The analyst has created a correlation rule to correlate events from Anti-Virus (AV>, Network Intrusion Prevention (NIPS) and the firewall. While reviewing just firewall events, the analyst notices a large spike in outbound Command and Control traffic, however, the correlation rule is not triggering The analyst then looks at the Network IPS and the Anti-Virus views and notices there are no alerts for this traffic. Which of the following features of NIPS and AV are most likely turned off?
An organization notices an increasing number of ESM concurrent connection events. To mitigate risks related to concurrent sessions which action should the organization take?
Which of the following is the minimum number of CPUs required to build a virtual image Enterprise Security Manager (ESM)?
Which of the following ports is the correct choice for use when configuring the database properties of a McAfee Network Security Platform (NSP) Device Data Source?
What Firewall component is natively used by the McAfee SIEM appliances to protect the appliances from unauthorized communications?
Which of the following operations is NOT an available selection when using Multi-Device Management?
In the Default Summary view on the Enterprise Security manager (ESM). which of the following panels shows the baseline averages?
The McAfee Advanced Correlation Engine (ACE) can t>e deployed in one of two modes which are.?
Which authentication methods can be configured to control alarm management privileges?
The historical ACE function allows the user to perform retrospective correlations on older data. In which of the following devices is the data located that the historical correlation engine uses?
One or more storage allocations, which together specify a total amount of storage, coupled with a data retention time that specifies the maximum number of days a log is to be stored, is known as a
With regard to Data Source configuration and event collection what does the acronym CEF stand for?
When viewing the Policy Tree, what four columns are displayed within the Rules Display pane?
When displaying baseline averages using the automatic time range option, baseline data is correlated by using the same time period that is being used for the current query for which of the following past number of intervals?
Which options within the Receiver properties should be selected to configure the device to respond to ICMP echo requests?