Month End Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which options within the Receiver properties should be selected to configure the device to respond to ICMP echo requests?

A.

Receiver ManagementAUpdate Device

B.

Receiver Configuration\lnterface

C.

Connedion\Status

D.

Key Management Key Device

The possibility of both data source Network Interface Cards (NICs) using the shared IP and MAC address at the same time is eliminated by using which of the following?

A.

iSCSI Adapter

B.

iPMICard

C.

PCI Adapter

D.

SAN Card

Which of the following are the Boolean logic functions that can be used to create Correlation Rules?

A.

NOR and AND

B.

AND and SET

C.

ORandSET

D.

OR and AND

The McAfee Enterprise Log Manager (ELM) offers three levels of compression (Low, Medium, and High). By default, the ELM compression level is set to Low. Which of compression (Low, Medium, and High). By default, the ELM compression level is set to Low. Which of the following is the compression ratio for the Medium level?

A.

17:1

B.

20:1

C.

10:1

D.

14:1

What Firewall component is natively used by the McAfee SIEM appliances to protect the appliances from unauthorized communications?

A.

Iptables

B.

McAfee Host Intrusion Prevention System (HIPS)

C.

Linux Firewall

D.

Access Control List (ACL)

With regard to Data Source configuration and event collection what does the acronym CEF stand for?

A.

Correlation Event Framing

B.

Common Event Format

C.

Common Event Framing

D.

Condition Event Format

Be default, events in McAfee SIEM are aggregated on which of the following three fields?

A.

Signature ID, Source IP, Source Port

B.

Signature ID, Source IP, Destination IP

C.

Signature ID, Destination IP, Source User

D.

Signature ID, Event ID, Source IP

Flow Aggregation is based on which of the following?

A.

Source IP, Source Port, Destination IP

B.

Source IP, Destination IP, Source User ID

C.

Source IP, Destination Port, Host ID

D.

Source IP, Destination IP, Destination Port

When displaying baseline averages using the automatic time range option, baseline data is correlated by using the same time period that is being used for the current query for which of the following past number of intervals?

A.

Three

B.

Seven

C.

Five

D.

Ten

The normalization value assigned to each data-source event allows

A.

increased usability via views based on category rather than signature ID

B.

more efficient parsing of each event by the McAfee SIEM Receiver.

C.

quicker ELM searches

D.

the McAfee ESM database to retain fewer events overall.