Web Control Flashcards

1
Q

Give a high level description of the Web Control module.

A

Web Control is a Browser Protection solution that monitors web searching and browsing activity on client computers, and protects against threats on web pages and in file downloads

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the “Protect” Features of Web Control?

A

Block and Allow List - Prevent users from visiting specific URLs or domains, or always allow access to sites that are important to your business

Rating Actions and Web Category Blocking - Use safety ratings and web categories defined by McAfee to control user access to sites, pages, and downloads

Secure Search - Automatically block risky sites from appearing in search results based on their safety rating

Self Protection - Prevents users from disabling the Web Control plug-in or uninstalling or changing Web Control files, registry keys, registry values, services, and processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the “Detect” features of Web Control?

A
  • Web Control button in the browser window - The Web Control plug-in displays a button indicating the safety rating for the site. Click the button for more information about the site.
  • Web Control icon on search results pages - An icon appears next to each listed site. The color of the icon indicates the safety rating for the site. Hover over the icon for more information about the site.
  • Site Reports - Details show how the safety rating was calculated based on types of threats detected, test results, and other data.
  • Dashboards and monitors - Display statistics about Web Control activity, including visits and downloads from sites by rating, content type, and blocked or allowed list.
  • Queries and Reports - retrieve detailed information about Web Control browser events, and save it in reports
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the “Correct” features of Web Control?

A

Interlock with other McAfee products - Disable Web Control automatically if it detects a web gateway appliance or if McAfee Client Proxy

File scanning for file downloads - Web control sends files to Threat Prevention for scanning. If it detects a threat, Threat Prevention responds with the configured action such as clean, and alerts the user

Dashboard and monitors - Monitor activity to understand browsing activity, then use that information to tune Web Control settings

Exclusions - Prevent Web Control from rating or blocking specific IP addresses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Where does Web Control get the reputation information to determine how to handle navigation to URLs

A

GTI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What browsers does Web Control support?

A
  • Internet Explorer 11
  • Chrome
  • Firefox
  • Firefox ESR
  • Safari

(Doesn’t support Microsoft Edge)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the different color coded buttons and what do they signify?

A

Green Secure - Site is tested daily and certified safe by McAfee Secure

Green -This site is safe.

Yellow - This site might have some issues.

Red - This site has some serious issues.

Grey - No rating is available for this site.
This button appears for FILE (file://) protocol URLs.

Orange - A communication error occurred with the McAfee GTI server that
contains rating information.

Blue - Web Control didn’t query McAfee GTI for this site, which indicates that the site is internal or in a private IP address range.

Black - This site is a phishing site

White - A setting allows this site

Gray translucent - A setting disabled web control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What do search result icons signify?

A

Check mark - Tests revealed no significant problems

Exclamation Point - Tests revealed some issues that users might need to know about. For example, the site tried to change the testers’ browser defaults, displayed pop-ups, or sent testers a significant amount of non-spam email.

Red X - Tests revealed some serious issues that users must consider carefully before accessing this site. For
example, the site sent testers spam email or bundled adware with a download.

Caution Symbol - A Web Control setting blocked this site.

Question Mark - This site is unrated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What feature in Web control allows you to view more details about a site?

A

Site report

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What details do site reports reveal?

A

An Overview of a website

Online Affiliations

Web Spam Test

Download Test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What can Web Control set rating actions for?

A

Sites and downloads for a site

Can either set to block or warn

Warn - Displays a warning to notify users of potential dangers associated with the site

Block - Web Control displays a message that the site is blocked and prevents the download

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How does Web Control work with Client Proxy?

A

If the ‘Disable if McAfee Client Proxy is detected’ option is selected, Web Control will be disabled if Client Proxy is redirecting

-When the client system is outside the internal network, Web Control is disabled and Client Proxy redirects
network traffic.

-When the client system moves from outside to inside the internal network, Client Proxy stops redirecting
and Web Control is reenabled.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How does Web Control work with a Web Gateway?

A

By configuring the ‘Use your organization’s default gateway’, ‘Detect web gateway enforcement’, or ‘Specify internal landmark to use’ settings, you can defer the enforcement of network traffic from web control to your web gateway

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How does the McAfee Team compile safety ratings for a site?

A

Automated tests compile safety ratings for a website by:
• Downloading files to check for viruses and potentially unwanted programs bundled with the download.
• Entering contact information into sign-up forms and checking for resulting spam or a high volume of
non-spam email sent by the site or its affiliates.
• Checking for excessive pop-up windows.
• Checking for attempts by the site to exploit browser vulnerabilities.
• Checking for deceptive or fraudulent practices employed by a site.

The team compiles test results into a safety report that can also include:
• Feedback submitted by site owners, which might include descriptions of safety precautions used by the site
or responses to user feedback about the site.
• Feedback submitted by site users, which might include reports of phishing scams or bad shopping
experiences.
• More analysis by McAfee experts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does Web Control handle file downloads?

A

Web Control checks the rating for the URL, then it performs a file reputation lookup on the file, and then assuming both of these check out, then the file is sent to Threat Prevention to be scanned. If the scan is clean, the file will be downloaded. Otherwise, it will be blocked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What information does Web Control send back to ePO?

A
  • Type of event initiated by the managed system (site visit or download)
  • Unique ID assigned to the managed system
  • Time
  • Domain
  • URL
  • Web Control rating for the event’s site
  • Whether the event’s site or site resource is on the Block and Allow List
  • Reason for action (allow, warn, or block) taken by the software
  • Observe mode status (on or off)
17
Q

How can users potentially circumvent policy settings for Web Control and hide their browsing behavior?

A

• Creating an application that browses the web.
• Creating a frame page to load websites in a frame.
• Disabling the plug-in from the Choose Add-ons pop-up window that Internet Explorer displays after
Web Control is installed.
• Disabling Web Control in Chrome or Firefox by managing add-ons or extensions in the browser.

18
Q

Is it safe to use Web Control as my only source of security against web-based threats?

A

No. Web Control tests many threats, and constantly adds new threats to its testing criteria, but it can’t
test for all threats. Users must continue to use traditional security defenses, such as virus and spyware
protection, intrusion prevention, and network access control.

19
Q

You think that certain users may be attempting to circumvent web control policy settings. How can you check to see if this is true?

A

Use queries that track browsing behavior and usage. Queries alert you when managed systems show
no browsing data or less browsing data than expected.

Check the compliance status of the client software using the Endpoint Security Web Control:
Compliance Status query. This query indicates when the software is disabled.

By setting up monitors that use the applicable queries, or frequently checking reports generated by
queries, you know when users circumvent policy settings. You can then take immediate steps to ensure
compliance.

20
Q

If Internet Explorer is the only browser installed on a managed system when Web Control is deployed,
must I redeploy the software after installing Firefox or Chrome?

A

No. Web Control detects both Firefox and Chrome when they are installed and immediately begins to
protect searching and browsing activities in that browser, while continuing to protect Internet Explorer.

21
Q

What are the recommended guidelines for creating a strategy?

A

1 Enable Observe mode and deploy the client software.
2 Evaluate browsing traffic and usage patterns (Reports).
3 Create policies.
4 Test and evaluate settings (Observe mode).
5 Ensure compliance, productivity, and security with frequent monitoring.

22
Q

What should you consider before configuring policies to make sure you configure web control in the way that is best for your organization?

A

• Assess the security concerns and vulnerabilities that apply to your business.
• Carefully consider any domains and sites that must be accessible to your managed systems and any sites to
block.
• Decide which network browsing activities to monitor.
• Determine your most effective and efficient forms of monitoring.

23
Q

What do the block and allows lists do?

A

• Allow indicates that users can always access the site, regardless of safety rating or content type.
• Block indicates that users can never access the site.
By default, if the same site appears as both blocked and allowed, the block action takes precedence. You can
configure a policy option for allowed sites to take priority.

24
Q

What is the function of site patterns?

A

The Block and Allow List policies use site patterns to specify a range of sites that are allowed or blocked. With
site patterns, you can allow or block a domain or a range of similar sites without entering each URL separately.

25
Q

How can Web Control use safety ratings to control access?

A

In the Content Actions settings, specify whether to allow, warn, or block sites and file downloads, based on the
safety rating.

26
Q

How can Web Control use web categories to control access?

A

McAfee defines categories for the types of content on websites. You can allow or block access to sites based on these categories.When you enable web category blocking in the Content Actions settings, the software blocks or allows categories of websites.

27
Q

What are the Web Control Policies categories?

A
Block and Allow List
Browser Control
Content Actions
Enforcement Messaging
Options
28
Q

What does Secure Search do?

A

Automatically filters the malicious sites in the search result based on their safety rating