What is ePO Flashcards

1
Q

What is McAfee ePO?

The central ______ ________ for all _______product installations, updates and other content.

A

software repository

McAfee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does McAfee ePO work?

_______ security software and ePO work to stop ________ attacks on the system and alert users when an ______ occurs.

A

McAfee
Malware
attack

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the ePO server?
the ePo server hosts the ___ _________, provides centralized management, delivers_________ policies and controls the updates, and processes events for ____________ _________.

A

ePO software
security
managed systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is an Agent Handler in the DMZ (Demilitarized Zone)?

Supports specific _____ connections to _______ ________ installed in the DMZ allowing user to connect through _____.

A

port
Agent Handlers
firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a DMZ (Demilitarized Zone)?
A perimeter network that protects and adds an extra layer of security to an organizations internal _______-_______ _________ from _________ traffic. For example, having a web server accessible to the public, but not allowing them to be able to access the private organization network.

A

local-area network

untrusted

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are Distributed Repository Connections?
Various connections to resources stored on ______________ ____________ in the network (____,______,____). EX. Web console connection: Using default port 8443, it has an HTTP connection between the ePO server and web browser.

A

distributed repositories

HTTP, FTP, UDP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is an automatic response?
______ w/ in your environment send events to the _______ and if these events match configured response rules associated w/ the affected system’s group and each parent group above it, designated actions are taken, per the rules configurations.

A

Systems

server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the Microsoft Database SQL Server Database?

This DB stores all _____ created and used by ______. Can be stored on the machine or separate machine.

A

data

ePO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a McAfee Agent?

_____ ___ component for secure communication between ____ and managed products.

A

Client Side

ePO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is an Agent-Server Secure Communications Interval (ASSCI)?
Communications that occur at regular intervals between your ______ and _______.
Ex. Agents communicate through their assigned Agent Handlers w/ the server

A

systems

server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the ePO Web Based Console?

Once ePO is installed on _____, console is available.

A

server
Client Machine > Browser
Can run queries

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the web update server?

The Web update server hosts the latest security content so that your ______ server can pull ______ @ ______ ______ .

A

ePO
content
Scheduled intervals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are Distributed Repositories?

A way to distribute _________ to _________ _________ to minimize network traffic across ______connections.

A

packages
managed systems
slow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What do Agent Handlers do?

Reduce the workload off of the ______ by off-loading ______ __________and ______ ______ connectivity duties.

A

server
event processing
McAfee Agent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are Tomcat services?
Tomcat provides front end of console’s user interface for management tasks such as ______ ____ __________, user management, policy management, dashboards, etc.
Notification system and supports interactions between ______ and ePO through ____ (software files in zipped format and installed on ePO server).

A

System Tree organization
endpoints
extensions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are security keys?

Security keys _______, ____________ and _________ communications and content w/ in ePO env.

Relies on 3 security key pairs
Authenticate _______-_______ communication
Verify the contents of ______ repositories
Verify the contents of _______ repositories

Each key pair has:
A secret key that signs messages or packages at the ______and
A public key that verifies the messages or packages at the ______

A

verify
authenticate
encrypt

Agent‑server
local
remote

source
target

17
Q

What are Agent-Server secure communication (ASSC) keys?

ASSC keys authenticate _______-_______ communication.
The ________ sends its public key to the ePO server the first time they communicate.
From then on, the ePO server uses the Agent’s public key to verify messages signed with the Agent’s ______ key.
The server uses its own secret key to sign messages to the _______.
The Agent uses the server’s _______ key to verify the Agent’s message.
Only one key pair can be designated as the ________ key.

A
Agent-Server
Agent
secret 
Agent 
public 
master
18
Q

What do Local Main Repositoy key pairs do?

Local Main Repository key pairs verify contents of ______ repositories.
Local Main (ePO) Repository secret key signs the ________ _________ before it is checked into the _______.
The repository public key verifies package contents.
The agent retrieves available new content each time the client update task runs.
This key pair is _______ to each server.

Can use same key pair in a multi-server env.

A

local
software package
repository
unique

19
Q

What do Remote Repository key pairs do?

Verify contents of ______ repositories.
The agent ______ key verifies content retrieved from the remote repository.
The _______ key of the trusted source signs content when posting content to its remote repository.
Trusted sources include:
McAfee download site
McAfee SIA (Security Industry Authority) repository
Note: If the secret key is deleted, you cannot perform a pull, even if you import a key from another server. Before you overwrite or delete this key, make sure you back it up in a secure location.

A

remote
public
secret

20
Q
  1. What modes does the McAfee Agent operate in?

2. What if I have not previously managed McAfee products on my network?

A
  1. Managed and unmanaged.

2. Updater mode

21
Q

What is a persistent connection in ePO?

A

it is known as the keep alive connection

keeps the connection to the ePO server active and reduces bandwidth.

22
Q

What are sensor services in ePO?

A

track system events and take actions on client systems.

23
Q

What is P2P (Peer to Peer communication)?

A

retrieve updates and install products, Mcafee agent communicates w/ ePO.
Downloads updates from the peer agents in same subnet reducing bandwidth.

24
Q

What are the different types of servers in ePO?

A
Syslog
AD
SNMP
LDAP
SMTP
25
Q

What does a Syslog server do?

A

Provides a way for network devices to send event messages to a separate login server.

26
Q

What does an AD server do?

A

The AD server is responsible for the central software repository for all McAfee product installations, updates, and other content.

27
Q

What does an LDAP server do?
Registering this type of server allows you to use ______ ___________ rules to dynamically enable assigned permission sets and to enable Active Directory (AD) User Login; Active Directory servers are an example of LDAP servers that can be used to _________ and import systems from an AD server to the ePO _______ ______.

A

Policy Assignment
synchronize
System Tree

28
Q

What does an SNMP server do?

A

Registering this type of server allows ePO to know where to send the trap to so it can receive the trap info

29
Q

What does the McAfee Agent do?

A

Retrieves updates, ensures task implementation, enforces policies and forwards events to managed systems.
Automatically checked into Main(master) repository.

30
Q

What are user sensors?

A

User sensors: Detects logged-on users on client system using OS API’s and apply user based policy.

31
Q

What are network sensors?
Network Sensors: Detects _______ _________ status using OS network API’s and determines if the agent functionality such as pulling updates from the repository or communicating to ePO should be performed.

A

network connectivity

32
Q

What is the best practice in terms of Agent Handlers and the network segment?

A

Best practice to have Agent Handlers on same network segment as ePO DB.