問題文
An analyst at a manufacturing company is documenting which security profile inspects which part of a session. A workstation is downloading an executable over an allowed application, and the same workstation later starts sending periodic beacons to an external host. Which profile is designed to act on the beaconing traffic rather than on the downloaded file?
選択肢
- The Antivirus profile, because every outbound session is scanned for known malicious payloads at the point where the file is reassembled.
- The Anti-Spyware profile, because it targets traffic generated by an already infected host that is trying to reach its controller.
- The Vulnerability Protection profile, because beaconing is treated as an attempt to exploit a weakness in the destination server that the workstation keeps contacting.
- The File Blocking profile, which stops the beacons because it controls the file types allowed in each direction, so a beacon payload counts as one of those types.