Lesson 8: Quarantine Functionality and Concepts

Lesson 8: Quarantine Functionality and Concepts

Created by
@ComfortingWetland

Questions and Answers

What should be selected for the flow control when creating a new Quarantine action set?

Quarantine

What should the thresholds be set to for immediate block in Quarantine settings?

1 and 1

For what purpose can TCP Reset be used as part of Quarantine Actions?

For SMTP virus filters

Which profile will be used to test the newly created Quarantine action set?

<p>DMZ Profile</p> Signup and view all the answers

When can a host appear in the Quarantined Hosts table?

<p>When it triggers a specific filter</p> Signup and view all the answers

What is recommended to use quarantine for?

<p>Unusual user activity</p> Signup and view all the answers

What is the purpose of setting automatic timeout in quarantine?

<p>To release quarantined hosts after a certain period</p> Signup and view all the answers

Where would a blocked stream be generated when an Action Set is configured for Block + Quarantine and a threshold is not set?

<p>In the Quarantined Hosts table</p> Signup and view all the answers

What is one of the main functions of Spyware Filters?

<p>Immediately block malicious traffic</p> Signup and view all the answers

When does Quarantine occur, according to the lesson?

<p>After excessive filter hits</p> Signup and view all the answers

What can be configured to occur at a user-defined threshold?

<p>Quarantine actions</p> Signup and view all the answers

What action can be taken before the threshold is triggered?

<p>Display a Quarantine web page</p> Signup and view all the answers

What is one consideration when configuring Quarantine for web requests?

<p>Display the Quarantine Block page</p> Signup and view all the answers

What is one way hosts can be released from Quarantine?

<p>Redirect web requests to an external server</p> Signup and view all the answers

What should be done with other non-web traffic, according to the lesson?

<p>Block other non-web traffic</p> Signup and view all the answers

What can be reached by hosts in Quarantine?

<p>Addresses which can be reached by quarantined hosts</p> Signup and view all the answers

What is the main function of TippingPoint Quarantine?

<p>Preventing insider threats and walk-in worms</p> Signup and view all the answers

How does Quarantine work with the source IP address in the packets?

<p>It adds the source IP to the Quarantine list</p> Signup and view all the answers

When can Blocking Quarantine be used?

<p>To prevent an infected machine from spreading worms</p> Signup and view all the answers

What does Quarantine communicate with switching infrastructures to do?

<p>Isolate offending endpoints with remediation VLANs</p> Signup and view all the answers

How does Blocking Quarantine help inform the user?

<p>By informing the user that something has gone wrong</p> Signup and view all the answers

What type of threats does TippingPoint Quarantine primarily aim to block?

<p>Insider threats and walk-in worms</p> Signup and view all the answers

In what situation can Quarantine be used to prevent network infection?

<p>When an infected machine is spreading worms</p> Signup and view all the answers

What does TippingPoint Quarantine do with the source IP in the packets it inspects?

<p>Adds it to the Quarantine list</p> Signup and view all the answers

More Quizzes Like This

Use Quizgecko on...
Browser
Browser