How Does Data at Rest Scanning Work?
Endpoint DLP data at rest scanning discovers sensitive data stored on managed
endpoints. You can identify improperly stored or unsecured sensitive information,
such as personal data, financial records, and intellectual property, that increases
your risk of data breaches and regulatory noncompliance with GDPR, HIPAA, and
PCI-DSS.
Prisma Agent uses delta scanning after the initial full scan,
inspecting only files created or modified since the last scan. Prisma Agent crawls the folder paths you configured, discovers files,
and ignores symbolic links. Prisma Agent also monitors file system
events to track file creations, modifications, and deletions. Each scan verdict
expires after 90 days, at which point Prisma Agent automatically
rescans the file regardless of whether the content changed.
When a scan identifies sensitive data that matches your data profiles,
Enterprise DLP generates a DLP incident that you can investigate and remediate
through the centralized incident management workflow in
Strata Cloud Manager. You
can view scan results for all discovered assets in the
Data
Asset Explorer, including matched data profiles, scan policies, and last
scan times for each asset. If the endpoint is offline during a scan,
Prisma Agent queues incidents locally and sends them to
Enterprise DLP when connectivity is restored.
Data at rest scanning runs as a low-priority background process on the endpoint.
Prisma Agent defers scanning when endpoint CPU usage is high and
resumes only when CPU usage drops, without impacting endpoint performance during
active use.
Data at rest scanning uses the local detection engine, which supports regex-based
data patterns and OCR detection. Classifiers that require cloud infrastructure,
such as ML, EDM, IDM, and trainable classifiers, aren't supported for data at
rest scans.