Quiz 4 Question 2 of 20

A threat hunter notices an EDR rule for PowerShell encoded commands fires dozens of times per day from deployment scripts. The rule catches real attacks but also floods triage with benign automation. Which action best preserves hunting value while maintaining coverage?

Select an answer to reveal the explanation.

Motivation