156-215.80 · Question #394
Which tool provides a list of trusted files to the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed?
The correct answer is A. ThreatWiki. ThreatWiki is Check Point's cloud-based threat intelligence encyclopedia that provides administrators with file reputation data, including trusted files that can be excluded from Threat Prevention scanning.
Question
Which tool provides a list of trusted files to the administrator so they can specify to the Threat Prevention blade that these files do not need to be scanned or analyzed?
Options
- AThreatWiki
- BWhitelist Files
- CAppWiki
- DIPS Protections
How the community answered
(30 responses)- A87% (26)
- B10% (3)
- C3% (1)
Why each option
ThreatWiki is Check Point's cloud-based threat intelligence encyclopedia that provides administrators with file reputation data, including trusted files that can be excluded from Threat Prevention scanning.
ThreatWiki is Check Point's online malware database that classifies files as malicious, benign, or trusted based on global threat intelligence feeds. Administrators use ThreatWiki to identify trusted files and instruct the Threat Prevention blade to skip scanning them, reducing false positives and improving gateway performance.
'Whitelist Files' describes a general concept of excluding files from scanning but is not the name of the specific Check Point tool that provides the trusted file intelligence list to administrators.
AppWiki is Check Point's application signature database used by the Application Control blade to identify and categorize network applications, not a file trust or malware classification tool.
IPS Protections is a component of the Intrusion Prevention System blade focused on detecting and blocking network-based exploits and attacks, not on identifying or classifying trusted files.
Concept tested: Check Point ThreatWiki trusted file identification for Threat Prevention
Source: https://www.checkpoint.com/threatwiki/
Topics
Community Discussion
No community discussion yet for this question.