Pass the RSA NetWitness Platform 050-11-CARSANWLN01 Questions and answers with CertsForce

Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions
Questions # 1:

You can configure replication for log data by setting up a remote collector and creating

Options:

A.

a Virtual Log Collector


B.

a lockbox


C.

host groups


D.

destination groups


Expert Solution
Questions # 2:

To access device information and perform device operations through RSA NetWitness. a user must be

Options:

A.

assigned the role of Operator"


B.

a member of a "DeviceUser" group in Active Directory


C.

a member of a role that has privileges for the device


D.

assigned read/write access to the NetWitness appliance


Expert Solution
Questions # 3:

What are the data sources available in RSA NetWitness when creating a Reporting Engine rule?

Options:

A.

Short, Long, Truncated


B.

IPDB, ODBC, FileReader


C.

Broker, Concentrator, Decoder


D.

NetWitness DB, Warehouse DB, Respond DB


Expert Solution
Questions # 4:

To create meta keys that will appear in the Investigation view, you would most commonly edit configuration files on the

Options:

A.

Packet Decoder


B.

Concentrator


C.

Broker


D.

Log Decoder


Expert Solution
Questions # 5:

Which of the following can NOT be configured as a data source for the Reporting Engine?

Options:

A.

Broker


B.

Concentrator


C.

Archiver


D.

ESA


Expert Solution
Questions # 6:

The logical operators available for Querying in Investigations depend on the Index Level of the individual meta key Which Index Level limits your query to the logical operators "exists'' and 'texists""?

Options:

A.

IndexNone


B.

IndexKeys


C.

IndexValues


D.

IndexAII


Expert Solution
Questions # 7:

Administrators can use the Profile feature to limit views with (Choose three)

Options:

A.

Meta groups


B.

Custom column groups


C.

Assigned pre-queries


D.

Automated role assignment


E.

Data privacy policies


F.

List view


Expert Solution
Questions # 8:

Which of the following actions can a Network Rule NOT perform?

Options:

A.

Filter


B.

Truncate


C.

Alert


D.

Forward


Expert Solution
Questions # 9:

To automate incident creation of alerts in the Respond interface, create

Options:

A.

ESA Rules


B.

Respond Rules


C.

Incident Rules


D.

Reporting Rules


Expert Solution
Questions # 10:

The Context Hub runs as a service on which Host?

Options:

A.

Decoder


B.

Concentrator


C.

ESA


D.

Server


Expert Solution
Viewing page 1 out of 3 pages
Viewing questions 1-10 out of questions