Choose a policy to use for your scan. Policies are located in the directory defined above or in the default directory used by ZAP. If no policies are available, it will use a default policy (attack strength and alert threshold defined to MEDIUM).