免费注册 查看新帖 |

Chinaunix

  平台 论坛 博客 文库
最近访问板块 发新帖
查看: 1221 | 回复: 0
打印 上一主题 下一主题

642-567题库下载 [复制链接]

论坛徽章:
0
跳转到指定楼层
1 [收藏(0)] [报告]
发表于 2011-03-01 09:00 |只看该作者 |倒序浏览
<p align="left"><p align="left">最新642-567题库分享</p></p><p align="left"><p align="left">1. Regarding MARS Appliance rules, which three statements are correct? (Choose three.)</p></p><p align="left"><p align="left">A. There are three types of rules: System Inspection Rules, User Inspection Rules, and Drop Rules.</p></p><p align="left"><p align="left">B. Rules can be saved as reports.</p></p><p align="left"><p align="left">C. Rules can be deleted.</p></p><p align="left"><p align="left">D. Rules trigger incidents.</p></p><p align="left"><p align="left">E. Rules can be defined using a seed file.</p></p><p align="left"><p align="left">F. Rules can be created using a query.</p></p><p align="left"><p align="left">Answer: ADF</p></p><p align="left"><p align="left">2. Which action enables the MARS Appliance to ignore false positive events by either dropping the events completely, or by just logging them to the database?</p></p><p align="left"><p align="left">A. Creating System Inspection Rules using the Drop operation</p></p><p align="left"><p align="left">B. Creating Drop Rules</p></p><p align="left"><p align="left">C. Inactivating the Rules</p></p><p align="left"><p align="left">D. Inactivating events</p></p><p align="left"><p align="left">E. Deleting the false positive events from the Incidents &gt; False Positives screen</p></p><p align="left"><p align="left">F. Deleting the false positive events from the Management &gt; Event Management screen</p></p><p align="left"><p align="left">Answer: B</p></p><p align="left"><p align="left">3. Which of the following is a supported mitigation feature on the MARS Appliance?</p></p><p align="left"><p align="left">A. Generating and pushing configuration commands to Layer 3 devices</p></p><p align="left"><p align="left">B. Generating and pushing configuration commands to Layer 2 devices</p></p><p align="left"><p align="left">C. Automatically dropping all suspected traffic at the nearest firewall</p></p><p align="left"><p align="left">D. Automatically dropping all suspected traffic at the nearest IPS appliance</p></p><p align="left"><p align="left">Answer: B</p></p><p align="left"><p align="left">4. Which browser plug-in is required to view the charts and graphs on the MARS Appliance?</p></p><p align="left"><p align="left">A. Macromedia Flash Player</p></p><p align="left"><p align="left">B. Sun Microsystems Java</p></p><p align="left"><p align="left">C. Microsoft PowerPoint</p></p><p align="left"><p align="left">D. Adobe SVG Viewer</p></p><p align="left"><p align="left">Answer: D</p></p><p align="left"><p align="left">5. A MARS Appliance cannot access certain devices through the default gateway. Troubleshooting has determined that this is a MARS configuration issue. Which additional MARS configuration will be required to correct this issue?</p></p><p align="left"><p align="left">A. Use the MARS GUI to enable a dynamic routing protocol.</p></p><p align="left"><p align="left">B. Use the MARS GUI to add a static route.</p></p><p align="left"><p align="left">C. Use the MARS GUI to configure multiple default gateways.</p></p><p align="left"><p align="left">D. Use the MARS CLI to enable a dynamic routing protocol.</p></p><p align="left"><p align="left">E. Use the MARS CLI to add a static route.</p></p><p align="left"><p align="left">F. Use the MARS CLI to configure multiple default gateways.</p></p><p align="left"><p align="left">Answer: E</p></p><p align="left"><p align="left">6. When adding a device to the MARS Appliance, what is the reporting IP address of the device?</p></p><p align="left"><p align="left">A. the source IP address that sends syslog information to the MARS Appliance</p></p><p align="left"><p align="left">B. the IP address MARS uses to access the device via SNMP</p></p><p align="left"><p align="left">C. the IP address MARS uses to access the device via Telnet or SSH</p></p><p align="left"><p align="left">D. the pre-NAT IP address of the device</p></p><p align="left"><p align="left">E. the highest loopback IP address configured on the Cisco reporting device</p></p><p align="left"><p align="left">Answer: A</p></p><p align="left"><p align="left">7. What enables the MARS Appliance to profile network usage and detect statistically significant anomalous behavior from a computed baseline?</p></p><p align="left"><p align="left">A. MARS Global Controller</p></p><p align="left"><p align="left">B. VMS</p></p><p align="left"><p align="left">C. Netflow</p></p><p align="left"><p align="left">D. CiscoWorks</p></p><p align="left"><p align="left">E. MARS custom parser</p></p><p align="left"><p align="left">Answer: C</p></p><p align="left"><p align="left">8. Which is a benefit of using the dollar variable (like $TARGET01) when creating queries in MARS?</p></p><p align="left"><p align="left">A. The dollar variable enables multiple queries to reference the same common 5-tuples information using a variable.</p></p><p align="left"><p align="left">B. The dollar variable ensures that the probes and attacks that are reported are happening to the same host.</p></p><p align="left"><p align="left">C. The dollar variable allows matching of any unknown reporting device.</p></p><p align="left"><p align="left">D. The dollar variable allows matching of any event type groups.</p></p><p align="left"><p align="left">E. The dollar variable enables the same query to be applied to different reports.</p></p><p align="left"><p align="left">Answer: B</p></p><p align="left"><p align="left">9. What will happen if you try to run a MARS query that will take a long time to complete?</p></p><p align="left"><p align="left">A. After submitting the query, the MARS GUI screen will be locked up until the query completes.</p></p><p align="left"><p align="left">B. The query will be automatically saved as a rule.</p></p><p align="left"><p align="left">C. The query will be automatically saved as a report.</p></p><p align="left"><p align="left">D. You will be prompted to &quot;Submit Batch&quot; to run the query in batch mode.</p></p><p align="left"><p align="left">E. You will be prompted to &quot;Submit Inline&quot; to run the query immediately.</p></p><p align="left"><p align="left">Answer: D</p></p><p align="left"><p align="left">10. The MARS Appliance (running release 3.4.1) supports which protocol for data archiving and restoring?</p></p><p align="left"><p align="left">A. NFS</p></p><p align="left"><p align="left">B. TFTP</p></p><p align="left"><p align="left">C. FTP</p></p><p align="left"><p align="left">D. secured FTP</p></p><p align="left"><p align="left">Answer: A</p></p>
您需要登录后才可以回帖 登录 | 注册

本版积分规则 发表回复

  

北京盛拓优讯信息技术有限公司. 版权所有 京ICP备16024965号-6 北京市公安局海淀分局网监中心备案编号:11010802020122 niuxiaotong@pcpop.com 17352615567
未成年举报专区
中国互联网协会会员  联系我们:huangweiwei@itpub.net
感谢所有关心和支持过ChinaUnix的朋友们 转载本站内容请注明原作者名及出处

清除 Cookies - ChinaUnix - Archiver - WAP - TOP