CCFA-200B · Question #161
Which option best describes the general process for a manual installation of the Falcon Sensor on MacOS?
The correct answer is C. Install the Falcon package, use falconctl to license the sensor, approve the system extension. Option C correctly captures the three-stage manual macOS Falcon installation: first, the package is installed; second, falconctl is run to provide the Customer ID (CID), which licenses and activates the sensor; third, macOS requires explicit user approval of the system…
Question
Which option best describes the general process for a manual installation of the Falcon Sensor on MacOS?
Options
- AGrant the Falcon package Full Disk Access, install the Falcon package, load the Falcon Sensor
- BInstall the Falcon package passing it the installation token in the command line
- CInstall the Falcon package, use falconctl to license the sensor, approve the system extension,
- DGrant the Falcon package Full Disk Access, install the Falcon package, use falconctl to license
How the community answered
(24 responses)- A4% (1)
- B4% (1)
- C92% (22)
Explanation
Option C correctly captures the three-stage manual macOS Falcon installation: first, the package is installed; second, falconctl is run to provide the Customer ID (CID), which licenses and activates the sensor; third, macOS requires explicit user approval of the system extension through Security & Privacy settings, since Apple restricts third-party kernel/system extensions by default.
Option A is wrong because granting Full Disk Access is not a prerequisite before installation - it's configured after, often via MDM policy, and "load the Falcon Sensor" is not the correct final step.
Option B describes passing an installation token on the command line, which is more characteristic of a Windows silent/automated installation, not the macOS manual process.
Option D is a near-miss but wrong because granting Full Disk Access is not the first step; installing the package comes first, and Full Disk Access is handled separately (typically via MDM or post-install system settings).
Memory tip: Think "Install → License → Approve" - on macOS you Install the package, License it with falconctl, and Approve the system extension. The acronym ILA (Install, License, Approve) keeps the order straight.
Topics
Community Discussion
No community discussion yet for this question.