It is recommended to start with Rapid Configs in Report mode before changing to Block to allow an opportunity to test changes.
Using a more dynamic Exception to start with is recommended. This makes it easier to verify the Exception is properly formatted.
Further testing should be done to determine how specific to make the Exception while still allowing desired functionality.
Exceptions may need to be adjusted over time depending on changes by 3rd party vendors.
Additional Information
Example: Suspicious Command Line Protection N-Z
By default the Sc Command Lines To Report is:
<cmdline:*create*>sc.exe
This means that anytime the process sc.exe includes create in the command line, the Agent may take action. An example that would trigger this Rapid Config could be: