When the interface is available, open cPanel → Security → ModSecurity.
You can enable or disable protection for all domains or manage individual domains. Because disabling ModSecurity removes its rule protection for that domain, use a temporary disable only to confirm whether ModSecurity is responsible for a reproducible request failure.
After testing, re-enable ModSecurity unless there is a documented reason to leave it off.