Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exc65

Checkpoint firewalls provide logs to the McAfee SIEM Receiver in which of the following formats?

A.

Syslog

B.

open Platform for Security (OPSEC)

C.

McAfee Event Format (MEF)

D.

Common Event Format (CEF)

Which of the following are the three compression ratios available for raw logs being handled by the ELM?

A.

10:1,14:1.19:1

B.

14:1,18:1,20:1

C.

14:1,17:1.21:1

D.

14:1,17:1,20:1

If the maximum size for the Policy Change History log is reached, which of the following happens to new entries?

A.

No new entries are added to the log.

B.

A new log file is created and the old one is archived.

C.

The oldest entries will be deleted to make way for the new entries.

D.

The newest entries will be buffered until an Administrator creates a new log file.

The security Analyst notices that there has been a large spike for Secure Shell

A.

McAfee ePIocy Orchestrator (ePO)

B.

The core switch

C.

The external switch

D.

The firewall

Zones allow a user to group devices and the events they generate by

A.

Geographical location and IP reputation

B.

Geographical reputation and IP Address

C.

Geographical location and IP Address

D.

Geographical location and File reputation

On the McAfee enterprise Security Manager (ESM), the default data Retention setting specifies that Event and Flow data should be maintained for

A.

365 days.

B.

same value as configured on the ELM.

C.

90 Days

D.

all data allowed by system

A backup of the ELM management database captures

A.

ELM configuration settings

B.

ELM configuration settings, and the ELM archive index

C.

ELM configuration settings, the ELM archive index, and all archived ELM contents.

D.

ELM configuration settings, the ELM archive index, and all archived ELM contents up to the ESM database retention limit.

The fundamental purpose of the Receiver Correlation Subsystem (RCS) is

A.

to analyze data from the ESM and detect matching patterns.

B.

to collect and consolidate identical data from the ESM into a single summary event.

C.

to classify or categorize data from the Receiver into related types and sub-types.

D.

to organize, retrieve and archive data from the Receiver into the SIEM database.

Which of the following is the Primary function of the Event Receiver (ERC) in relation to the Enterprise Security Manager (ESM)?

A.

Collect and parse events before the ESM pulls them form the ERC

B.

Collect and parse the events before the receiver forwards them to the ESM

C.

Collect and store the events before they are forwarded to the ESM for parsing

D.

Collect and parse the events before forwarding them to the ELM

Which of the following is the name of the Dashboard View that shows correlated events for the selected Data Source?

A.

Default Summary

B.

Normalized Dashboard

C.

Incidents Dashboard

D.

Triggered Alarms