chapter 11 Flashcards

1
Q

Recordings

the PSM and PSM for SSH, create video and text recordings for privileged sessions and store them in the vault where they can be viewed at any time by authorized users

you can store PSM video and text recordings in an external storage device

[none]

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

you can enable session recording in the (blank) for all platforms or for specific platforms by use of exceptions

A

master policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

only members of the (blank) group can view recordings in the psm

A

auditors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

recordings created by psm for ssh are currently displayed in the (blank) interface

A

classic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Sizing Calculations for the PSM Server

(𝑆𝑃𝑆𝑀) = (πΆπ‘ π‘’π‘ π‘ π‘–π‘œπ‘›)(π‘‘π‘ π‘’π‘ π‘ π‘–π‘œπ‘›)(π‘…π‘ π‘’π‘ π‘ π‘–π‘œπ‘› π‘Ÿπ‘’π‘π‘œπ‘Ÿπ‘‘π‘–π‘›π‘”) + 20𝐺B

SPSM = Required storage on PSM Server

Csession = Maximum Number of Concurrent Sessions

tsession = Average length of recorded session

Rsession recording = Average bit rate of recorded video
⎼ 100 KB/min – average SSH session
⎼ 200 KB/min – average low activity RDP session
⎼ 300 KB/min – average high activity RDP session with rich wallpaper

(25 sessions) x (180 minutes/session) x (300 KB/minute) + 20GB = 21.35GB

A

blank

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Sizing Calculations for the Vault Server

(π‘†π‘‰π‘Žπ‘’π‘™π‘‘) = (π‘‘π‘Ÿπ‘’π‘‘π‘’π‘›π‘‘π‘–π‘œπ‘›)(π‘π‘ π‘’π‘ π‘ π‘–π‘œπ‘›)(π‘‘π‘ π‘’π‘ π‘ π‘–π‘œπ‘›)(π‘…π‘ π‘’π‘ π‘ π‘–π‘œπ‘› π‘Ÿπ‘’π‘π‘œπ‘Ÿπ‘‘π‘–π‘›π‘”) + 20𝐺B

SVault = Required storage on Vault Server

tretention = Retention history requirement

Nsession = Average number of recorded sessions per day

tsession = Average length of recorded session

Rsession recording = Average bit rate of recorded video
⎼ 100 KB/min – average SSH session
⎼ 200 KB/min – average low activity RDP session
⎼ 300 KB/min – average high activity RDP session with rich wallpaper

(90 days) x (400 sessions/day) x (180 minutes/session) x (300 KB/minute) + 20GB = 1.96 TB

A

blank

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

session recordings are stored by default in a safe called (blank)

customer recordings safes can be defined at the platofrm level

the safes are created automatically by the psm when it uploads the first recording to the vault

for example, a separate recordings safe for sox-compliant linux accounts (365 retention period)

A

psmRecordings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

members of the (blank) group are automatically granted permissions on all recording safes

you can also manually set different auditors for each recording safe according to their access control policy

A

auditors

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

by default, the (blank) records al activities that take place during privileged sessions and provides audit data for the following events:
-sql commands
-ssh keystrokes
-windows titles
-universal keystrokes

the (blank) for ssh can create audit records for activities that are performed during ssh, scp, and telnet connections

when integrated with the PTA, the suspicious activity risk score is also available the monitoring pane, allowing the auditing team to prioritize session auditing based on risk

A

psm

psm

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

a unix admin rdp’s into a server through the PSM. This is done over port (blank)

alternately, he can make a http/s connection to the server via the (blank) on port (blank)

in the first case, the session audit is sent in real time from the psm to the vault

in the second case, the vault forwards real time audit information to SIEM and or PTA for activity risk analysis

A

1858

pvwa

1858

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

the (blank) enables authorized users to monitor active sessions, take part in controlling these sessions, and suspend for terminate them. It can also automatically suspend or terminate sessions when notified by the (blank) or a third-party threat analytics tool

A

psm

pta

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

while it is not possible to monitor or control live (blank) sessions, it is possible to view the live session audit

A

psm for ssh

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

live session monitoring settings determine how users can monitor live privileged sessions and the types of activites that they can perform

by default, all members of the vault group (blank) are authorized to suspend and terminate active sessions

A

PSMLiveSessionTerminators

How well did you know this?
1
Not at all
2
3
4
5
Perfectly