14.25-36 Flashcards

1
Q

NCDOC Roll up looks at these specific compliance

checks.

A
  1. McAfee Agent Version
  2. Virus Scan
  3. DAT files
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What task is used to migrate events from old database to new database.

A

Event Migration

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What task is set for systems older than 14
days. Moves to inactive group. Needs to be modified to run daily. Systems are deleted
after 30 days.

A

Inactive Agent Cleanup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Synchronizes select Windows NT domains and Active Directory containers that are mapped to System Tree groups. This task can also be performed manually.

A

NT Domain/Active Directory Synchronization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Retrieves packages from the source site, and then places them in the master repository

A

Repository Pull

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Updates distributed repositories from the master repository.

A

Repository Replication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Imports summary data from other registered ePO

servers

A

Roll Up Data: Managed Systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Runs a selected query and allows you to chain sub actions related to the
query results

A

Run Query

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Evaluates all managed systems against a selected tag’s criteria, and applies the tag to all matching systems.

A

Run Tag Criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

This runs the query “Systems with High Sequence Errors,” moves these agents to the
duplicate agent GUID list, and deletes the system from the System Tree– remove systems with potentially duplicate GUIDs

A

Duplicate Agent GUID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is an extension of the ePO and provides system and file activity monitoring.

A

McAfee ABM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

ABM provides automated support for INFOCON baseline assessments
Also focuses on:

A
Registry
Services
Local User/Groups
Ports
Files
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Asset Scan that is run once; the first time a system is added to the tree.

A

Baseline Scan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Scan captures changes to the monitored systems since last baseline

A

Activity Scan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who provides the HBSS Policy Layout guide, and pushes out revisions as new policies
emerge.

A

Program Executive Office C4I (PEO-C4I) Naval Networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What provides step-by-step procedures for installing ESX, as well as importing the virtual machine templates into the CND-OSE suite

A

CND-OSE 1.4 Site Installation Guide

17
Q

Six Step TroubleShooting

A
  1. System Recognition 2. Symptom Elaboration 3. Listing Probable Faulty Function 4. Localizing Probable Faulty Function 5. Localizing Probable Faulty Component 6. Failure Analysis
18
Q

VMWare Tools Resolves what issues.

A
  1. Low video resolution 2. Inadequate color depth 3. Incorrect display of network speed
  2. Restricted movement of the mouse
  3. Inability to copy and paste and drag-and-drop files
  4. Missing sound 7. Provides the ability to take quiesced snapshots of the guest OS 8. Synchronizes the time in the guest operating system with the time on the host
19
Q

HBSS VM requires 3 services to be running in order.

A
  1. MCAFEETOMCATSVC
  2. MCAFEEEVENTPARSERSRV
  3. MCAFEEAPACHESRV
20
Q

SQL server and SQL Server Agent depend on what account?

A

cnd_a_db

21
Q

What log stores RSS Actions?

A

RSDSensor_out.log

22
Q

Which log stores retina scan events?

A

_RetinaScanner.log

23
Q

Which log stores retina update events

A

debug_Syncit.log

24
Q

What details all actions of ePO server.

A

Server.log

25
Q

What contains database logs that are required to be reviewed in accordance with PMS
checks?

A

MSSQL log

26
Q

What logs are generated on each managed asset and are accessible via the Client UI Activity
Log.

A

HIP Logs

27
Q

How to get to the activity log if icon isn’t working.

A

C:\Program Files\McAfee\Common Framework\CmdAgent.exe

28
Q

CND-OSE Backup types and schedule.

A

All backups are started at 0030.
MSSQL- daily
SCCVI/ACAS and Audit Data- weekly on Sundays

29
Q

The Host IPS log found on ePO is broken into what 4 major sections

A
  1. Events
  2. IPS Client Rules
  3. Firewall Client Rules
  4. App Blocking Client Rules
30
Q

What info is found on the Client UI Logs

A

Event Type, IP Address/ User, Application

31
Q

Trusted Networks policy affects what?

A

Firewall rules stating “Trusted” as the source, as well

as NIPS.

32
Q

What within HIP is responsible for host intrusions, network intrusions, as well as
the shielding and enveloping of applications.

A

The IPS software

33
Q

What controls which application can open?

A

App Blocking-Creation

34
Q

What controls which applications can bind together?

A

App Blocking- Hooking

35
Q

What can configure HIP agent interface.

A

General- Client UI

36
Q

What is the active directory account used to perform repository pulls?

A

cndose_proxy account

37
Q

What error is caused by an issue with the account used to perform repository pulls?

A

“invalid credentials”

38
Q

Logs to review in troubleshooting.

A

Packet Filter Log, Firewall Log Web Proxy Log