After deploying CrowdStrike Falcon, you notice that one of your domain controllers (DCs) is not reporting its activity in the Falcon Console. This DC is responsible for managing a significant number of endpoints. Which of the following actions will help you resolve this issue?
During a security review, a CrowdStrike Falcon Identity Threat Detection alert is triggered for a high-risk user attempting to access a sensitive application from an unusual geographic location. As a security analyst, you need to investigate the incident further using available pivots in the CrowdStrike console. Which of the following actions is the most appropriate first step for an identity-based investigation?