When a system access point is violated, the action depends on how the rule is configured.
If the rule was configured to:
Report — Information is recorded in the log file.
Block — Access is denied.
Take these steps:
Review the log file to determine which system access points were violated and which rules detected the violations.
Configure the Access Protection rules to allow users access to legitimate items and prevent users from accessing protected items.
Use these scenarios to decide which action to take as a response.
Detection type | Scenarios |
|---|---|
Unwanted processes |
|
Legitimate processes |
|