An organization detects a surge in failed login attempts across several user accounts. Most of these accounts belong to employees who are not currently on active projects. The CrowdStrike platform flags multiple accounts with medium risk scores. What should the analyst do to prioritize user assessment and mitigate potential threats?
Your organization wants to delegate the task of creating and managing policy rules to a security analyst. To minimize risk, you want to assign the minimum necessary Falcon role to allow the analyst to create, edit, and delete policy rules but prevent access to unrelated administrative tasks. Which Falcon role should you assign to the security analyst?
You need to use the Falcon Fusion GraphQL API to retrieve login events for a specific user, identified by their email address, and only include events where the status is "success." How should you structure this query?