  • 2. Version: 8.0 Question 1 The historical ACE functon allows the user to perform retrospectie correlatons on older data. In which of the following deiices is the data located that the historical correlaton engine uses? A. ELM B. REC C. ADM D. ESM Aoswern A Question 2 When preparing to apply a patch to the Enterprise Security Manager (ESM) and completng the ESM checklist, the command cat/proc7mdstat has been issued to determine RAID functonally The system returns an actie driie result identied as [U J What acton should be taken? A. Apply the patch, this is a properly functonal RAID which can be upgraded. B. Apply the patch, driie 1 is actie and can be upgraded. C. Apply the patch, driie 2 is actie and can be upgraded. D. Contact support before proceeding with the upgrade. Aoswern D Question 3 The McAfee Adianced Correlaton Engine (ACE) can t>e deployed in one of two modes which are.? A. Threshold and Anomaly. B. Preienton and Detecton. C. Stateful and Stateless. D. Historical and Real-Time. Aoswern D Question 4 The Database Eient Monitor (DEM) appliance preients disclosure of Personally Identiable Informaton (Pll) by employing which of the following features to those types of informaton? A. Obfuscaton masks B. Pll ilter masks
  • 3. C. Sensitie data masks D. Filter masks Aoswern C Question 5 One or more storage allocatons, which together specify a total amount of storage, coupled with a data retenton tme that speciies the maximum number of days a log is to be stored, is known as a A. Storage Volume. B. Storage Pool. C. Storage Deiice. D. Storage Area Network (SAN). Aoswern B Question 6 Which of the following security technologies sits inline on the network and preients atacks based on signatures and behaiioral analysis that can be conigured as a data source within the SIEM? A. Firewall B. Email Gateway C. Host Intrusion Preienton System D. Network Intrusion Preienton System Aoswern D Question 7 Analysts can efectiely use the McAfee SIEM to identfy threats by ? A. focusing on aggregated and correlated eients data. B. disabling aggregaton, so all data are iisible. C. studying ELM archiies, to analyze the original data D. use the streaming eient iiewer to analyze data. Aoswern A
