▸case-18 When Proofpoint TAP attachment sandboxing returns a confirmed malicious verdict for an incoming email file, an engineer suggests leaving the email in the user's inbox with an updated subject line header. What policy action should be configured for confirmed malicious verdicts? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-17 When multiple employees receive distinct phishing emails that share infrastructure or payload patterns, our SOC team spends hours correlating them manually. How does Proofpoint TAP handle grouping related individual attack instances? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-16 Our corporate legal department uses a trusted third-party e-signature portal that breaks when links in their emails are rewritten by Proofpoint URL Defense. How should this trusted domain exception be configured in URL Defense? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-08 We are configuring Proofpoint URL Defense for inbound email. A consultant advised us to scan links only during original email ingestion to save click-time processing overhead. How should URL evaluation timing be configured to catch late-weaponized phishing links? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-03 I am tasked with hardening our email gateway using Proofpoint sandboxing features. Could you supply a comprehensive configuration summary outlining attachment handling rules, handling of encrypted payloads, alert settings for highly targeted employees, and post-implementation validation steps? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-22 We are configuring Microsoft Defender for Office 365 Safe Attachments policies in the Microsoft Defender portal (security.microsoft.com). Should we set the Safe Attachments policy response to 'Block', 'Replace', or 'Dynamic Delivery' within Exchange Online protection? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-09 Our CISO wants to identify which specific employees in our organization are receiving the highest volume of targeted attacks so we can apply stricter MFA and security awareness policies to them. What feature within Proofpoint TAP provides this specific user-centric visibility? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-19 Our threat intelligence team wants to know what underlying intelligence database and AI engine powers Proofpoint TAP's predictive analysis and threat scoring across global email traffic. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-01 We are rolling out Proofpoint Targeted Attack Protection across our organization and need a recommended policy outline for processing file attachments. Please provide a structured strategy detailing how different categories of incoming file types should be routed—such as which extensions require active detonation versus immediate blocking—and how password-protected archives or delayed delivery should be handled. | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-04 We are setting up attachment handling rules in Proofpoint TAP. Most security guides suggest sending all executable and script files like .bat, .cmd, .js, and .ps1 to the sandbox for dynamic analysis so we can observe their payload execution. Should we detonate these script files in the sandbox or handle them differently? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-14 To validate our Proofpoint URL Defense deployment, our testing team wants to send a plain text email containing a link to google.com and check if it gets blocked. How should URL Defense rewriting and blocking be accurately validated? | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-21 Our compliance officer wants us to create an outbound Data Loss Prevention (DLP) rule to scan outgoing emails for 16-digit credit card numbers using regular expressions and block messages that contain unencrypted PCI data. How should PCI DSS credit card regex rules be structured for email DLP? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-15 Our SOC manager wants daily operational visibility into threats caught by Proofpoint TAP without requiring analysts to log into the Threat Insight dashboard every morning. What automated notification mechanism should be configured? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-02 Our security operations team needs an end-to-end deployment guide for establishing Proofpoint TAP email controls. Please draft a phased technical workflow covering initial policy activation, link rewriting and click-time evaluation rules, threat dashboard oversight, and SIEM logging integration. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-10 When configuring sandbox detonation profiles in Proofpoint TAP, an engineer suggests only sending .exe files to the virtual machines and allowing all document and archive formats through to save sandbox capacity. Which file extensions should be included in the dynamic detonation policy? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-06 Our executives complain that email sandboxing delays message delivery by several minutes while attachments detonate. They want us to hold the entire email until the attachment is cleared, but end users are missing meeting invites. How should message body and attachment delivery be configured to balance security with delivery speed? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-05 When password-protected zip files arrive in inbound email, our security team usually quarantines them immediately to eliminate any risk of encrypted malware slipping past inspection. Is this the recommended workflow in Proofpoint TAP, or should an intermediate decryption step be attempted first? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-20 We need to publish DMARC, SPF, and DKIM records in DNS for our primary email domain to prevent spoofing. Should we publish an SPF record with `v=spf1 include:_spf.proofpoint.com ~all` and set the DMARC policy to `p=reject` directly in public DNS? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-12 When setting up Proofpoint TAP attachment sandboxing, an admin asks whether sandbox detonation is limited strictly to Windows virtual machine environments or if multiple operating system environments are supported. | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-07 In Proofpoint URL Defense, when a link is evaluated at time-of-click and found to be suspicious—but not definitively confirmed as malicious—our analyst suggests outright blocking access to avoid any risk. Is blocking the standard action for suspicious URLs, or what response action should be shown to the user? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-11 We need to integrate Proofpoint TAP threat events into our enterprise SIEM for automated SOC triage. What export mechanism and protocol should be configured between TAP and the SIEM platform? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
▸case-13 After completing the Proofpoint TAP installation, our QA team wants to verify that the attachment sandboxing engine is functioning properly. They plan to send a standard plain text file containing benign words. What standard test file and document types should be used to validate attachment detonation? | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |