Exit PSE-ENDPOINT Palo Alto Networks System Engineer Professional - Endpoint
Question 4 of 5
0% complete
Q4 Multiple choice

An administrator is testing an exploit that is expected to be blocked by the JIT Mitigation EPM protecting the viewer application in use. No prevention occurs, and the attack is successful.
In which two ways can the administrator determine the reason for the missed prevention? (Choose two.)

Select all that apply.

  • A

    Check in the HKLM\SYSTEM\Cyvera\Policy registry key and subkeys whether JIT Mitigation is enabled for this application

  • B

    Check if a Just-In-Time debugger is installed on the system

  • C

    Check that the Traps libraries are injected into the application

  • D

    Check that all JIT Mitigation functions are enabled in the HKLM\SYSTEM\Cyvera\Policy\Organization
    \Process\Default registry key