QUESTIONS AND SOLUTIONS GRADED A+
◉ 2. What action should be taken if an event is found to be a false
positive?.
Answer: -Start the tuning process
◉ 3. Which product is responsible for collecting endpoint properties
and policy enforcement?.
Answer: -McAfee HIPS (?)
◉ 4. What is the correct order for prioritizing events?.
Answer: -Severity; Action Taken; Volume
◉ 5. An admin creates ___________ to manage the software installed on
the endpoint..
Answer: -Policies
◉ 6. Which HIPS label shows the friendly name of a HIPS event?.
Answer: -Signature Name
, ◉ 7. Which of the following is not true about ArcSight and
situational awareness?.
Answer: -Prevention
◉ 8. In order to manage an endpoint; ___________ must be installed..
Answer: -McAfee Agent (?)
◉ 9. A dashboard is a collection of __________ shown together in the
same location..
Answer: -Monitors
◉ 10. Which VSE label shows the friendly name of a VSE event?.
Answer: -Threat Name
◉ 11. Which feature does HIPS and VSE both have in common but is
disabled on one when both are installed on the same endpoint?.
Answer: -Buffer Overflow Protection
◉ 12. Which query filter label helps group similar data for VSE?.
Answer: -Threat Type
◉ 13. As an Analyst; your duty includes reviewing all the data
collected by the ePO server..