When you go to Server > Advanced Settings and click on the online help it will outline all the settings and usage.
In regards to "IncidentDetection.TrialMode" it states:
Prevention demo mode setting to generate prevention incidents without having a prevention setup.
If true, SMTP incidents coming from the Copy Rule and Packet Capture channels appear as if they were prevented and HTTP incidents coming from Packet Capture channel appear as if they were prevented
The default setting is false.
Also note: In addition to controlling the demo mode for Prevent, it also controls the trial mode for the Protect product. If this setting is set to true the protect functionality will be disabled.