An Administrator has identified an EPM-triggered false positive and has used the Create Rule button from within the relevant entry in the Security Events > Preventions > Exploits tab. What is the result of the created rule?
D) The new rule will include the EPM that raised the prevention, the process that triggered the prevention, the machine on which the prevention was triggered, and a descriptive name for the rule.
Okay, I'm leaning towards A. If the admin is trying to address a false positive, they probably want to stop all EPM injection into the faulted process, right?
I'm going with D. The rule should include all the relevant details like the EPM, process, machine, and a descriptive name. Seems like the most comprehensive option.
Hmm, I think the answer is B. The new rule should stop all EPM injection into processes on the machine where the prevention was triggered, not just the faulted process.
Marisha
3 months agoViki
2 months agoArt
3 months agoKayleigh
3 months agoTarra
3 months agoKenneth
3 months agoBeatriz
3 months agoBarbra
3 months agoSalley
3 months agoHyman
3 months agoDalene
4 months agoCarmen
4 months agoTran
3 months agoMel
3 months agoCassandra
4 months agoHyman
4 months ago