Labour Day Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: scxmas70

MA0-104 Exam Dumps - Intel Security Certified Product Specialist

Question # 4

The security Analyst notices that there has been a large spike for Secure Shell

A.

McAfee ePIocy Orchestrator (ePO)

B.

The core switch

C.

The external switch

D.

The firewall

Full Access
Question # 5

An organization notices an increasing number of ESM concurrent connection events. To mitigate risks related to concurrent sessions which action should the organization take?

A.

Increase the concurrent session alarm threshold

B.

Decrease the console timeout value

C.

Increase the number of the concurrent sessions allowed

D.

Customize the login page with the organization's logo

Full Access
Question # 6

The Database Event Monitor (DEM) appliance prevents disclosure of Personally Identifiable Information (Pll) by employing which of the following features to those types of information?

A.

Obfuscation masks

B.

Pll filter masks

C.

Sensitive data masks

D.

Filter masks

Full Access
Question # 7

When the automated system backup is configured to include events, flows and log data, the first backup will capture all events, flows and logs

 

A.

in the ESM database.

B.

in the ESM database older than what is currently held in the Receivers.

C.

inserted in the ESM database on the most recent Receiver poll.

D.

in the ESM database from the current day.

Full Access
Question # 8

A SIEM allows an organization the ability to correlate seemingly disparate streams of traffic into a central console for analysis. This correlation, in many cases, can point out activities that might otherwise go undetected This type of detection is also known as

A.

anomaly based detection

B.

behavioral based detection.

C.

heuristic based detection.

D.

signature based detection

Full Access
Question # 9

Which of the following is the minimum number of CPUs required to build a virtual image Enterprise Security Manager (ESM)?

A.

Two units

B.

Four units

C.

Six units

D.

Eight units

Full Access
Question # 10

Reports can be created by selecting the ESM System Properties window, the Reports Icon in the top right of the ESM screen or by which of the following other method selecting the ESM System Properties window, the Reports Icon in the top right of the ESM screen or by which of the following other methods within Alarm Creation?

A.

Actions tab

B.

Conditions tab

C.

Escalation tab

D.

Summary tab

Full Access