📝 Section Review: Threat Prevention
اہم نکاتKey TakeawaysKey Takeaways
- Threat Prevention blades: IPS، Anti-Bot، Anti-Virus، Application Control، URL Filtering اور SandBlast — ہر گیٹ وے پر چالو، ایک پالیسی سے منظم۔Threat Prevention blades: IPS, Anti-Bot, Anti-Virus, Application Control, URL Filtering aur SandBlast — har gateway par enabled, ek policy se managed۔Threat Prevention blades: IPS, Anti-Bot, Anti-Virus, Application Control, URL Filtering, and SandBlast — enabled per gateway, managed by one policy.
- Profiles blade actions (Prevent/Detect) یکجا کرتے ہیں؛ blades بند کرنے کے بجائے انفرادی protections overrides سے ترتیب دیں۔Profiles blade actions (Prevent/Detect) bundle karte hain; blades disable karne ke bajaye individual protections overrides se tune karein.Profiles bundle blade actions (Prevent/Detect); tune individual protections with overrides instead of disabling blades.
- SandBlast Threat Emulation + ML رویے کا تجزیہ zero-days پکڑتا ہے؛ Threat Extraction فوراً محفوظ کاپیاں پہنچاتا ہے۔SandBlast Threat Emulation + ML behavior analysis zero-days pakarti hai; Threat Extraction foran safe copies deliver karta hai.SandBlast Threat Emulation + ML behavior analysis catches zero-days; Threat Extraction delivers safe copies instantly.
- HTTPS Inspection معتمد CA سے decrypt-inspect-re-encrypt کرتا ہے؛ CA clients پر نصب کریں اور حساس زمرے bypass کریں۔HTTPS Inspection trusted CA se decrypt-inspect-re-encrypt karta hai; CA clients par deploy karein aur sensitive categories bypass karein.HTTPS Inspection decrypts-inspects-re-encrypts with a trusted CA; deploy the CA to clients and bypass sensitive categories.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ ہر ایک ایک سطر میں: IPS، Anti-Bot، Anti-Virus، SandBlast۔Har ek ek line mein: IPS, Anti-Bot, Anti-Virus, SandBlast۔One line each: IPS, Anti-Bot, Anti-Virus, SandBlast.
IPS = signatures سے معروف حملے؛ Anti-Bot = C&C رویے سے متاثرہ ہوسٹس؛ Anti-Virus = فائلوں میں معروف میلویئر؛ SandBlast = sandbox detonation سے نامعلوم/zero-day فائلیں۔IPS = signatures se known attacks; Anti-Bot = C&C behavior se infected hosts; Anti-Virus = files mein known malware; SandBlast = sandbox detonation se unknown/zero-day files۔IPS = known attacks via signatures; Anti-Bot = infected hosts via C&C behavior; Anti-Virus = known malware in files; SandBlast = unknown/zero-day files via sandbox detonation.
❓ Emulation بمقابلہ Extraction؟Emulation vs Extraction?Emulation vs Extraction?
Threat Emulation فائل کو کلاؤڈ sandbox میں detonate کرتا ہے اور ML اس کے رویے کو اسکور کرتا ہے؛ Threat Extraction فوراً محفوظ reconstructed کاپی پہنچاتا ہے تاکہ صارفین کچھ انتظار نہ کریں۔Threat Emulation file ko cloud sandbox mein detonate karta hai aur ML us ke behavior ko score karta hai; Threat Extraction foran safe reconstructed copy deliver karta hai taake users kuch intezar na karein.Threat Emulation detonates the file in a cloud sandbox and ML scores its behavior; Threat Extraction instantly delivers a safe reconstructed copy so users wait for nothing.
❓ HTTPS inspect کیوں کریں، اور رازداری کی حد کیا ہے؟HTTPS inspect kyun karein, aur privacy guardrail kya hai?Why inspect HTTPS, and what's the privacy guardrail?
HTTPS Inspection: گیٹ وے معتمد CA سے decrypt کرتا ہے، blades سے جانچتا ہے، اور دوبارہ encrypt کرتا ہے۔ اس کے بغیر encrypted خطرات نظر نہیں آتے۔ بینکنگ جیسے حساس زمرے bypass کریں۔HTTPS Inspection: gateway trusted CA se decrypt karta hai, blades se inspect karta hai, aur dobara encrypt karta hai. Is ke baghair encrypted threats nazar nahi aate. Banking jaise sensitive categories bypass karein.HTTPS Inspection: the gateway decrypts with a trusted CA, inspects with the blades, and re-encrypts. Without it, encrypted threats are invisible. Bypass sensitive categories like banking.