- 论坛徽章:
- 0
|
<p align="left"><p align="left">最新642-567题库分享</p></p><p align="left"><p align="left">1. Regarding MARS Appliance rules, which three statements are correct? (Choose three.)</p></p><p align="left"><p align="left">A. There are three types of rules: System Inspection Rules, User Inspection Rules, and Drop Rules.</p></p><p align="left"><p align="left">B. Rules can be saved as reports.</p></p><p align="left"><p align="left">C. Rules can be deleted.</p></p><p align="left"><p align="left">D. Rules trigger incidents.</p></p><p align="left"><p align="left">E. Rules can be defined using a seed file.</p></p><p align="left"><p align="left">F. Rules can be created using a query.</p></p><p align="left"><p align="left">Answer: ADF</p></p><p align="left"><p align="left">2. Which action enables the MARS Appliance to ignore false positive events by either dropping the events completely, or by just logging them to the database?</p></p><p align="left"><p align="left">A. Creating System Inspection Rules using the Drop operation</p></p><p align="left"><p align="left">B. Creating Drop Rules</p></p><p align="left"><p align="left">C. Inactivating the Rules</p></p><p align="left"><p align="left">D. Inactivating events</p></p><p align="left"><p align="left">E. Deleting the false positive events from the Incidents > False Positives screen</p></p><p align="left"><p align="left">F. Deleting the false positive events from the Management > Event Management screen</p></p><p align="left"><p align="left">Answer: B</p></p><p align="left"><p align="left">3. Which of the following is a supported mitigation feature on the MARS Appliance?</p></p><p align="left"><p align="left">A. Generating and pushing configuration commands to Layer 3 devices</p></p><p align="left"><p align="left">B. Generating and pushing configuration commands to Layer 2 devices</p></p><p align="left"><p align="left">C. Automatically dropping all suspected traffic at the nearest firewall</p></p><p align="left"><p align="left">D. Automatically dropping all suspected traffic at the nearest IPS appliance</p></p><p align="left"><p align="left">Answer: B</p></p><p align="left"><p align="left">4. Which browser plug-in is required to view the charts and graphs on the MARS Appliance?</p></p><p align="left"><p align="left">A. Macromedia Flash Player</p></p><p align="left"><p align="left">B. Sun Microsystems Java</p></p><p align="left"><p align="left">C. Microsoft PowerPoint</p></p><p align="left"><p align="left">D. Adobe SVG Viewer</p></p><p align="left"><p align="left">Answer: D</p></p><p align="left"><p align="left">5. A MARS Appliance cannot access certain devices through the default gateway. Troubleshooting has determined that this is a MARS configuration issue. Which additional MARS configuration will be required to correct this issue?</p></p><p align="left"><p align="left">A. Use the MARS GUI to enable a dynamic routing protocol.</p></p><p align="left"><p align="left">B. Use the MARS GUI to add a static route.</p></p><p align="left"><p align="left">C. Use the MARS GUI to configure multiple default gateways.</p></p><p align="left"><p align="left">D. Use the MARS CLI to enable a dynamic routing protocol.</p></p><p align="left"><p align="left">E. Use the MARS CLI to add a static route.</p></p><p align="left"><p align="left">F. Use the MARS CLI to configure multiple default gateways.</p></p><p align="left"><p align="left">Answer: E</p></p><p align="left"><p align="left">6. When adding a device to the MARS Appliance, what is the reporting IP address of the device?</p></p><p align="left"><p align="left">A. the source IP address that sends syslog information to the MARS Appliance</p></p><p align="left"><p align="left">B. the IP address MARS uses to access the device via SNMP</p></p><p align="left"><p align="left">C. the IP address MARS uses to access the device via Telnet or SSH</p></p><p align="left"><p align="left">D. the pre-NAT IP address of the device</p></p><p align="left"><p align="left">E. the highest loopback IP address configured on the Cisco reporting device</p></p><p align="left"><p align="left">Answer: A</p></p><p align="left"><p align="left">7. What enables the MARS Appliance to profile network usage and detect statistically significant anomalous behavior from a computed baseline?</p></p><p align="left"><p align="left">A. MARS Global Controller</p></p><p align="left"><p align="left">B. VMS</p></p><p align="left"><p align="left">C. Netflow</p></p><p align="left"><p align="left">D. CiscoWorks</p></p><p align="left"><p align="left">E. MARS custom parser</p></p><p align="left"><p align="left">Answer: C</p></p><p align="left"><p align="left">8. Which is a benefit of using the dollar variable (like $TARGET01) when creating queries in MARS?</p></p><p align="left"><p align="left">A. The dollar variable enables multiple queries to reference the same common 5-tuples information using a variable.</p></p><p align="left"><p align="left">B. The dollar variable ensures that the probes and attacks that are reported are happening to the same host.</p></p><p align="left"><p align="left">C. The dollar variable allows matching of any unknown reporting device.</p></p><p align="left"><p align="left">D. The dollar variable allows matching of any event type groups.</p></p><p align="left"><p align="left">E. The dollar variable enables the same query to be applied to different reports.</p></p><p align="left"><p align="left">Answer: B</p></p><p align="left"><p align="left">9. What will happen if you try to run a MARS query that will take a long time to complete?</p></p><p align="left"><p align="left">A. After submitting the query, the MARS GUI screen will be locked up until the query completes.</p></p><p align="left"><p align="left">B. The query will be automatically saved as a rule.</p></p><p align="left"><p align="left">C. The query will be automatically saved as a report.</p></p><p align="left"><p align="left">D. You will be prompted to "Submit Batch" to run the query in batch mode.</p></p><p align="left"><p align="left">E. You will be prompted to "Submit Inline" to run the query immediately.</p></p><p align="left"><p align="left">Answer: D</p></p><p align="left"><p align="left">10. The MARS Appliance (running release 3.4.1) supports which protocol for data archiving and restoring?</p></p><p align="left"><p align="left">A. NFS</p></p><p align="left"><p align="left">B. TFTP</p></p><p align="left"><p align="left">C. FTP</p></p><p align="left"><p align="left">D. secured FTP</p></p><p align="left"><p align="left">Answer: A</p></p> |
|