Is there any method or example to help determine false positives and potential ransomware attacks?
Applies to
- ONTAP 9
- Autonomous Ransomware Protection (ARP)
Answer
- No, NetApp does not provide concrete examples for making such determinations.
- When evaluating whether a detection is a
false positiveor apotential ransomware attack, the final judgment must be made by the customer, based on their specific environment and context. - The basic approach involves manually inspecting each affected file or using security tools to assist in the analysis.
- Additionally, a broader assessment can be made by considering factors such as the file’s location, intended use, and file type.
Additional Information
additionalInformation_text
