1. CND Services include Prepare; Protect and _________ -CORRECT ANS--Respond
2. What action should be taken if an event is found to be a false positive? -CORRECT ANS--Start the
tuning process
3. Which product is responsible for collecting endpoint properties and policy enforcement? -CORRECT
ANS--McAfee HIPS (?)
4. What is the correct order for prioritizing events? -CORRECT ANS--Severity; Action Taken; Volume
5. An admin creates ___________ to manage the software installed on the endpoint. -CORRECT ANS--
Policies
6. Which HIPS label shows the friendly name of a HIPS event? -CORRECT ANS--Signature Name
7. Which of the following is not true about ArcSight and situational awareness? -CORRECT ANS--
Prevention
8. In order to manage an endpoint; ___________ must be installed. -CORRECT ANS--McAfee Agent (?)
9. A dashboard is a collection of __________ shown together in the same location. -CORRECT ANS--
Monitors
10. Which VSE label shows the friendly name of a VSE event? -CORRECT ANS--Threat Name
11. Which feature does HIPS and VSE both have in common but is disabled on one when both are
installed on the same endpoint? -CORRECT ANS--Buffer Overflow Protection
12. Which query filter label helps group similar data for VSE? -CORRECT ANS--Threat Type