In Falcon Identity Protection, thethree-dot (â‹®) action menuon anidentity-based detectionprovides analysts with a limited set of actions that applydirectly to the detection itself. According to the CCIS curriculum, these actions are designed to support investigation workflow, tuning, and documentation.
The supported actions in the detection-level three-dot menu include:
Edit status, which allows analysts to update the detection state (for example, New, In Progress, or Closed).
Add comment, which enables collaboration and documentation directly on the detection.
Add exclusion, where supported, to suppress future detections that match known benign behavior.
Add to Watchlistisnot includedin this menu because watchlists are applied toentities(such as users, service accounts, or endpoints), not to detections. Watchlists are managed from entity views or investigation workflows and are used to increase visibility and monitoring priority for specific identities—not to act on individual detections.
This distinction is emphasized in CCIS training to reinforce the separation betweenentity-centric actionsanddetection-centric actions. Because watchlists operate at the entity level,Option Bis the correct and verified answer.