Audit Fix FAQ
Why are PAF scripts imported into CAR with an Approved status?
Policy Audit Fix (PAF) remediation scripts are Qualys-provided and pre-validated. When imported into CAR, they are automatically assigned an Approved status because they originate from the trusted PAF script library.
Unlike custom scripts created by users, PAF scripts do not require manual review or approval before they can be used in remediation jobs.
How can I determine whether PAF is remediating controls on a host?
Policy Audit Fix (PAF) does not automatically remediate controls on any host. Remediation occurs only when a user creates and executes a remediation job.
To verify whether remediation is occurring:
- Check the Audit Fix page for jobs targeting the host.
- Review the status of remediation jobs to determine whether they are running, completed, or failed.
- Review the updated compliance report after the remediation job is executed to confirm if the targeted controls are remediated.
If no remediation job has been created or executed for a host, PAF is not performing any remediation on that host.
Does enabling PAF and importing scripts into CAR automatically remediate controls on a host?
No. Enabling Policy Audit Fix (PAF) and importing remediation scripts into CAR are prerequisite steps that prepare a host for remediation, but they do not trigger remediation automatically.
To remediate controls, you must:
- Create a remediation job.
- Select the controls or policies to remediate.
- Select the target hosts.
- Schedule or execute the remediation job.
If scripts are in the Approved state and PAF is enabled on a host, is remediation automatically executed?
No. An Approved status indicates that a remediation script is authorized and available for use. Similarly, enabling PAF on a host makes the host eligible for remediation.
Neither action initiates remediation. Remediation occurs only when a user explicitly creates and executes a remediation job that targets the host.