I'm going to have to go with B). Turning on that ransomware-like behavior rule is the way to go. Gotta stay one step ahead of those sneaky ransomware guys, am I right?
D) Start in the monitored policy until it's clear no attacks are happening? Seriously? That's like putting your head in the sand and hoping for the best. Not a fan.
Hmm, I'm not sure I trust the analytics to handle this. I'd go with A) Look at current attacks to see if the software is vulnerable. Better to be safe than sorry, you know?
C) Recognize that analytics will automatically block the attacks that may occur seems like a pretty convenient and hands-off approach. I'm all for that!
I think the most effective way is B) Turn on the performs ransomware-like behavior rule in the policies. That's the best way to proactively detect and block ransomware attacks.
Fausto
3 months agoGoldie
3 months agoMike
2 months agoAileen
2 months agoSarah
2 months agoRonny
2 months agoZoila
3 months agoHerman
2 months agoJulieta
3 months agoRosendo
3 months agoNan
2 months agoLorrine
2 months agoBettye
2 months agoArlie
3 months agoBarney
4 months agoHannah
4 months agoChristene
2 months agoElmira
3 months agoAdelle
3 months agoEthan
4 months agoBarney
4 months ago