The McAfee SIEM solution satisfies which of the following compliance requirements?
A SIEM can be effectively used to identify active threats from internal systems by monitoring/correlating events that occur
The analyst has created a correlation rule to correlate events from Anti-Virus (AV>, Network Intrusion Prevention (NIPS) and the firewall. While reviewing just firewall events, the analyst notices a large spike in outbound Command and Control traffic, however, the correlation rule is not triggering The analyst then looks at the Network IPS and the Anti-Virus views and notices there are no alerts for this traffic. Which of the following features of NIPS and AV are most likely turned off?
Which of the following is the minimum amount of disk space required to install the McAfee Enterprise Security Manager (ESM) as a virtual machine?
Which of the following features of the Enterprise Log Manager (ELM) can alert the user if any data has been modified?
Which options within the Receiver properties should be selected to configure the device to respond to ICMP echo requests?
The normalization value assigned to each data-source event allows
When a Correlation Rule successfully triggers, this occurs at the
What Firewall component is natively used by the McAfee SIEM appliances to protect the appliances from unauthorized communications?
PDF + Testing Engine
|
---|
$66 |
Testing Engine
|
---|
$50 |
PDF (Q&A)
|
---|
$42 |
McAfee Free Exams |
---|
![]() |