Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the McAfee ISCPS SIEM MA0-104 Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam MA0-104 Premium Access

View all detail and faqs for the MA0-104 exam


815 Students Passed

84% Average Score

93% Same Questions
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Alarms using field match as the condition type allow for selected Actions to be taken when the Alarm condition is met. Which of the following McAfee ePolicy Orchestrator (ePO) Actions can be selected when creating such Alarm?

Options:

A.

Send Events

B.

Collect and Send Properties

C.

Agent Uninstall

D.

Assign Tag with ePO

Questions # 12:

The primary function of the Application Data Monitor (ADM) appliance is to decode traffic at layer

Options:

A.

one for inspection.

B.

three for inspection.

C.

five for inspection.

D.

seven for inspection.

Questions # 13:

On the McAfee enterprise Security Manager (ESM), the default data Retention setting specifies that Event and Flow data should be maintained for

Options:

A.

365 days.

B.

same value as configured on the ELM.

C.

90 Days

D.

all data allowed by system

Questions # 14:

A security administrator is configuring the Enterprise Security Manager (ESM) to comply with corporate security policy and wishes to restrict access to the ESM to certain users and machines Which of the following actions would accomplish this?

Options:

A.

Configure the Access Control List and setup user accounts

B.

Define user groups and set permissions based on IP

C.

Assign AD users to computer assignment groups

D.

Setup local accounts based on IP Zones

Questions # 15:

Which of the following is the minimum amount of disk space required to install the McAfee Enterprise Security Manager (ESM) as a virtual machine?

Options:

A.

100 GB

B.

250GB

C.

500 GB

D.

1 TB

Questions # 16:

When preparing to apply a patch to the Enterprise Security Manager (ESM) and completing the ESM checklist, the command cat/proc7mdstat has been issued to determine RAID functionally The system returns an active drive result identified as [U J What action should be taken?

Options:

A.

Apply the patch, this is a properly functional RAID which can be upgraded.

B.

Apply the patch, drive 1 is active and can be upgraded.

C.

Apply the patch, drive 2 is active and can be upgraded.

D.

Contact support before proceeding with the upgrade.

Questions # 17:

The ESM supports five Authentication methods. The default login option uses the standard Username and Password format. Which of the following are the other four methods available?

Options:

A.

RADIUS, TACACS+, Active Directory, LDAP.

B.

Active Directory, NTLM, TACACS+, LDAP.

C.

LDAP, Active Directory, RADIUS, CAC.

D.

CAC, LDAP, RADIUS,TACACS+.

Questions # 18:

When displaying baseline averages using the automatic time range option, baseline data is correlated by using the same time period that is being used for the current query for which of the following past number of intervals?

Options:

A.

Three

B.

Seven

C.

Five

D.

Ten

Questions # 19:

The Database Event Monitor (DEM) appliance prevents disclosure of Personally Identifiable Information (Pll) by employing which of the following features to those types of information?

Options:

A.

Obfuscation masks

B.

Pll filter masks

C.

Sensitive data masks

D.

Filter masks

Questions # 20:

A McAfee Event Receiver (ERC) will allow for how many Correlation Data Sources to be configured?

Options:

A.

1

B.

3

C.

5

D.

10

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.