AA- Day2 Flashcards

1
Q

Visibility with SPAN and DHCP

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Device Profile Library (DPL) & Device Classification Engine (DCE) Purpose

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Advanced Classification

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Advanced Criteria : Authentication Events

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Advanced Criteria: Events

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Advanced Criteria: Track changes

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Advanced Criteria: User Directory

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Advanced Criteria: Other Device Information 1

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Advanced Criteria: Other Device Information 2

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Quiz

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Criteria Logic

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Add to List

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Whitelisting and Blacklisting

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Commonly Misconfigured Criteria

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Scripts as Actions

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Reasons for Irresolvable Criteria

A
  1. Non existent property for the endpoint

> Testing for a windows property on non-windows devices

> Looking for a property on an unmanaged device such as a security camera

  1. Inability to access the endpoint due to

> Network issues

> Incorrect credentials

  1. Endpoint is outside of the deployment’s IP Assignments
  2. Endpoint is not part of the Internal Network
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Setting Counters

A

This Counters action is helpful for policy testing and enforcement

Example: On 1st incident of matching AV not updated we send a notification. On the 2nd incident of matching we block or quarantine the device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

“ACtion” Scheduling

A

scheduling an action is useful when e.g. you run muliple scripts and you need to run them after each other and not all at the same time

19
Q

Key Policy Errors to Avoid

A
20
Q

Quiz

A
21
Q

Quiz

A
22
Q

FLEXX Lincesing Model

A
23
Q

Resilience and HA Licensing

A
24
Q

Options to transition to FLEXX Licensing

A
  • Hardware Refresh
  • Upgrade
  • Migrate
25
Q

Upgrade Preperation (for Licensing to FLEXX migration)

A
26
Q

ForeScout Upgrade:

  • From Gui
  • From CLI
A
27
Q

Module Licensing when Upgrading

A
28
Q

Migrating to FLEXX licensing - Steps

A
29
Q

Quizz

A
30
Q

Quizz

A
31
Q

Extended Modules - Notes

A
32
Q

Available Module Categories

A
  • Advanced Threat Protection (ATD)
  • Endpoint Protection Platform (EPP)
  • Mobile Device Management (MDM)
  • Open Integration Module (OIM):data exchange
  • Security Information and Event Management (SIEM)
  • Vulnerability Management (VM)
  • Privileged Access Management (PAM)
  • IT SErvice Management (ITSM)
  • Next Generation Firewall (NGFW)
  • Client Management Tool (CMT)
33
Q

Extended Modules - Deployment steps (1)

A
34
Q

Extended Modules - Deployment steps (2)

A
35
Q

quizz

A
36
Q

Backups - System Components

A
37
Q

Backup - One Time

A
38
Q

Backups - Scheduled Automatic (1/3): Configure Backup Server

A
39
Q

Backups - Scheduled Automatic (2/3): Configure Encryption Password

A
40
Q

Backups - Scheduled Automatic (3/3): Set Schedule and back up parameters

A
41
Q

Backups - Restorin a System Backup

A
42
Q

Backup Restore - EM Component (1/2)

A
43
Q

Backup Restore - EM Component (2/2)

A