問題文
Endpoint groups can be defined by characteristics or by picking machines. Why is the characteristic-based form usually preferred for policy targeting?
選択肢
- Because hand-picked groups cannot be used in policies, so the only way to attach a prevention profile to a machine is to describe the machine with characteristics.
- Because a hand-picked group is limited to a small number of machines and, once that limit is reached, the group has to be split into several groups that then all have to be named individually in every policy that targets them.
- Because characteristic-based groups are evaluated on the endpoint rather than on the server, which makes them effective while the machine is offline.
- New machines that match the characteristics join the group without anyone editing it, so protection reaches them the first time they register.