ANNEX D: SECURITY (HBSS + ACAS)
QUESTIONS AND CORRECT ANSWERS
SecurityA2TechnicalA2InformationA2GuideA2(STIG)A2-A2Ans--
AA2carefullyA2craftedA2documentA2thatA2includesA2notA2onlyA2DoDA2policiesA2andA2security
A2regulations,A2butA2alsoA2up-
todateA2bestA2practicesA2andA2configurationA2guidelines.A2TheseA2guidelinesA2areA2usedA2
forA2securingA2aA2specificA2systemA2orA2applicationA2inA2accordanceA2withA2DoDA2require
ments.
Host-BasedA2SecurityA2SystemsA2(HBSS)A2-A2Ans--
AA2hostA2basedA2securityA2system,A2whichA2meansA2itA2isA2locatedA2onA2theA2individualA2w
orkstationA2orA2theA2host.A2UsesA2multipleA2differentA2modulesA2toA2monitor,A2detect,A2and
A2counterA2againstA2knownA2cyberA2threats.
AssuredA2ComplianceA2AssessmentA2SolutionA2(ACAS)A2-A2Ans--
ConsistsA2ofA2aA2suiteA2ofA2productsA2toA2includeA2RedA2HatA2EnterpriseA2Linux,A2Security
A2Center,A2NessusA2ScannerA2andA2theA2NessusA2NetworkA2MonitorA2(formerlyA2theA2Pas
siveA2VulnerabilityA2Scanner)A2whichA2isA2providedA2byA2DISAA2toA2DoDA2Customers.
PublicA2KeyA2InfrastructureA2(PKI)A2-A2Ans--
AA2frameworkA2thatA2consistsA2ofA2hardware,A2software,A2people,A2processes,A2andA2polic
ies,A2thatA2togetherA2helpsA2identifyA2andA2solveA2informationA2securityA2problemsA2forA2y
ouA2byA2establishingA2safeA2andA2reliableA2environmentA2forA2electronicA2transactionsA2inA
2theA2internet.
PublicA2KeyA2EncryptionA2-A2Ans--
ProtectsA2theA2confidentiality,A2integrity,A2authenticityA2andA2non-repudiationA2ofA2data.
WhyA2doA2weA2useA2HBSSA2-A2Ans--
USA2CyberA2CommandA2(USCYBERCOM)A2mandatesA2thatA2HBSSA2beA2installedA2onA2e
veryA2DoDA2system.
HBSSA2ComponentsA2-A2Ans--
ePolicyA2OrchestratorA2Server,A2theA2McAfeeA2Agent,A2theA2distributedA2repositories,A2an
dA2theA2registeredA2servers.
McAfeeA2AgentA2-A2Ans--
ItsA2jobA2isA2toA2provideA2aA2secureA2communicationA2channelA2toA2theA2ePOA2andA2mana
gesA2allA2ofA2theA2otherA2modulesA2thatA2willA2beA2installedA2onA2theA2clientA2machineA2(VS
E,A2HIPS,A2etc.).
, AgentA2toA2ServerA2CommunicationA2IntervalA2(ASCI)A2-A2Ans--
DeterminesA2howA2oftenA2theA2agentA2checksA2inA2withA2theA2ePO.A2DefaultA2isA260A2minu
tes.
AgentA2toA2ServerA2CommunicationA2(ASCI)A2-A2Ans--
EncryptedA2communicationA2usingA2SecureA2SocketsA2LayerA2(SSL)A2orA2TransportA2Lay
erA2SecurityA2(TLS).A2AllA2encryptionA2isA2128-
bitA2strengthA2and,A2exceptA2forA2MacA2OSA2X,A2isA2FIPSA2140-2A2compliant.
Wake-upA2callsA2-A2Ans--
WhenA2theA2ePOA2forcesA2theA2managedA2machineA2toA2initiateA2anA2ASCIA2outsideA2ofA2i
tsA2normalA2interval.
ACASA2RepositoriesA2-A2Ans--
ProprietaryA2dataA2files,A2residingA2onA2theA2securityA2center,A2thatA2storeA2scanA2results.A
2EveryA2timeA2aA2scanA2isA2initiated,A2theA2scanA2resultsA2areA2importedA2intoA2oneA2reposi
tory.
ACASA2RepositoryA2TypesA2-A2Ans--Local,A2Remote,A2andA2OfflineA2Repositories
LocalA2RepositoryA2-A2Ans--
ActiveA2repositoriesA2ofA2SecurityA2CenterA2dataA2collectedA2viaA2scannersA2attachedA2toA
2theA2localA2SecurityA2Center.
RemoteA2RepositoryA2-A2Ans--
ContainA2IPA2addressA2andA2vulnerabilityA2informationA2obtainedA2viaA2networkA2synchron
izationA2withA2aA2secondA2(remote)A2SecurityA2Center.
OfflineA2RepositoryA2-A2Ans--
EnableA2SecurityA2CenterA2toA2obtainA2repositoryA2dataA2viaA2manualA2fileA2export/
importA2fromA2aA2remoteA2SecurityA2CenterA2thatA2isA2notA2network-accessible.
AuditA2FilesA2-A2Ans--
TextA2filesA2thatA2containA2theA2specificA2configuration,A2fileA2permission,A2andA2accessA2c
ontrolA2testsA2toA2beA2performed.A2TheyA2areA2anA2attachmentA2toA2aA2scanA2policyA2used
A2withA2credentialsA2toA2auditA2aA2host'sA2configuration.
PublicA2KeyA2InfrastructureA2(PKI)A2-A2Ans--
AA2frameworkA2thatA2consistsA2ofA2hardware,A2software,A2people,A2processes,A2andA2polic
ies,A2thatA2togetherA2helpsA2identifyA2andA2solveA2informationA2securityA2problemsA2forA2y
ouA2byA2establishingA2safeA2andA2reliableA2environmentA2forA2electronicA2transactionsA2inA
2theA2internet.
ImportanceA2ofA2PKIA2-A2Ans--
AllowsA2usA2toA2takeA2advantageA2ofA2theA2speedA2andA2immediacyA2ofA2theA2InternetA2wh
QUESTIONS AND CORRECT ANSWERS
SecurityA2TechnicalA2InformationA2GuideA2(STIG)A2-A2Ans--
AA2carefullyA2craftedA2documentA2thatA2includesA2notA2onlyA2DoDA2policiesA2andA2security
A2regulations,A2butA2alsoA2up-
todateA2bestA2practicesA2andA2configurationA2guidelines.A2TheseA2guidelinesA2areA2usedA2
forA2securingA2aA2specificA2systemA2orA2applicationA2inA2accordanceA2withA2DoDA2require
ments.
Host-BasedA2SecurityA2SystemsA2(HBSS)A2-A2Ans--
AA2hostA2basedA2securityA2system,A2whichA2meansA2itA2isA2locatedA2onA2theA2individualA2w
orkstationA2orA2theA2host.A2UsesA2multipleA2differentA2modulesA2toA2monitor,A2detect,A2and
A2counterA2againstA2knownA2cyberA2threats.
AssuredA2ComplianceA2AssessmentA2SolutionA2(ACAS)A2-A2Ans--
ConsistsA2ofA2aA2suiteA2ofA2productsA2toA2includeA2RedA2HatA2EnterpriseA2Linux,A2Security
A2Center,A2NessusA2ScannerA2andA2theA2NessusA2NetworkA2MonitorA2(formerlyA2theA2Pas
siveA2VulnerabilityA2Scanner)A2whichA2isA2providedA2byA2DISAA2toA2DoDA2Customers.
PublicA2KeyA2InfrastructureA2(PKI)A2-A2Ans--
AA2frameworkA2thatA2consistsA2ofA2hardware,A2software,A2people,A2processes,A2andA2polic
ies,A2thatA2togetherA2helpsA2identifyA2andA2solveA2informationA2securityA2problemsA2forA2y
ouA2byA2establishingA2safeA2andA2reliableA2environmentA2forA2electronicA2transactionsA2inA
2theA2internet.
PublicA2KeyA2EncryptionA2-A2Ans--
ProtectsA2theA2confidentiality,A2integrity,A2authenticityA2andA2non-repudiationA2ofA2data.
WhyA2doA2weA2useA2HBSSA2-A2Ans--
USA2CyberA2CommandA2(USCYBERCOM)A2mandatesA2thatA2HBSSA2beA2installedA2onA2e
veryA2DoDA2system.
HBSSA2ComponentsA2-A2Ans--
ePolicyA2OrchestratorA2Server,A2theA2McAfeeA2Agent,A2theA2distributedA2repositories,A2an
dA2theA2registeredA2servers.
McAfeeA2AgentA2-A2Ans--
ItsA2jobA2isA2toA2provideA2aA2secureA2communicationA2channelA2toA2theA2ePOA2andA2mana
gesA2allA2ofA2theA2otherA2modulesA2thatA2willA2beA2installedA2onA2theA2clientA2machineA2(VS
E,A2HIPS,A2etc.).
, AgentA2toA2ServerA2CommunicationA2IntervalA2(ASCI)A2-A2Ans--
DeterminesA2howA2oftenA2theA2agentA2checksA2inA2withA2theA2ePO.A2DefaultA2isA260A2minu
tes.
AgentA2toA2ServerA2CommunicationA2(ASCI)A2-A2Ans--
EncryptedA2communicationA2usingA2SecureA2SocketsA2LayerA2(SSL)A2orA2TransportA2Lay
erA2SecurityA2(TLS).A2AllA2encryptionA2isA2128-
bitA2strengthA2and,A2exceptA2forA2MacA2OSA2X,A2isA2FIPSA2140-2A2compliant.
Wake-upA2callsA2-A2Ans--
WhenA2theA2ePOA2forcesA2theA2managedA2machineA2toA2initiateA2anA2ASCIA2outsideA2ofA2i
tsA2normalA2interval.
ACASA2RepositoriesA2-A2Ans--
ProprietaryA2dataA2files,A2residingA2onA2theA2securityA2center,A2thatA2storeA2scanA2results.A
2EveryA2timeA2aA2scanA2isA2initiated,A2theA2scanA2resultsA2areA2importedA2intoA2oneA2reposi
tory.
ACASA2RepositoryA2TypesA2-A2Ans--Local,A2Remote,A2andA2OfflineA2Repositories
LocalA2RepositoryA2-A2Ans--
ActiveA2repositoriesA2ofA2SecurityA2CenterA2dataA2collectedA2viaA2scannersA2attachedA2toA
2theA2localA2SecurityA2Center.
RemoteA2RepositoryA2-A2Ans--
ContainA2IPA2addressA2andA2vulnerabilityA2informationA2obtainedA2viaA2networkA2synchron
izationA2withA2aA2secondA2(remote)A2SecurityA2Center.
OfflineA2RepositoryA2-A2Ans--
EnableA2SecurityA2CenterA2toA2obtainA2repositoryA2dataA2viaA2manualA2fileA2export/
importA2fromA2aA2remoteA2SecurityA2CenterA2thatA2isA2notA2network-accessible.
AuditA2FilesA2-A2Ans--
TextA2filesA2thatA2containA2theA2specificA2configuration,A2fileA2permission,A2andA2accessA2c
ontrolA2testsA2toA2beA2performed.A2TheyA2areA2anA2attachmentA2toA2aA2scanA2policyA2used
A2withA2credentialsA2toA2auditA2aA2host'sA2configuration.
PublicA2KeyA2InfrastructureA2(PKI)A2-A2Ans--
AA2frameworkA2thatA2consistsA2ofA2hardware,A2software,A2people,A2processes,A2andA2polic
ies,A2thatA2togetherA2helpsA2identifyA2andA2solveA2informationA2securityA2problemsA2forA2y
ouA2byA2establishingA2safeA2andA2reliableA2environmentA2forA2electronicA2transactionsA2inA
2theA2internet.
ImportanceA2ofA2PKIA2-A2Ans--
AllowsA2usA2toA2takeA2advantageA2ofA2theA2speedA2andA2immediacyA2ofA2theA2InternetA2wh