10 free sample questions from a bank of 279, with the correct answers and explanations. No signup required — start practising right now.
1What is the function of a single asterisk (*) in an ML exclusion pattern?
The single asterisk will match any number of characters, including none. It does include separator characters, such as \ or /, which separate portions of a file path
The single asterisk will match any number of characters, including none. It does not include separator characters, such as \ or /, which separate portions of a file path
The single asterisk is the insertion point for the variable list that follows the path
The single asterisk is only used to start an expression, and it represents the drive letter
Answer: B
2One of your development teams is working on code for a new enterprise application but Falcon continually flags the execution as a detection during testing. All development work is required to be stored on a file share in a folder called "devcode." What setting can you use to reduce false positives on this file path?
USB Device Policy
Firewall Rule Group
Containment Policy
Machine Learning Exclusions
Answer: D
3When a host belongs to more than one host group, how is sensor update precedence determined?
Groups have no impact on sensor update policies
Sensors of hosts that belong to more than one group must be manually updated
The highest precedence policy from the most important group is applied to the host
All of the host's groups are examined in aggregate and the policy with highest precedence is applied to the host
Answer: D
4What may prevent a user from logging into Falcon via single sign-on (SSO)?
The SSO username doesn't match their email address in Falcon
The maintenance token has expired
Falcon is in reduced functionality mode
The user never configured their security questions
Answer: A
5The Customer ID (CID) is important in which of the following scenarios?
When adding a user to the Falcon console under the Users application
When performing the sensor installation process
When setting up API keys
When performing a Host Search
Answer: B
6Which statement describes what is recommended for the Default Sensor Update policy?
The Default Sensor Update policy should align to an organization's overall sensor updating practice while leveraging Auto N-1 and Auto N-2 configurations where possible
The Default Sensor Update should be configured to always automatically upgrade to the latest sensor version
Since the Default Sensor Update policy is pre-configured with recommend settings out of the box, configuration of the Default Sensor Update policy is not required
No configuration is required. Once a Custom Sensor Update policy is created the Default Sensor Update policy is disabled
Answer: A
7You need to have the ability to monitor suspicious VBA macros. Which Sensor Visibility setting should be turned on within the Prevention policy settings?
Script-based Execution Monitoring
Interpreter-Only
Additional User Mode Data
Engine (Full Visibility)
Answer: A
8What is the purpose of the Machine-Learning Prevention Monitoring Report?
It is designed to give an administrator a quick overview of machine-learning aggressiveness settings as well as the numbers of items actually quarantined
It is the dashboard used by an analyst to view all items quarantined and to release any items deemed non-malicious
It is the dashboard used to see machine-learning preventions, and it is used to identify spikes in activity and possible targeted attacks
It is designed to show malware that would have been blocked in your environment based on different Machine-Learning Prevention settings
Answer: D
9The Remote Access Graph in Visibility Reports displays:
a bar chart where a bar represents a daily count of remote connections
a geographical chart showing the geo-location of remote IP address
a graph showing connections between hosts and users
a pie chart showing a count per remote logon type
Answer: C
10What internet domain needs to be added to any required allowlists to allow sensors to communicate with the CrowdStrike Cloud?