
13 What happens if a security VM detects a threat
If a security VM detects a threat on one of the guest VMs, it sends an alert to Enterprise Console.
Specifically:
■
An alert is displayed on the dashboard.
■
A red warning icon is displayed in the computer list, on the Status tab, next to the security VM
in the Alerts and errors column.
If the security VM detects a threat when a user tries to access a file, a message may also be displayed
on the guest VM informing the user that the file cannot be accessed, although this depends on the
application used to access the file.
14 Deal with a threat
To deal with a threat that a security VM has detected:
■
Find out more about the threat and how to deal with it.
■
Clean up a guest VM.
■
Clear the alert from Enterprise Console.
The following sections guide you through the process.
14.1 Find out about the threat
To find out more about the threat and how to deal with it:
1. In Enterprise Console, in the computer list in the lower right part of the window, double-click
the security VM to display the Computer details dialog box.
In the History section, Items detected are listed. The name of the threat is shown in the Name
column and the affected guest VM and file are shown in the Details column.
2. Click the name of the threat.
This connects you to the Sophos website, where you can read a description of the item and
advice on what actions to take against it.
You are ready to deal with the threat using one of the methods described in the next section.
25
startup guide
Comentarios a estos manuales