AA- Day2 Flashcards
Visibility with SPAN and DHCP
Device Profile Library (DPL) & Device Classification Engine (DCE) Purpose
Advanced Classification
Advanced Criteria : Authentication Events
Advanced Criteria: Events
Advanced Criteria: Track changes
Advanced Criteria: User Directory
Advanced Criteria: Other Device Information 1
Advanced Criteria: Other Device Information 2
Quiz
Criteria Logic
Add to List
Whitelisting and Blacklisting
Commonly Misconfigured Criteria
Scripts as Actions
Reasons for Irresolvable Criteria
- Non existent property for the endpoint
> Testing for a windows property on non-windows devices
> Looking for a property on an unmanaged device such as a security camera
- Inability to access the endpoint due to
> Network issues
> Incorrect credentials
- Endpoint is outside of the deployment’s IP Assignments
- Endpoint is not part of the Internal Network
Setting Counters
This Counters action is helpful for policy testing and enforcement
Example: On 1st incident of matching AV not updated we send a notification. On the 2nd incident of matching we block or quarantine the device.