Technology
Adversaries
Products
CyberSecurity General Knowledge
100

Which CrowdStrike Falcon capability uses behavioral AI to detect threats WITHOUT relying on an internet connection or cloud lookup?

Falcon Prevent (on-sensor ML)

100

From which country is the BEAR derived

Russia

100

What CrowdStrike service provides 24/7 human-led threat hunting?

Adversary Overwatch

100

SentinelOne's Platform is called what?

Singularity

200

What is the name of CrowdStrike's cloud-native data platform that powers Falcon's telemetry?

Threat Graph

200

WIZARD SPIDER is a prolific eCrime group. What country are they believed to operate from?

Russia!

200

What does CrowdStrike's Falcon platform primarily use to detect threats?

AI and Machine Learning

200

What is the name of Palo Alto Networks' endpoint and XDR product that competes directly with Falcon?

Cortex XDR

300

What is CrowdStrike's term for the automated workflow and response orchestration engine built into the Falcon platform?

Falcon FUSION

300

CROWDSTRIKE attributed the 2014 Sony Pictures hack to which nation-state adversary group?

Labyrinth Chollima (North Korea)

300

What distinguishes Falcon Complete from Falcon OverWatch?

Falcon Complete is a fully managed detection & response service, while OverWatch is a managed threat hunting overlay

300

What independent evaluation does CrowdStrike regularly participate in that proves detection effectiveness against competitors?

MITRE ATT&CK Evaluations

400

Falcon Identity Threat Protection detects identity-based attacks by integrating with which core enterprise directory service?

Active Directory

400

WIZARD SPIDER is a well-known eCrime adversary group. What ransomware family are they most associated with?

Ryuk / Conti

400

What is the "1-10-60 rule" that CrowdStrike champions in cybersecurity?

Detect in 1 min, investigate in 10 min, contain in 60 min

400

What is the "1-10-60 rule" that CrowdStrike champions in cybersecurity?

Detect in 1 min, investigate in 10 min, contain in 60 min

500

In CrowdStrike's Threat Graph, approximately how many events are ingested per day at peak scale?

1 Trillion

500

In CrowdStrike's Intelligence taxonomy, what specific criteria differentiate a "BEAR" (Russian) adversary from a "SPIDER" (eCrime) adversary when attribution is ambiguous?

SPIDER actors are always financially motivated with no nation-state nexus; BEAR actors operate under FSB, GRU, or SVR direction with geopolitical objectives

500

What is a SPIFFE?

Secure Production Identity Framework for Everyone

SPIFFE is an open standard that gives workloads (like microservices, containers, or applications) a verified identity so they can securely communicate with each other — without using passwords or API keys.

500

Legacy AV tools like Symantec and Trellix rely on what outdated method that CrowdStrike has moved beyond?

Signature Based Detection

M
e
n
u