Answers
1. CND Services include Prepare; Attack
Protect and Remediate
Respond
Diagnose
-Respond
2. What action should be taken if Ignore It
an event is found to be a false Start the tuning process
positive? Call the helpdesk
Open a ticket with DISA
-Start the tuning process
3. Which product is responsible McAfee VirusScan
for collecting endpoint proper- McAfee HIPS
ties and policy enforcement? McAfee Agent
ACCM
-McAfee Agent
4. What is the correct order for Severity; Action Taken; Volume
prioritizing events? Action Taken; Severity; Volume
Volume; Severity; Action Taken
Severity; Volume; Action Taken
-Severity; Action Taken; Volume
5. An admin creates to Rules
manage the software installed Policies
on the endpoint. Groups
Client tasks
, -Policies
6. Which HIPS label shows the Threat Name
friendly name of a HIPS event? Signature Name (Host IPS)
Param value
Product name
-Signature Name (Host IPS)
7. Which of the following is not Correlation
true about ArcSight and situa- Monitoring
tional awareness? Analysis
Prevention
-Prevention
8. In order to manage an end- McAfee Agent
point; must be in- McAfee HIPS
stalled. McAfee VirusScan Enterprise
McAfee RSD
-McAfee Agent
9. A dashboard is a collection of Monitors
shown together in Reports
the same location. Charts
Lists
-Reports
10. Which VSE label shows the Threat Name
friendly name of a VSE event? Signature Name (Host IPS)
Param Value
2/5