PCNSA · Question #322
Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?
The correct answer is B. imap. This question references a screenshot of an Anti-Spyware or threat profile configuration showing protocol decoder actions. The IMAP decoder is configured with an action of 'allow' (permit traffic) while also having machine-learning (ML) inline detection enabled and logging…
Question
Review the screenshot below. Based on the information it contains, which protocol decoder will detect a machine-learning match, create a Threat log entry, and permit the traffic?
Exhibit
Options
- Asmb
- Bimap
- Cftp
- Dhttp2
How the community answered
(40 responses)- A3% (1)
- B80% (32)
- C13% (5)
- D5% (2)
Explanation
This question references a screenshot of an Anti-Spyware or threat profile configuration showing protocol decoder actions. The IMAP decoder is configured with an action of 'allow' (permit traffic) while also having machine-learning (ML) inline detection enabled and logging turned on (creating a Threat log entry). The other decoders (SMB, FTP, HTTP2) have different actions configured - such as block or reset - that would not permit the traffic. The combination of ML detection + Threat logging + allow action uniquely identifies IMAP in the referenced screenshot.
Topics
Community Discussion
No community discussion yet for this question.
