📝 Section Review: Threat Prevention
اہم نکاتKey TakeawaysKey Takeaways
- پروفائلز پروفائل گروپس کے ذریعے رولز سے اٹیچ ہوتے ہیں — ہر رول پر ایک گروپ، ریڈیبل رہتا ہے۔Profiles profile groups ke zariye rules se attach hote hain — har rule par ek group, readable rehta hai.Profiles attach to rules via profile groups — one group per rule keeps it readable.
- آئی پی ایس ایکشنز: الاؤ، الرٹ، ڈراپ، ری سیٹ — ری سیٹ سیشن مار دیتا ہے، ڈراپ چپ چاپ گرا دیتا ہے۔IPS actions: allow, alert, drop, reset — reset session maar deta hai, drop chup chaap gira deta hai.IPS actions: allow, alert, drop, reset — reset kills the session, drop discards silently.
- فالس پازیٹو پر صرف اس سگنیچر کو ایکسیپشن دیں — پورا پروفائل ڈس ایبل کبھی نہ کریں۔False positive par sirf us signature ko exception dein — poora profile disable kabhi na karein.For a false positive, exception the single signature — never disable the whole profile.
- وائلڈ فائر سینڈ باکس + اِن لائن ایم ایل + ڈی این ایس سیکیورٹی = لیئرڈ زیرو ڈے ڈیفینس۔WildFire sandbox + inline ML + DNS Security = layered zero-day defense.WildFire sandbox + inline ML + DNS Security = layered zero-day defense.
- ہارملس ای آئی سی اے آر فائل سے ٹیسٹ کریں اور تھریٹ لاگ دیکھیں — پروفائلز کام کرنے کا سیف ثبوت۔Harmless EICAR file se test karein aur threat log dekhein — profiles kaam karne ka safe saboot.Test with the harmless EICAR file and watch the threat log — safe proof profiles work.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ سیکیورٹی رول بمقابلہ سیکیورٹی پروفائل؟Security rule vs security profile?Security rule vs security profile?
رولز الاؤ/بلاک کرتی ہیں؛ پروفائلز الاؤڈ ٹریفک کو میلویئر، اسپائی ویئر اور ایکسپلائٹس کے لیے اسکین کرتے ہیں۔Rules allow/block karti hain; profiles allowed traffic ko malware, spyware aur exploits ke liye scan karte hain.Rules allow/block; profiles scan allowed traffic for malware, spyware, and exploits.
❓ رول پر پروفائلز کیسے اپلائی کرتے ہیں؟Rule par profiles kaise apply karte hain?How do you apply profiles to a rule?
اے وی، اینٹی اسپائی ویئر، ولنریبیلیٹی، یو آر ایل، وائلڈ فائر، ڈی این ایس پروفائلز بنڈل کر کے گروپ کو رول سے اٹیچ کریں — ہر رول پر ایک سیٹنگ۔AV, anti-spyware, vulnerability, URL, WildFire, DNS profiles bundle karke group ko rule se attach karein — har rule par ek setting.Bundle AV, anti-spyware, vulnerability, URL, WildFire, DNS profiles and attach the group to the rule — one setting per rule.
❓ وائلڈ فائر اور اِن لائن ایم ایل زیرو ڈیز کو کیسے روکتے ہیں؟WildFire aur inline ML zero-days ko kaise rokte hain?How do WildFire and inline ML stop zero-days?
یہ ان نون فائلز کو کلاؤڈ سینڈ باکس میں ڈیٹونیٹ کرتا ہے اور بینائن/گرے ویئر/میلیشس ورڈکٹس دیتا ہے؛ اِن لائن ایم ایل فائلز کو لوکلی ملی سیکنڈز میں جج کرتا ہے۔Ye unknown files ko cloud sandbox mein detonate karta hai aur benign/grayware/malicious verdicts deta hai; inline ML files ko locally milliseconds mein judge karta hai.It detonates unknown files in a cloud sandbox and returns benign/grayware/malicious verdicts; inline ML judges files locally in milliseconds.
❓ ڈی این ایس سیکیورٹی کیا کرتی ہے؟DNS Security kya karti hai?What does DNS Security do?
یہ ڈی این ایس کوئریز پر ایم ایل استعمال کر کے ڈی جی اے ڈومینز، ٹنلنگ اور فشنگ کو پہچانتی ہے — اور انہیں سنک ہول کرتی ہے۔Ye DNS queries par ML use karke DGA domains, tunneling aur phishing ko pehchanti hai — aur unhein sinkhole karti hai.It uses ML on DNS queries to spot DGA domains, tunneling, and phishing — and sinkholes them.