Repositories Flashcards

1
Q

What are repositories?

A

House your security software packages and their updates for distribution to your managed systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Why is important to keep all of your security software up to date?

A

Security software is only as effective as the latest installed updates. For example, if your DAT files are out of date, even the best anti-virus software cannot detect new threats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What kind of content is typically included on respositories?

A
  • Managed software to deploy to your clients
  • Security content such as DATs and signatures
  • Patches and any other software needed for client tasks that you create using ePO
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

T/F Repositories can manage policies, collect events, and have code installed on them

A

False, a repository is nothing more than a file share located in your environment that your clients can access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do you get the content on your repositories out to your managed systems?

A

Via the McAfee Agent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the components of the repository infrastructure and how do they work together?

A

Source site - updated daily by McAfee

Master Repository - regularly pulls DAT and engine updates files from the source site

Distributed Repository - The master repository replicates the packages to distributed repositories in the network

Managed systems - The managed systems in the network retrieve updates from a master or distributed repository

Fallback site - if managed systems can’t access the distributed repositories or the Master Repository, they retrieve updates form the fallback site

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the source site?

A

The source site provides all updates for your Master Repository. McAfee posts software updates to this site regularly, such as DATS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How do you get content from the source site to your Master repository?

A

By using pull tasks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

T/F: You must use the McAfee HTTP or FTP update sites as your source site in your environment?

A

False, you can change the source site or create multiple source sites

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

T/F You must use a source site as a source of content for your Master Repository?

A

False, You could just download updates and then check them into your master repository manually. But the source site allows for automation of this process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the Master Repository?

A

The Master Repository maintains the latest versions of security software and updates for your environment. This repository is the source for the rest of your environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a distributed repository?

A

A repository that hosts a copy of your master repository.
Typically, these are placed strategically throughout your network to ensure that managed systems are updated while minimizing network traffic, especially across slow connections

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How do you replicate the contents of your master repository to distributed repositories in your environment?

A

Through replication that occurs:
-Automatically when specified package types are checked in to the Master Repository (only if global updating is enabled)

  • On a recurring schedule with replication tasks
  • Manually, by running a replicate now task
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Why are distributed repositories useful?

A

DR help reduce updating traffic across low-bandwidth, connections, or at remote sites with many endpoints.

For instance, if there is a remote location with a slow connection to the ePO server, by configuring a DR there and having the endpoints pull their content updates from said DR, updates are copied across a slow connection only once - to the DR - instead of once to each system in the remote location

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the fallback site?

A

A source site enabled as a back up site for when managed systems can’t access their usual repositories?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

T/F: Only one fallback site can be enabled

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

How many different branches are located in ePO repositories, and what are they called?

A

Current
Evaluation
Previous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is the purpose of the current branch?

A

The current branch should hold the latest packages and updates that you feel comfortable being distributed to the entirety of your environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the purpose of the evaluation branch?

A

The evaluation branch should hold the latest versions of packages or updates that you would like to test on a small group of test systems before deploying to the entirety of your environment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is the purpose of the previous branch?

A

The previous branch should hold the prior versions of DATs or packages that are known to function properly. This way, if something goes awry with a newer version of a package, you can redeploy your older versions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

T/F: The ePO server always acts as the Master Repository?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are the possible types of Distributed Repositories?

A
  • FTP repositories
  • HTTP repositories
  • UNC share repositories
  • SuperAgent repositories
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

T/F: ePO requires not only certain protocols for its distributed repositories, but also specific server vendors to provide these protocols

A

False, while certain protocols are required, any server vendor can provide these protocols.

For example, if you use an HTTP repo, you could use either Microsoft Internet Information Services (IIS) or Apache server (apache)

24
Q

T/F: There is no OS requirement for systems that host a distributed repository

A

True. As long as the ePO server can access the folders you specify to copy its content to, and as long as the agents can connect to these folder to download their updates, everything works as expected

25
Q

If you’re starting with a new installation with no preconfigured repositories, what is a good type of DR to go with?

A

A SuperAgent, because they’re easy to configure and are reliable

26
Q

Is it possible to use an unmanaged system as a distributed repository?

A

Yes, but a local admin must keep the distributed files up to date manually.

It’s generally a better idea to manage your DRs through ePO, so recommended to only use unmanaged DRs if managed DRs are in conflict with network or organizational policy

27
Q

Talk about FTP servers as distributed repositories.

A
  • Fast
  • Able to manage extensive loads from the clients pulling data
  • Helpful in a DMZ where HTTP might not be optimal, and UNC shares can’t be used
  • Clients don’t need authentication and can use an anonymous log to pull their content.
  • Not needing authentication reduces chance of failure
28
Q

Talk about HTTP servers as distributed repositories

A
  • Fast serving out files to large environments

- Allow clients to pull content without authentication, reducing chance that a client might fail to pull its content

29
Q

Why can UNC Shares as distributed repositories potentially cause problems?

A

Agents might not properly update if your agents cannot authenticate to your UNC share because they are not part of the domain or the credentials are incorrect

30
Q

What features do SuperAgents have that differentiate them from the other types of Distributed Repositories?

A
  • LazyCaching - allows SuperAgents to retrieve data from ePO servers only when requested by a local agent node
  • Ability to send wake up calls agents in its broadcast domain
31
Q

What is the most optimal way to organize your SuperAgents?

A

Organizing them in a hierarchy, where each layer is using LazyCaching, further saves bandwidth and minimizes the wide-area network traffic

32
Q

What advantages do SuperAgents have over the other types of distributed repositories?

A
  • Folder locations are created automatically on the host system before adding the repository to the repository list
  • SuperAgent repositories don’t require additional replication or updating credentials - account permissions are created when the agent is converted to a SuperAgent
33
Q

When configuring systems as SuperAgents, what considerations should be made?

A
  • Use existing file repositories in your environment, like SCCM
  • You don’t need a SuperAgent on every subnet
  • Turn off Global Updating to prevent unwanted updates of new engines or patches from the Master Repository
34
Q

What is the recommended level of SuperAgent hierarchy to implement?

A

Three Level Hierarchy

35
Q

What are the repository list files?

A

SiteList.xml and SiteMgr.xml

36
Q

What is the purpose of the repository list files

A

Includes the location and encrypted network credentials that managed systems use to select the repository and retrieve updates. The server sends the repository list to the McAfee Agent during Agent-Server communication

37
Q

What are the specific uses of the two repository list files?

A

SiteList.xml:

  • Import to a McAfee Agent during installation
  • Used by the agent and supported products

SiteMgr.xml:
-Back up and restore your distributed repositories and source sites if you have to reinstall the server

  • Import the distributed repositories and source sites from a previous installation of the McAfee ePO software
  • Used when reinstalling the McAfee ePO server, or for importing into other ePO servers that use the same distributed repositories or source sites
38
Q

What factors should be considered when determining where to place repositories?

A
  • How many nodes do you manage with the ePO server?
  • Are these nodes located in different geographic locations?
  • What connectivity do you have to your repositories?
39
Q

What is the typical rule of Distributed Repository placement?

A

Typically, you create a repository for each large geographic location, but there a several caveats.

40
Q

What is the most common mistake in regards to DR?

A

Having too few or too many, consequently overloading network bandwidth

41
Q

Why can Global Updating cause issues in a large environment?

A

Global Updating can saturate your WAN links. For instance, sometimes McAfee releases ENS engine updates which are several MBs, compared to 400-KB DAT files. This can saturate your WAN links, and also you may prefer to upgrade in a stage release

42
Q

What is the sequence of events for the Global Updating process?

A
  1. Content or packages are checked in to the Master Repository.
  2. The McAfee ePO server performs an incremental replication to all distributed repositories.
  3. The McAfee ePO server issues a wake-up call to all SuperAgents in the environment.
  4. The SuperAgent broadcasts a global update message to all agents in the SuperAgent subnet.
  5. Upon receipt of the broadcast, the agent is supplied with a minimum catalog version needed.
  6. The agent searches the distributed repositories for a site that has this minimum catalog version.
  7. Once a suitable repository is found, the agent runs the update task.
43
Q

How do you create a new source site in ePO?

A

Go to the Source Sites server setting

44
Q

If the ePO server and/or the McAfee Agent use a proxy server to connect to the internet, how do you configure this?

A

For the ePO server: The Proxy Settings Server Setting

For the McAfee Agent: In the Agent Repository policy

45
Q

What does the “bypass local addresses’ box in the Proxy Settings configuration screen do?

A

Input the IP Addresses or FQDN of systems hosting DR that you want the ePO server to be able to connect to directly

46
Q

How do you control which Repositories your managed systems reach out to for updates?

A

Through the McAfee Agent Repository Policy

47
Q

How can you export the SiteList.xml file?

A

Go to the master repository and select the export sitelist option

48
Q

T/F: McAfee releases both DATs and Engines daily.

A

False, DATs are daily, engines are less frequently

49
Q

What should be considered when scheduling a pull task?

A

Bandwidth and network usage - If you are using global updating, as recommended, schedule a pull task to run when bandwidth usage by other resources is low. With global updating, the update files are distributed automatically after the pull task finishes

Frequency of the task - DAT files are released daily, but you might not want to use your resources daily for updating

Replication and update tasks - Schedule replication tasks and client updates tasks to ensure that the update files are distributed throughout your environment

50
Q

What is the best way to ensure that your distributed repositories stay up to date?

A

Scheduling regular Repository Replicatino server tasks is the best way to ensure that your distributed repositories are up-to-date

51
Q

What is the difference between full replication and incremental replication?

A

Full replication means that entire contents of your Master Repository are copied over to your distributed repositories

Incremental replication uses less bandwidth by only copying updates in the Master Repository that are not yet in the distributed repository

52
Q

What is the recommended way to utilize both incremental and full replications tasks in ePO?

A

Schedule a daily incremental replication task. Schedule a weekly full replication task if it is possible for files to be deleted from the distributed repository outside of the replication functionality of the McAfee ePO software.

53
Q

How can you lessen the impact that replication tasks have on bandwidth resources.

A
  • By replicating to different servers at different times

- By selecting only the specific files and signatures that are necessary to each system for replication

54
Q

How does the McAfee Agent choose which repository to update from?

A

The Agent can use a network ICMP ping or subnet address compare algorithms to find the distributed repository with the quickest response time (usually the closet repository to the system on the network)

Or, you can make it so that agents adhere to a repository order that you configure in the agent repository policy. While doing this, you can enable or disable specific distributed repositories

55
Q

At how many nodes in your environment do Distributed Repositories become recommended rather than optional?

A

> 25,000 systems