Palo Alto Networks PSE-Endpoint Exam - Topic 2 Question 2 Discussion
An administrator is testing an exploit that is expected to be blocked by the JIT Mitigation EPM protecting the viewer application in use. No prevention occurs, and the attack is successful.In which two ways can the administrator determine the reason for the missed prevention? (Choose two.)
A) Check in the HKLM\SYSTEM\Cyvera\Policy registry key and subkeys whether JIT Mitigation is enabled for this application and C) Check that the Traps libraries are injected into the application
B) Check if a Just-In-Time debugger is installed on the system
D) Check that all JIT Mitigation functions are enabled in the HKLM\SYSTEM\Cyvera\Policy\Organization\Process\Default registry key
Renato
9 months agoGerry
9 months agoRhea
9 months agoOra
10 months agoGrover
10 months agoTheron
10 months agoRonna
10 months agoEmily
10 months agoElbert
10 months agoXuan
10 months agoRessie
10 months agoFrank
10 months agoDorsey
10 months ago