Transit bus-yard kiosks must not run unknown binaries. Which Carbon Black Cloud control meets that intent?
Select an answer to reveal the explanation.
Short Explanation
A weekly scan is a rear-view mirror; the kiosk needs a locked ignition. Put a restrictive Endpoint Standard prevention policy on those sensors so unknown binaries never start.
Full Explanation
Carbon Black Cloud Endpoint Standard prevention policy is the control that blocks unknown or unwanted execution on the sensor. Weekly AV outside Carbon Black, EDR watchlists, and NSX Distributed Firewall do not implement that host execution policy. A restrictive policy assigned to the bus-yard kiosk group matches the lock-down intent.