McAfee Agent Flashcards

1
Q

How does the McAfee Agent fit into the ePO architecture?

A

It’s the client side component that provides secure communication between ePO and managed products

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the primary functions that are carried out by the McAfee Agent?

A
  • Installs products and their upgrades on managed systems
  • Updates security content such as the V3 DAT files or AMCore Content Package associated with ENS
  • Enforces policies and schedules tasks on managed systems
  • Gathers information and events from managed systems, and sends them to McAfee ePO
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

When managing a larger network, how many superagents should be configured?

A

One in every subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Give a high level description of the added functionality that a SuperAgent provides

A

Acts as an intermediary between the ePO server and other agents in the same network broadcast segment by caching information received from ePO, the master repository, or a mirror distributed repository and distributes it to agents in its network subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The Agent is based on what type of architecture? Why is it advantageous?

A

It’s based on services (messaging) architecture. In messaging-based architecture, the services communicate using a common language, reducing the use of system resources such as number of threads, number of handles, memory, and cpu

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the Agent’s manifest based policy?

A

Fetches only the changed policy settings from ePO, using fewer resources for comparing or merging settings.

ePO doesn’t have to compute the changed policy at each agent-server communication, helping to save network bandwidth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does Agent 5.6.X require multiple TCP connections during a single agent-server communication?

A

No, previous versions did, requiring more network bandwidth. 5.6.X uses the same TCP connection when performing an agent-server communication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How is the McAfee Agent able to track system events on the client system?

A

Via sensor services:

User sensors - Detects the logged on users on the client system using operating system APIs and apply the user-based policies accordingly

Network sensors - Detects the network connectivity status using operating system network APIs and determines if the agent functionality such as pulling updates from the repository or communicating to ePO should be performed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How does priority event forwarding work?

A

Makes it so that events that reach a certain severity threshold are forwarded to the ePO server with greater priority

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Deselect “Retrieve all system and product properties (recommended)”.
If unchecked retrieve only a subset of properties. What does it retrieve?

A

System properties and minimal product properties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How does agent-server communication work?
During each agent-server communication, McAfee Agent collects its _________ _________ _________, as well as events that have not yet been sent, and sends them to the ______. The server sends new or changed policies and tasks to the _______ _______, and the repository list if it has changed since the last agent-server communication. McAfee Agent enforces the new -________ locally on the managed system and applies any task or repository changes.

A

current system properties
server
McAfee Agent
policies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How long does it take the Agent to call into the server after it is initially installed?

A

45 seconds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What events trigger the McAfee agent to call in to the ePO server?

A
  • The agent-server communication interval (ASCI) elapses.
  • Wake-up calls are sent from McAfee ePO or Agent Handlers.
  • A scheduled wake-up task runs on the client systems.
  • Communication is initiated manually from the managed system (using the Agent Status monitor or command line).
  • A “Run Immediately” client task runs on the client systems.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What factors can cause the cumulative demand on the network, ePO, or the Agent Handler to be significant?

A
  • Number of systems managed by McAfee ePO
  • If your organization has stringent threat response requirements
  • If the network or physical location of clients in relation to servers or Agent Handlers is highly distributed
  • If there is inadequate available bandwidth
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

if your environment has a high number of systems managed by ePO, if your organization has stringent threat response requirements, if the network or physical location of clients in relation to server or Agent Handlers is highly distributed, or if there is inadequate available bandwidth, should you do more or less frequent agent server communications?

A

At the organization level, less frequent. However, for individual clients that perform critical functions, you might want to set a more frequent interval

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the methods that the McAfee Agent tries to use to establish communication?

A
  • IP Address
  • FQDN
  • NetBIOS name
  • Relay
  • Proxy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What happens if the Agent exhausts all of the various connection methods and still fails to establish a connection?

A

The McAfee Agent will try to connect again during the next ASCI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What does a wake up call do?

A

Triggers an immediate ASC rather than waiting for the current interval to elapse

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What are the two ways to issue a wake up call?

A

Manually from the server - (Requires an open wake-up communication port)

On a schedule set by the administrator

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are some possible reasons for issuing a wakeup call?

A
  • Making a policy change that you want to enforce immediately, without waiting for the scheduled ASCI
  • (ePO On-Premises)You create a task that you want to run immediately. The Run Task Now option creats a task, then assigns it to specififed client systems and sends wake-up calls
  • A query generated a report indicating that a client is out of compliance, and you want to test its status as part of a troubleshooting procedure
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is a SuperAgent?

A

A distributed repository which is designed to reduce the load on the ePO server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

Other than acting as a Distributed Repository, what can a SuperAgent do?

A

Broadcast wake-up calls to other agents on the same network subnet. The SuperAgent receives a wake-up call from ePO, then wakes up the agents in its subnet

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What types of systems are best suited to host SuperAgents?

A

Servers (or systems that are always on)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is the process of a SuperAgent wake-up call?

A

Server sends a wake-up call to all SuperAgents

SuperAgents broadcast a wake-up call to McAfee Agent in the same broadcast domain

All notified McAfee Agent (McAfee Agent notified by a SuperAgent and all SuperAgents) exchange data with McAfee ePO or Agent Handler

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

How does LazyCaching work

A

Allows the SuperAgent to retrieve data from the configured repositories only when requested by a local agent.

When a client system first requests content, the SuperAgent assigned to that system downloads the request content from its configured repositories and caches that content

The cache is updated when a newer version of the requested package is available in the Master Repository.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

How are communication interruptions involving superagents handled?

A

When a SuperAgent receives a request for content that might be outdated, the SuperAgent tries to contact McAfee ePO to see if new content is available.

If the connection tries time out, the SuperAgent distributes content from its own repository instead. This content transfer is done to make sure that the requester receives content even if that content might be outdated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is the purpose of the flush interval and the purge interval for LazyCaching

A

Flush interval is in reference to content in the SuperAgent memory that is outdated

Purge interval is in reference to content that’s no longer in use and needs to be purged

28
Q

Can you use mobile devices or laptops as SuperAgents? Why

A

It’s against best practice recommendation to do this. Should enable SuperAgents only on PCs or Virtual Systems. This is so that Distributed Repository can always be available. If the device is not ON, then the Distributed Repository cannot be accessed.

29
Q

How many requests can a SuperAgent handle concurrently?

A

1024

30
Q

Is it okay to set up SuperAgents on systems with poor network connectivity, or that are connected using VPNs? Why?

A

NO, the system needs to have a reliable connection and always be on.

31
Q

If you are using a SuperAgent hierarchy for updates, how many levels should there be max?

A

Three

32
Q

What function does a SuperAgent that’s configured as a RelayServer perform?

A

It bridges communications between client machines and the ePO server

33
Q

How does it work when an agent uses relay to communicate with McAfee ePO?

A

The connections are established in two parts; first between McAfee Agent and the RelayServer, and second between the RelayServer and McAfee ePO. These connections are maintained during the communication.

34
Q

How does the peer to peer functionality work with agents?

A

When an agent requires a content update, it tries to discover peer-to-peer servers with the content update in its broadcast domain. On receiving the request, the agents configured as peer-to-peer servers check if they have the requested content and respond back to the agent. The agent requesting the content downloads it from the peer-to-peer server that responds first.

35
Q

What protocol do Agents configured as P2P servers use to deliver content?

A

HTTP

36
Q

What happens if an Agent can’t discover a p2p server or the content update that it needs amongst its peers in its broadcast domain?

A

It falls backs to repository, as configured in its policy

37
Q

What ports are used during P2P communication?

A

8082 to discover peer servers, and port 8081 to server peer agents with updates

38
Q

What does it mean to configure an Agent as a Peer to Peer server?

A

It enables it to provide updates to others in the broadcast domain when requested

39
Q

What is default cache location and size for a Peer to Peer server? Can it be changed?

A

\data\mcafeeP2P
512 MB
Yes

40
Q

Which systems shouldn’t be configured as Peer to Peer servers?

A

Laptops, mobile devices, systems with poor network connectivity, systems connected with a VPN

41
Q

How do you configure Agents to be peer to peer servers or clients?

A

Through the p2p tab in the Agent General Policy

42
Q

By default, are Agents configured to be Peer to peer clients, peer to peer server, both, or neither?

A

Both

43
Q

What does the McAfee Agent Statistics task do?

A

Collects statistics and network bandwidth from RelayServers, SuperAgent hierarchies, and peer to peer statistics

44
Q

How can you see the results from a McAfee Agent Statistics task?

A

Run an Agent Statistics Information query

45
Q

How to change the language in the agent interface and the event log?

A

Through the Agent Troubleshooting policy

46
Q

What constitutes an inactive agent?

A

One that has not communicated with ePO in a user-specified time.

It is possible for agents to become disabled, or for users to uninstall them. It’s also possible that the system hosting the McAfee Agent might have been removed from the network

47
Q

What is the McAfee best practice in regards to inactive agents?

A

Perform regular weekly searches for systems with these inactive agents

48
Q

What are the two predefined tasks that help manage GUID (Global Unique ID) problems?

A
  • Duplicate Agent GUID - remove systems with potentially duplicated GUIDs
  • Duplicate Agent GUID - Clear error count
49
Q

What are the two modes that the Agent is capable of operating in?

A

Managed - Agent connects and communicates with ePO to manage McAfee product updates

Unmanaged mode - Agent doesn’t connect or communicate with ePO, but pulls updates from HTTP or FTP servers

50
Q

What are the ways to change the agent from unmanaged mode to managed mode?

A
  • Use the installer package Framepkg
  • Locally provision with maconfig
  • Remotely provision with maconfig
51
Q

How to change the agent from managed to unmanaged mode?

A

Remove the system from the system tree

52
Q

When the user selects ‘Update Security’ from the System Tray icon, what contents are updated?

A
Patch releases
Legacy product plug-in (.DLL) files
Service Pack releases
SuperDAT file (SDAT*.EXE) packages
Supplemental DAT (Extra.DAT) files
DAT files
Antivirus engines
Managed product signatures
53
Q

What is the name of the command line tool for the McAfee Agent

A

Windows - cmdagent.exe

Non-Windows - cmdagent

54
Q

Which command line switch will display all of the options for the agent and what they do respectively?

A

cmdagent.exe -h

55
Q

Where can you find the Agent Installation logs?

A
  • %TEMP%\McAfeeLogs, if the McAfee Agent is installed or upgraded manually.
  • C:\Windows\Temp\McAfeeLogs, if McAfee Agent is installed using push or deployment task on McAfee ePO.
56
Q

Where can you find the Agent Product logs

A

ProgramData - McAfee - Agent - Logs

57
Q

How can you view the McAfee Agent product log from ePO?

A

From Single System Troubleshooting

58
Q

What type of content is able to be provided by a peer to peer server

A

All of the content that’s available in ePO repositories

59
Q

How many concurrent connections does a peer to peer server support?

A

10 connections concurrently

60
Q

What does the McAfee Smart Installer refer to?

A

The installer that is used by the Agent Deployment URLs that are created by ePO

61
Q

What ports are used by the McAfee Agent?

A

8081 TCP

  • Inbound connection from ePO or Agent Handler.
  • Peer-to-peer server serves content, Relay connections established

8082 UDP

  • Inbound connection to McAfee Agent
  • Peer-to-peer server discovery, RelayServer discovery

8083 UDP
-RelayServer discovery for previous versions of McAfee Agent

62
Q

What are the minimum system requirements for the McAfee Agent?

A

Installed disk space - 50 MB, excluding log files

Memory - 512 MB RAM

Processor Speed - 1GHz

63
Q

What are the various of methods of deploying the ePO agent?

A
  • Pushing them to systems directly from ePO (selecting many systems can affect network throughput, must specify credential)
  • Using FramePkg installer (allows for information such as custom properties to be added on an individual basis)
  • Using 3rd party software Like SCCM
  • Logon scripts
  • Customized McAfee Smart installer (Agent Deployment URL) (Managed system users must have admin rights to install McAfee Agent Manually)
  • Deployment Task (only as upgrade, agent must already be present on the target systems)
  • Creating an image with McAfee agent (must remove the GUID using the command line switch, otherwise will cause sequencing errors from multiple identical systems
64
Q

What factors should make you consider having a longer ASCI?

A
  • Number of Systems managed by ePO being large
  • Organization has stringent threat response requirements
  • If the network or physical location of clients in relation to servers or Agent Handlers is highly distributed
  • If there is inadequate available bandwidth
65
Q

What are some notable features of the Agent that aren’t available on Linux/Mac

A
  • Automatic McAfee Agent Uninstall from ePO
  • Cluster node property reporting
  • Mirror Task
  • UNC repository updating
  • Agent Status Monitor
  • McTray application support
66
Q

What agent feature is available on Windows and Macintosh, but not Linux?

A

User Based Policy