What is the purpose of the Machine-Learning Prevention Monitoring Audit Log?
Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to “C:\Users\Bob\DevCode\felix.dll”. In the detection, you see that it is triggering only on a specific Falcon IOA. What would be the best course of action for this situation?
Your development team is working on a new enterprise application, but Falcon starts creating alerts during testing. The alert points to C:\Users\Bob\DevCode\felix.dll. In the detection, you see that it is triggering only on a specific Falcon IOA. What action should be taken to resolve this issue?
What is the fastest way to locate inactive sensors in the Falcon console?
When configuring a third-party integration to communicate with the Falcon API, which credential combination must be generated first?
What are the three required parts of a Fusion SOAR workflow condition?
What happens to detections in the console after clicking “Disable Detections” for a host from within the Host Management page?
What log would you use to investigate unusual activity invoked with a script interfacing with the Falcon platform?
Where would you apply a configuration to allow IP addresses over which your hosts will always be allowed to communicate, even if a host is contained?
After successfully installing Falcon on a new employee’s laptop, you notice that the machine is assigned the default prevention policy instead of the custom prevention policy you created. You verify that the Falcon sensor is functioning properly, and you confirm that the custom policy is enabled and successfully running on more than 1,000 other Falcon hosts. What is the likely cause of this issue?
TESTED 26 May 2026