Threat Prevention supports different scan processes (Standard, High Risk, and Low Risk) for on-access scanning.
These scan processes help achieve a balance between the security and performance impact of scanning. You can either use the Standard scan settings for all processes, or use high-risk, or low-risk processes. You can configure the scan settings depending on the process or program through which a file is accessed. If a process or program doesn't fall under these categories, Threat Prevention applies the standard process settings for scanning.
Standard process — Apply the standard scan settings when performing an on-access scanning.
High Risk — Identify the high risk process and configure its scan policy. For example, you can add the browser as a high risk process and set its scan policy to scan when it downloads a file.
Low Risk — Identify the low risk process and configure its scan policy. For example, you can add the XCode app as a low risk process and set its scan policy to Do not scan. The software does not scan when you use XCode.