Web Control Flashcards
Give a high level description of the Web Control module.
Web Control is a Browser Protection solution that monitors web searching and browsing activity on client computers, and protects against threats on web pages and in file downloads
What are the “Protect” Features of Web Control?
Block and Allow List - Prevent users from visiting specific URLs or domains, or always allow access to sites that are important to your business
Rating Actions and Web Category Blocking - Use safety ratings and web categories defined by McAfee to control user access to sites, pages, and downloads
Secure Search - Automatically block risky sites from appearing in search results based on their safety rating
Self Protection - Prevents users from disabling the Web Control plug-in or uninstalling or changing Web Control files, registry keys, registry values, services, and processes
What are the “Detect” features of Web Control?
- Web Control button in the browser window - The Web Control plug-in displays a button indicating the safety rating for the site. Click the button for more information about the site.
- Web Control icon on search results pages - An icon appears next to each listed site. The color of the icon indicates the safety rating for the site. Hover over the icon for more information about the site.
- Site Reports - Details show how the safety rating was calculated based on types of threats detected, test results, and other data.
- Dashboards and monitors - Display statistics about Web Control activity, including visits and downloads from sites by rating, content type, and blocked or allowed list.
- Queries and Reports - retrieve detailed information about Web Control browser events, and save it in reports
What are the “Correct” features of Web Control?
Interlock with other McAfee products - Disable Web Control automatically if it detects a web gateway appliance or if McAfee Client Proxy
File scanning for file downloads - Web control sends files to Threat Prevention for scanning. If it detects a threat, Threat Prevention responds with the configured action such as clean, and alerts the user
Dashboard and monitors - Monitor activity to understand browsing activity, then use that information to tune Web Control settings
Exclusions - Prevent Web Control from rating or blocking specific IP addresses
Where does Web Control get the reputation information to determine how to handle navigation to URLs
GTI
What browsers does Web Control support?
- Internet Explorer 11
- Chrome
- Firefox
- Firefox ESR
- Safari
(Doesn’t support Microsoft Edge)
What are the different color coded buttons and what do they signify?
Green Secure - Site is tested daily and certified safe by McAfee Secure
Green -This site is safe.
Yellow - This site might have some issues.
Red - This site has some serious issues.
Grey - No rating is available for this site.
This button appears for FILE (file://) protocol URLs.
Orange - A communication error occurred with the McAfee GTI server that
contains rating information.
Blue - Web Control didn’t query McAfee GTI for this site, which indicates that the site is internal or in a private IP address range.
Black - This site is a phishing site
White - A setting allows this site
Gray translucent - A setting disabled web control
What do search result icons signify?
Check mark - Tests revealed no significant problems
Exclamation Point - Tests revealed some issues that users might need to know about. For example, the site tried to change the testers’ browser defaults, displayed pop-ups, or sent testers a significant amount of non-spam email.
Red X - Tests revealed some serious issues that users must consider carefully before accessing this site. For
example, the site sent testers spam email or bundled adware with a download.
Caution Symbol - A Web Control setting blocked this site.
Question Mark - This site is unrated.
What feature in Web control allows you to view more details about a site?
Site report
What details do site reports reveal?
An Overview of a website
Online Affiliations
Web Spam Test
Download Test
What can Web Control set rating actions for?
Sites and downloads for a site
Can either set to block or warn
Warn - Displays a warning to notify users of potential dangers associated with the site
Block - Web Control displays a message that the site is blocked and prevents the download
How does Web Control work with Client Proxy?
If the ‘Disable if McAfee Client Proxy is detected’ option is selected, Web Control will be disabled if Client Proxy is redirecting
-When the client system is outside the internal network, Web Control is disabled and Client Proxy redirects
network traffic.
-When the client system moves from outside to inside the internal network, Client Proxy stops redirecting
and Web Control is reenabled.
How does Web Control work with a Web Gateway?
By configuring the ‘Use your organization’s default gateway’, ‘Detect web gateway enforcement’, or ‘Specify internal landmark to use’ settings, you can defer the enforcement of network traffic from web control to your web gateway
How does the McAfee Team compile safety ratings for a site?
Automated tests compile safety ratings for a website by:
• Downloading files to check for viruses and potentially unwanted programs bundled with the download.
• Entering contact information into sign-up forms and checking for resulting spam or a high volume of
non-spam email sent by the site or its affiliates.
• Checking for excessive pop-up windows.
• Checking for attempts by the site to exploit browser vulnerabilities.
• Checking for deceptive or fraudulent practices employed by a site.
The team compiles test results into a safety report that can also include:
• Feedback submitted by site owners, which might include descriptions of safety precautions used by the site
or responses to user feedback about the site.
• Feedback submitted by site users, which might include reports of phishing scams or bad shopping
experiences.
• More analysis by McAfee experts.
How does Web Control handle file downloads?
Web Control checks the rating for the URL, then it performs a file reputation lookup on the file, and then assuming both of these check out, then the file is sent to Threat Prevention to be scanned. If the scan is clean, the file will be downloaded. Otherwise, it will be blocked