The OWASP ModSecurity core rules are the most secure but likely to cause false positives. If you aren't familiar with mod_security then I would recommend switching to Atomic's free ruleset. Otherwise you will have to look at the domains logs to see which rules are triggering. The Plesk interface allows you to disable certain rules for a domain under domain -> Web Application Firewall.