Q53
Single choice
You have 1,000 on-premises Windows 11 Pro devices that are onboarded to Microsoft Defender for Endpoint.
You have a Microsoft 365 subscription that uses Microsoft Defender XDR.
You identify that an attacker performed the following actions on a device:
1. Modified the filesystem path of a registry-based antivirus exclusion
2. Downloaded a malicious file to the file system path
You initiate a live response session on the device.
You need to undo the registry change.
Which command should you run?