You assigned an Attack Surface Reduction profile (Profile1) to all Windows 11 devices and now an Adobe Reader plug-in is blocked. To allow that plug-in, what should you configure in Profile1?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure ASR Only Per Rule exclusions in Profile1..
Why this is the answer
Attack Surface Reduction (ASR) rules can block legitimate applications or plugins. To allow a specific Adobe Reader plug-in while maintaining the overall ASR protection, you should configure ASR Only Per Rule exclusions within Profile1. This allows you to specify files, folders, or processes that should be exempt from particular ASR rules, preventing the plug-in from being blocked without disabling the entire rule. Creating an Endpoint Privilege Management policy is for elevating privileges, not for managing ASR exclusions. Adding a scope tag is for administrative access control, not for configuring ASR rule behavior. Creating a device compliance policy defines security baselines and actions for non-compliant devices, but doesn't directly manage ASR rule exclusions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed