คาอธิบาย:
การควบคุมในส่วนนี้เป็นการกาหนดว่า a user account is allowed to attach a debugger to any process
or the kernel. A debugger allows a user to view and manipulate the memory and execution
context of any process. การตั้งค่าแนะนาให้เป็นไปตามด้านล่าง:
• For the Enterprise Member Server and Enterprise Domain Controller profile(s),
the recommended value is Administrators.
• For the SSLF Member Server and SSLF Domain Controller profile(s), the
recommended value is No one.
เหตุผล:
Configuring the system as recommended will reduce the probability for a malicious local
user to circumvent application or system security control or view sensitive information
loaded in memory.