|
Enterprise DLP returns the previously cached verdict in DLP
Incidents () when traffic matches the same Endpoint DLP
policy rule if Optical Character Recognition (OCR) () is first disabled and then enabled, or vice
versa.
For example, you have Policy Rule A
Action configured to Alert when traffic
containing sensitive data is detected. You also have OCR
disabled. Traffic is evaluated against Policy Rule
A and not sensitive data is detected so Enterprise DLP returns a Scan Not Match verdict.
Later you change the Action for Policy Rule
A to Block and enable
OCR. Traffic is again evaluated against Policy
Rule A but sensitive data is detected. In
this case, the DLP Incident erroneously displays the verdict as
Scan Not Match.
|