Q: 15
What best describes what happens to detections in the console after clicking "Enable Detections" for a
host which previously had its detections disabled?
Options
Discussion
I don't think it's C. B. I figured when you re-enable detections, the console might pull in some historical events that happened while detections were off. Maybe I'm mixing it up with another EDR, but pretty sure I saw similar behavior before. If anyone can confirm 100%, let me know.
Its C. When you hit Enable Detections, only new detections start coming in for that host. B's a trap since Falcon doesn't go back and recover old detections when re-enabled. Pretty sure that's standard behavior, unless something changed.
Yeah, C makes sense. You only see new detections after you turn it back on, nothing from before comes back. That's how CrowdStrike works as far as I know. Let me know if there's edge cases I missed.
C is right. Once you re-enable detections, only new alerts show up in the console for that host. Anything that happened while detections were off won't get restored. Pretty sure that's how Falcon handles it, but correct me if I'm off.
Be respectful. No spam.
Question 15 of 35