TENSOR Framework

Q268 · Host scope 5

← Question library

Preserved graph release · 0.20260206e

Have scope boundaries for endpoint execution and persistence activity in privileged access events been expanded to include connected evidence?

Question ID
Q268
Category
Host
Archetype
scope
Declared entry point
No

The wording and classification above are preserved from this release. It does not contain assessment criteria, applicability rules, investigation-specific context, or evidence for this question. Those must not be inferred from the graph alone.

Recorded outgoing routes

These links show the graph's published routing. Following a link does not record an assessment or authorize an action.

Incoming routes (3)
  • Q26 on no (Q26-no-Q268)
  • Q127 on unknown (Q127-unknown-Q268)
  • Q214 on yes (Q214-yes-Q268)

Cite this exact question

Include the question ID, graph version, and source digest so that later revisions cannot silently change the reference.

TENSOR Framework, graph 0.20260206e, question Q268: “Have scope boundaries for endpoint execution and persistence activity in privileged access events been expanded to include connected evidence?” https://tensor-standards.pages.dev/questions/0.20260206e/Q268/
Source SHA-256
dfc3f1a965c01b6f7ade253e426e69abcbad688fab20d9d00065d71c777c010c

Download the exact graph · Pinned repository source

Using this question in the candidate Core

This preserved entry is not a converted Core 0.1.0-draft.1 definition. A reviewed conversion must supply explicit assessment criteria and parameters, preserve the source identity, and document any change in meaning. See the candidate contract and contribution process.