New Year Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free McAfee MA0-104 Practice Exam with Questions & Answers | Set: 2

Questions 11

Which of the following are the three default users defined within the Users and Groups option in the ESM properties?

Options:
A.

NGCP, POLICY, REPORT

B.

NGCP, BACKUP, REPORT

C.

ADMIN, POLICY, REPORT

D.

NGCP, SYSTEM, REPORT

McAfee MA0-104 Premium Access
Questions 12

The configuration of a receiver has recently been modified and issues occur. Which command will collect historical data?

Options:
A.

htop

B.

getstatsdata

C.

snmpget

D.

df

Questions 13

A security administrator is configuring the Enterprise Security Manager (ESM) to comply with corporate security policy and wishes to restrict access to the ESM to certain users and machines Which of the following actions would accomplish this?

Options:
A.

Configure the Access Control List and setup user accounts

B.

Define user groups and set permissions based on IP

C.

Assign AD users to computer assignment groups

D.

Setup local accounts based on IP Zones

Questions 14

While investigating beaconing Malware, an analyst can narrow the search quickly by using which of the following watchlists in the McAfee SIEM?

Options:
A.

MTIE Suspicious and Malicious

B.

TSI Suspicious and Malicious

C.

GTI Suspicious and Malicious

D.

MTI Suspicious and Malicious

Questions 15

The possibility of both data source Network Interface Cards (NICs) using the shared IP and MAC address at the same time is eliminated by using which of the following?

Options:
A.

iSCSI Adapter

B.

iPMICard

C.

PCI Adapter

D.

SAN Card

Questions 16

The McAfee Enterprise Log Manager (ELM) offers three levels of compression (Low, Medium, and High). By default, the ELM compression level is set to Low. Which of compression (Low, Medium, and High). By default, the ELM compression level is set to Low. Which of the following is the compression ratio for the Medium level?

Options:
A.

17:1

B.

20:1

C.

10:1

D.

14:1

Questions 17

When displaying baseline averages using the automatic time range option, baseline data is correlated by using the same time period that is being used for the current query for which of the following past number of intervals?

Options:
A.

Three

B.

Seven

C.

Five

D.

Ten

Questions 18

When writing custom correlation rules, the analyst should focus on

Options:
A.

multiple security controls and events specific to the environment.

B.

any one specific high-quality indicator of compromise.

C.

malware alerts announced by industry security groups

D.

firewall events, as they provide the first indication of a compromise

Questions 19

Internet perimeter firewall data-sources provide excellent visibility into

Options:
A.

backbone Intrusion Prevention System (IPS) detections.

B.

server misbehavior.

C.

inbound port scans

D.

client patch level.

Questions 20

A SIEM allows an organization the ability to correlate seemingly disparate streams of traffic into a central console for analysis. This correlation, in many cases, can point out activities that might otherwise go undetected This type of detection is also known as

Options:
A.

anomaly based detection

B.

behavioral based detection.

C.

heuristic based detection.

D.

signature based detection