a full list of all commands that were executed, including both the input commands and their output.
Question 8
A company's policy requires that all Falcon sensor updates are first tested on a pilot group of non-critical systems for one week before being promoted to production. The production systems should remain on the currently approved version during this testing period. How can an administrator configure Sensor Update Policies to enforce this?
Answer and explanation
Correct answer: B
This approach provides the most control and meets the requirements. The pilot group policy set to 'Latest Version' or 'N-1' will automatically receive new updates for testing. The production group policy is locked to a specific, validated version, preventing unintended updates. After the one-week test, the administrator can update the production policy to the new version, ensuring a controlled, staged rollout.
Question 9
A developer at a software company frequently compiles a custom, in-house application named 'DataCruncher.exe'. Each compilation results in a new file hash, causing repeated Machine Learning (ML) detections and quarantines, which disrupts their workflow. The application is always located in 'D:\dev_builds'. What is the most precise and secure method to create an ML exclusion for this scenario?
Answer and explanation
Correct answer: B
Excluding the specific file path is the most precise method. It allows only 'DataCruncher.exe' within that directory to be excluded, while any other potentially malicious file dropped into 'D:\dev_builds' would still be inspected by Falcon. Excluding the entire directory ('D:\dev_builds*') would create a security blind spot. Using a hash is not viable as it changes with each compilation.
Question 10
What is the primary purpose of assigning a Customer ID (CID) during the Falcon sensor installation?
Answer and explanation
Correct answer: B
The Customer ID (CID) is a unique identifier that associates the installed sensor with a specific customer's environment (tenant) in the CrowdStrike cloud. This ensures that the host checks in correctly, sends its data to the right location, and receives the appropriate policies and configurations from the correct Falcon console.