問題文
A compliance team wants to be told whenever a particular remote-access utility is launched on finance workstations. The utility is a legitimate tool that the company has simply decided nobody should run there. Which capability fits this requirement?
選択肢
- A custom rule that describes the behavior of launching that utility, so that the activity is reported even though it is not malicious in itself.
- A dynamic host group whose rule matches on the utility's presence.
- An entry on the blocklist for the utility's file hash, so that the platform reports it wherever it is seen.
- A file path exclusion for the utility on the finance workstations.