問題文
An analyst has to explain to an auditor why threat inspection is configured on rules that permit traffic and not on the rules that deny it. What is the reason?
選択肢
- Denied sessions are inspected by a separate profile type that is attached to the zone instead of the rule, and that is why the deny rules in the rulebase do not carry any profile of their own.
- Deny rules cannot reference any object so a profile has to be attached at the zone level if the denied sessions are to be recorded at all in the threat log.
- Inspection of the content happens on sessions that are allowed to proceed, so a rule that denies the session has nothing left to inspect.
- Inspection is disabled on deny rules to save resources so that the analyst turns it on again only when a denied session has to be studied in detail.