CERTIFICATION SCRIPT 2026
QUESTIONS WITH SOLUTIONS
GRADED A+
◍ Domain I.
Answer: Employee Assistance Program Design, administration, and
management
◍ DISA HBSS 201 Admin ePO5.1 (2016 Version).
Answer: Pull Task
◍ What can be created to prevent interpreting a normal behavior as an attack?.
Answer: Exception
◍ Which executable runs the main HIPS service?.
Answer: Firesvc.exe
◍ How do yo uninstall the HIPS 7.0 client for Windows from a managed
system?.
Answer: Remove the extension from the ePO Server and initiate the McAfee
Agent wakeup call.( double check answer)
◍ Domain II.
Answer: Employee Assistance Services to the Work Organization
◍ Assume three IPS policies are applied to a node; 1 default and 2 custom.
The default severity level is set to HIGH; 1 custom severity level is set to
LOW and the other custom is set to MEDIU
M. What is the effective severity level outcome for the applied policy?.
Answer: Low MedLeast Restrictive - testing
,◍ Domain III.
Answer: Employee assistance services to employees and family members
◍ EAP definition.
Answer: a set of professional services specifically designed to: 1) improve
and/or maintain the productivity and healthy functioning of the workplace
and to address a work organization's particular business needs through the
application of specialized knowledge and expertise about human behavior
and mental health.
◍ EAP core technology definition.
Answer: essential components of the employee assistance profession.
◍ EAP core technology 1.
Answer: M (management consultation): consultation with, training of, and
assistance to work organization leadership (managers, supervisors, and
union stewards) seeking to manage troubled employees, enhance the work
environment, and improve employee job performance.
◍ EAP core technology 2.
Answer: A (advertisement): active promotion of the availability of EA
services to employees, their family members and the work organization
◍ Which ePO repository provides all updates to the ePO Master repository?.
Answer: Source
◍ Which is not a type of IPS Signature?.
Answer: Network Signatures
◍ If a connection is in the state table; what action will occur with future traffic
for that connection?.
Answer: Allow
◍ Which ePO component gathers the events from the managed systems and
communicates them to the ePO server?.
Answer: McAfee Agent
◍ EAP core technology 3.
, Answer: P (problem identification): confidential and timely problem
identification/assessment services for employee clients with personal
concerns that may affect job performance
◍ What are the four main types of Permission Sets in ePO?.
Answer: Executive Reviewer; Global Reviewer; Group Admin; Group
Reviewer
◍ EAP core technology 4.
Answer: I (intervention): use of constructive confrontation, motivation, and
short-term intervention with employee clients to address concerns that affect
job performance
◍ EAP core technology 5.
Answer: R (referral): referral of employee clients for diagnosis, treatment,
and assistance, as well as case monitoring and follow-up services
◍ EAP core technology 6.
Answer: N (Networking): Assisting work organizations in establishing and
maintaining effective relations with treatment and other service providers,
and in managing provider contracts
◍ To manually move a system from one group to another; you do which two
things with the system to move it to the other group?.
Answer: A. Drag and drop - testing
◍ Which ePO core component enforces the policies on the systems?.
Answer: McAfee Agent
◍ In the Client Task Catalog you can export all of your client tasks into an
XML file that can be imported into another ePolicy Orchestrator Server..
Answer: True
◍ From this list select the format that you cannot export your query results to..
Answer: DOC - testing
◍ Each Firewall Rule provides a set of conditions that which of the following
has to meet?.
, Answer: B. Computers - testing
◍ EAP core technology 7.
Answer: A (Access and Advertising): Consultation to work organizations to
encourage availability of and employee access to health benefits covering
medical and behavioral problems including, but not limited to, alcoholism,
drug abuse, and mental and emotional disorders
◍ EAP core technology 8.
Answer: P (program evaluation): evaluation of the effects of EA services on
work organizations and individual job performance.
◍ Which IPS policy determines what options are available to a client computer
with a HIPS client; including; whether or not the client icon appears in the
system tray; types of intrusion alerts; and password to allow access to the
client user interface?.
Answer: D. Client UI - testing
◍ how many employees in the
U. S. receive EAP counseling services.
Answer: 1 in 20 (5%)
◍ how many employees have a severe enough problem to warrant treatment?.
Answer: 4 in 100 (4%)
◍ Which of the following is not a protection level defined in the IPS
Protection Policy?.
Answer: C. Log - testing
◍ Do EA professionals ask about legal concerns of employees.
Answer: Yes.
◍ What are the four severity levels of signature in HIPS?.
Answer: High, Medium, Low, Informational
◍ The Client Task Catalog allows you to create which of the following?.
Answer: B. Client task objects - testing
◍ To verify that the IP address sorting criteria that has not been configured to