Palo Alto Networks PSE-Endpoint Exam - Topic 2 Question 2 Discussion
An administrator is testing an exploit that is expected to be blocked by the JIT Mitigation EPM protecting the viewer application in use. No prevention occurs, and the attack is successful.In which two ways can the administrator determine the reason for the missed prevention? (Choose two.)
A) Check in the HKLM\SYSTEM\Cyvera\Policy registry key and subkeys whether JIT Mitigation is enabled for this application and C) Check that the Traps libraries are injected into the application
B) Check if a Just-In-Time debugger is installed on the system
D) Check that all JIT Mitigation functions are enabled in the HKLM\SYSTEM\Cyvera\Policy\Organization\Process\Default registry key
Renato
11 months agoGerry
11 months agoRhea
11 months agoOra
11 months agoGrover
11 months agoTheron
12 months agoRonna
12 months agoEmily
12 months agoElbert
12 months agoXuan
12 months agoRessie
12 months agoFrank
12 months agoDorsey
12 months ago