Week 6 Flashcards
What are the ePO compliance checks?
- McAfee Agent Version
- virus scan
- anti spyware
- HIP
- PA
- Assets
- DAT files
FIM allows you to do what? 4 things.
- Define which files should be tracked
- Define what files should not be checked
- Specify the frequency for detecting file change
- See and receive notification about changes to file or file attributes
Two types of scans for ABM
- baseline
- activity
ABM has how many policy categories?
What are they?
3
- file permissions
- registry permissions
- Trusted activity
If there is a suspected attack, who do you inform?
IAM
What log details all actions of the ePO Application Server?
EpoApSvr.log
What log file is a more detailed version of the log available through the McAfee Agent GUI?
Agent_.log
What log provides detailed information of all actions performed by Rogue System Sensors?
RSDSensor_out.log
How often does the RSS log communicate with ePO?
Every 5 minutes
What are the common logs contained on all Windows machines?
- Application
- Security
- System
What is the boot order?
- MSSQL
- ACAS (SSCVI)
- HBSS
What are the two services on MSSQL that are required to run?
- SQL Server (MSSQLSERVER)
- SQL Server Agent (MSSQLSERVER)
When is MSSQL backed up?
Daily at 0030
When is ACAS/SCCVI backed up?
Weekly on Sunday
CANES she’s what for cross domain services?
Thin client
What VMs are used on DHCP in the UNCLAS and Secret enclaves?
- IAEXET
- WEB
Is DHCP allowed on SCI?
No!
What is used to restrict data flow from applications and users in each enclave?
-virtual routing and forwarding
How is CANES providing data-at-rest protection?
Hard drive encryption
Net IQ is used for?
Analyze siem log
Are CANES logging standards the same as DISA, what we currently use?
Yes
EMET can be used to prevent?
PKI based man-in-the-middle
What is he module that applies local security to servers on COMPOSE networks?
SCM-security configuration module
Where is Symantec Endpoint Protection Manager installed?
EX001