Weekend Sale - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

Which device index file should you use to create new meta keys?

A.

index-user, xml

B.

index-default xml

C.

index- xml

D.

index--custom xml

Which of the following choices is defined as being a delineated set of network data units that comprise a transaction from start to finish'?

A.

Frame

B.

Packet

C.

Session

D.

Token

The Reporting Engine is located on which device?

A.

Decoder

B.

Concentrator

C.

ESA

D.

NetWitness Server

What is the main purpose of creating a meta group?

A.

Isolate log data

B.

Perform Visualization analysis

C.

Eliminate unneeded keys

D.

Increase the amount of data available for analysis

Which of the following can NOT be configured as a data source for the Reporting Engine?

A.

Broker

B.

Concentrator

C.

Archiver

D.

ESA

Which step happens first in the RSA NetWitness data flow on the Packet Decoder when the capture interface is set to packet_mmap_"?

A.

Feeds evaluated

B.

Network rules evaluated

C.

Application rules evaluated

D.

Berkeley Packet Filter evaluated

To report on matches in the NWDB against a series of fixed values, include which feature in your report definition?

A.

An Application Rule

B.

A List

C.

An Enrichment Source

D.

A Subscription

To enable reporting alerts to be sent to the Respond interface, you would

A.

set up an output action in the Report Engine configuration

B.

change the capture interface in Reporting sources

C.

configure forwarding of alerts in the Reporting Engine configuration

D.

set up an output action in a Report

Administrators can use the Profile feature to limit views with (Choose three)

A.

Meta groups

B.

Custom column groups

C.

Assigned pre-queries

D.

Automated role assignment

E.

Data privacy policies

F.

List view

The RSA NetWitness Reporting Engine provides visibility into captured data via which of the following mechanisms?

A.

static and/or dynamic analysis

B.

alerts, reports and charts

C.

community and/or sandbox analysis

D.

ad hoc, schedules, and/or auto-run features