You enable Sweep Scan Protection and Host port scan in IPS to determine if a large amount of traffic from a specific internal IP address is a network attack, or a user's system is infected with a worm. Will you get all the information you need from these actions?
You need to determine if your company's Web servers are accessed an excessive number of times from the same host. How would you configure this in the IPS tab?
When two or more DLP rules are matched, the action taken is the most restrictive action. Rank the following items from the lowest restriction level (1) to the highest (4).
1. Ask User
2. Prevent
3. Detect
4. Inform User