AA- Day2 Flashcards
Visibility with SPAN and DHCP

Device Profile Library (DPL) & Device Classification Engine (DCE) Purpose

Advanced Classification

Advanced Criteria : Authentication Events

Advanced Criteria: Events

Advanced Criteria: Track changes

Advanced Criteria: User Directory

Advanced Criteria: Other Device Information 1

Advanced Criteria: Other Device Information 2

Quiz

Criteria Logic

Add to List

Whitelisting and Blacklisting

Commonly Misconfigured Criteria

Scripts as Actions

Reasons for Irresolvable Criteria
- Non existent property for the endpoint
> Testing for a windows property on non-windows devices
> Looking for a property on an unmanaged device such as a security camera
- Inability to access the endpoint due to
> Network issues
> Incorrect credentials
- Endpoint is outside of the deployment’s IP Assignments
- Endpoint is not part of the Internal Network

Setting Counters
This Counters action is helpful for policy testing and enforcement
Example: On 1st incident of matching AV not updated we send a notification. On the 2nd incident of matching we block or quarantine the device.
