You are troubleshooting an issue with an Azure account registered in Falcon Cloud Security. The registration appeared to be successful but certain CSPM operations, including asset inventories and IOM detection, are failing.
How can you securely test the hypothesis that these failed CSPM operations are related to your firewall configuration?
Which Fusion workflow trigger can be used to take an action when a vulnerability is found on one of your container images?
You are a cloud security analyst concerned about adversaries obtaining admin privileges in your cloud environments.
Which Cloud Identity Analyzer category should you look at first?
You are setting up a Falcon Fusion SOAR workflow to notify your team when any new executable is downloaded to a container and run. You are using a Kubernetes and containers trigger.
Which trigger subcategory and type should you select for this purpose?
You are concerned about an overprivileged cloud identity.
What steps should you take to identify issues with the account's permissions?
You are investigating potential data exfiltration by reviewing IOAs in Falcon Cloud Security. You must check for any evidence of Defense Evasion via Impair Defenses: Disable or Modify Tools activity in your Azure environment.
Which IOA filters meet those requirements to identify any related IOAs?
Which category in the Containers dashboard can be used to identify containers that are performing activity not configured in the container image?
Your team wants to review container vulnerabilities on a weekly basis. Not all members of the team reviewing the information will have access to the Falcon console.
How can you automatically distribute the vulnerable container information from Cloud Security?
In which environment condition does CrowdStrike recommend starting with Phase 1: Initial deployment rather than moving directly to Phase 2: Interim protection?