Getting Started with ESM Flashcards

1
Q

Why you need to do rule updates on your SIEM?

A

This is because Trellix team is always developing new signatures to identify threats on network traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

After you do a rule update on your SIEM you need to do a Rollout. How can you do this?

A
  • Clic on Policy editor
  • Clic on Operations
  • Clic on Rollout
  • Check Rollout policy to all devices now
  • Clic OK
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Trellix ESM allows you to configure which two types of user accounts?

A
  • System Administrators
  • General Users
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

To what refers the process of Keying on ESM?

A

It is the process to exchange ssh keys between devices when adding devices like ACE, ERC, ELM and so on to the ESM. This procedure allows to protect comunication between each device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the “tail -f /var/log/message” command useful when working with Trellix components directly from the shell?

A

It allows to observe the current activity on the device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What you need to do after an update process on any of the Trellix components?

A
  • You need to key the device again
  • Write out device data sources
  • Rollout policies to all devices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Yo have been asked to do a write out of the devices data sources on your SIEM. How can you do this?

A

This is applied on ERC you go to Data Sources, and then uncheck and check again any data source that has the Parsing option enabled, this enables the Write button on the bottom of the window.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is aggregation concept refers to on ESM?

A

Is the ability to group multiple events on a single event with a event count.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly