📝 Section Review: Threat Protection & Analytics
اہم نکاتKey TakeawaysKey Takeaways
- اینٹی وائرس معلوم میلویئر کو فوراً بلاک کرتا ہے؛ سینڈ باکس برتاؤ سے مشکوک فائلز پکڑتی ہے؛ ML عالمی پیٹرنز سے زیرو ڈے پکڑتا ہے۔Antivirus maloom malware ko foran block karta hai; sandbox bartao se mashkook files pakarti hai; ML global patterns se zero-day pakarta hai.Antivirus blocks known malware instantly; sandbox catches suspicious files by behavior; ML catches zero-days by global patterns.
- کلاؤڈ ایفیکٹ: ایک کسٹمر کی ڈیٹیکشن سیکنڈوں میں ہر ٹیننٹ کو بچاتی ہے۔Cloud effect: ek customer ki detection secondon mein har tenant ko bachati hai.Cloud effect: one customer's detection protects every tenant within seconds.
- 'یہ کیوں بلاک ہوا؟' کے لیے Web Insights پہلی جگہ ہے — صارف، URL یا ایکشن سے فلٹر کریں۔'Yeh kyun block hua?' ke liye Web Insights pehli jagah hai — user, URL ya action se filter karein.Web Insights is your first stop for 'why is this blocked?' — filter by user, URL, or action.
- Security Insights تھریٹ ڈیٹیکشنز دکھاتا ہے: میلویئر، فشنگ، سینڈ باکس ورڈکٹس۔Security Insights threat detections dikhata hai: malware, phishing, sandbox verdicts.Security Insights shows threat detections: malware, phishing, sandbox verdicts.
- False positives allowlist سے handle ہوتے ہیں (مثلاً Malware Protection میں فائل ہیش)۔False positives allowlist se handle hote hain (masalan Malware Protection mein file hash).False positives are handled via allowlists (e.g. file hash in Malware Protection).
- اپنے SIEM میں لاگز بھیجنے کے لیے Nanolog Streaming Service (NSS) استعمال کریں۔Apne SIEM mein logs bhejne ke liye Nanolog Streaming Service (NSS) istemal karein.Use Nanolog Streaming Service (NSS) to feed logs into your SIEM.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ ZIA کی تین تھریٹ پروٹیکشن لیئرز کے نام بتائیں۔ZIA ki teen threat protection layers ke naam batayein.Name ZIA's three threat protection layers.
اینٹی وائرس معلوم میلویئر کو سگنیچرز سے پکڑتا ہے؛ سینڈ باکس مشکوک فائلز کو الگ ماحول میں چلاتی ہے اور برتاؤ سے بلاک کرتی ہے؛ ML کبھی نہ دیکھی ہوئی زیرو ڈے کو عالمی پیٹرنز سے پکڑتا ہے۔Antivirus maloom malware ko signatures se pakarta hai; sandbox mashkook files ko isolated environment mein chalata hai aur bartao se block karta hai; ML kabhi na dekhi hui zero-day ko global patterns se pakarta hai.Antivirus catches known malware by signatures; the sandbox detonates suspicious files in isolation and blocks by behavior; ML catches never-seen-before zero-days by global patterns.
❓ سینڈ باکسنگ کا 'کلاؤڈ ایفیکٹ' کیا ہے؟Sandboxing ka 'cloud effect' kya hai?What is the 'cloud effect' of sandboxing?
کلاؤڈ ایفیکٹ: ایک سینڈ باکس کا فیصلہ فوراً تمام ٹیننٹس کو بچاتا ہے — ایک کسٹمر پر ہونے والے حملے کی کوشش سب کی حفاظت بن جاتی ہے۔Cloud effect: ek sandbox ka faisla foran tamam tenants ko bachata hai — ek customer par hone wale hamle ki koshish sab ki hifazat ban jati hai.Cloud effect: one sandbox verdict protects all tenants instantly — one customer's attack attempt becomes everyone's defense.
❓ ZIA ٹربل شوٹنگ کا طریقہ بتائیں۔ZIA troubleshooting ka tariqa batayein.Walk through the ZIA troubleshooting flow.
مسئلہ دوبارہ پیدا کریں، Web Insights میں ٹرانزیکشن ڈھونڈیں، میچ شدہ پالیسی پڑھیں، رول ٹھیک کریں یا استثنا شامل کریں، Activate کریں، اور دوبارہ ٹیسٹ کریں۔Masla dobara paida karein, Web Insights mein transaction dhoondein, matched policy parhein, rule theek karein ya exception add karein, Activate karein, aur dobara test karein.Reproduce the problem, find the transaction in Web Insights, read the matched policy, fix the rule or add an exception, Activate, and re-test.
❓ ZIA کے لاگز SIEM تک کیسے پہنچتے ہیں؟ZIA ke logs SIEM tak kaise pahunchte hain?How do ZIA logs reach a SIEM?
NSS (Nanolog Streaming Service) ZIA کے لاگز آپ کے لاگ سرور/SIEM پر بھیجتا ہے، retention اور اینالسس کے لیے۔NSS (Nanolog Streaming Service) ZIA ke logs aap ke log server/SIEM par bhejta hai, retention aur analysis ke liye.NSS (Nanolog Streaming Service) streams ZIA logs to your log server/SIEM for retention and analysis.