nerdexam
CrowdStrike

CCFA-200B · Question #161

Which option best describes the general process for a manual installation of the Falcon Sensor on MacOS?

The correct answer is C. Install the Falcon package, use falconctl to license the sensor, approve the system extension. Option C correctly captures the three-stage manual macOS Falcon installation: first, the package is installed; second, falconctl is run to provide the Customer ID (CID), which licenses and activates the sensor; third, macOS requires explicit user approval of the system…

Falcon Sensor Deployment

Question

Which option best describes the general process for a manual installation of the Falcon Sensor on MacOS?

Options

  • AGrant the Falcon package Full Disk Access, install the Falcon package, load the Falcon Sensor
  • BInstall the Falcon package passing it the installation token in the command line
  • CInstall the Falcon package, use falconctl to license the sensor, approve the system extension,
  • DGrant the Falcon package Full Disk Access, install the Falcon package, use falconctl to license

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    92% (22)

Explanation

Option C correctly captures the three-stage manual macOS Falcon installation: first, the package is installed; second, falconctl is run to provide the Customer ID (CID), which licenses and activates the sensor; third, macOS requires explicit user approval of the system extension through Security & Privacy settings, since Apple restricts third-party kernel/system extensions by default.

Option A is wrong because granting Full Disk Access is not a prerequisite before installation - it's configured after, often via MDM policy, and "load the Falcon Sensor" is not the correct final step.

Option B describes passing an installation token on the command line, which is more characteristic of a Windows silent/automated installation, not the macOS manual process.

Option D is a near-miss but wrong because granting Full Disk Access is not the first step; installing the package comes first, and Full Disk Access is handled separately (typically via MDM or post-install system settings).

Memory tip: Think "Install → License → Approve" - on macOS you Install the package, License it with falconctl, and Approve the system extension. The acronym ILA (Install, License, Approve) keeps the order straight.

Topics

#MacOS sensor installation#falconctl#system extension approval#sensor licensing

Community Discussion

No community discussion yet for this question.

Full CCFA-200B Practice