Chapter 10


"Do I Know This Already?" Quiz

1.

B

2.

D

3.

A

4.

D

5.

C

6.

B

7.

A

8.

C

9.

E

10.

C

Q&A

1.

What are the five CiscoWorks user roles that are relevant to IDS MC and Security Monitor operations?

[click here]

Answer: The CiscoWorks user roles that are relevant to IDS MC and Security Monitor are Help Desk, Approver, Network Operator, Network Administrator, and System Administrator.

2.

What is the minimum amount of RAM and virtual memory recommended for a Windows server running Security Monitor?

[click here]

Answer: The minimum amount of RAM recommended for the Security Monitor server is 1 GB, and the recommended minimum amount of virtual memory is 2 GB.

3.

What is the minimum amount of RAM and virtual memory recommended for a Windows client system used to connect to Security Monitor?

[click here]

Answer: The minimum amount of RAM recommended for a Security Monitor client is 256 MB, and the recommended minimum amount of virtual memory is 400 MB.

4.

Which two browsers are supported for use by the Windows-based Security Monitor client systems?

[click here]

Answer: The supported browsers for Windows-based Security Monitor client systems are Internet Explorer 6.0 with Service Pack 1 and Netscape Navigator 7.1.

5.

What types of devices can you monitor with Security Monitor?

[click here]

Answer: You can monitor the following devices with Security Monitor: Cisco IDS devices, Cisco IOS IDS/IPS devices, Cisco PIX/FWSM devices, Cisco Security Agent Management Centers, and Remote Cisco Security Monitors.

6.

What are the two major protocols used to communicate between Security Monitor and IDS/IPS devices?

[click here]

Answer: To communicate with IDS/IPS devices, Security Monitor uses both RDEP and PostOffice protocols.

7.

Which parameters can you use to configure event rules?

[click here]

Answer: When defining event rules, you can specify the following parameters: Originating Device, Originating Device Address, Attacker Address, Victim Address, Signature Name, Signature ID, and Severity.

8.

What actions can an event rule initiate?

[click here]

Answer: An event rule can initiate any of the following actions: send a notification via e-mail, log a console notification event, and execute a script.

9.

What are the four tasks that you need to perform when adding an event rule?

[click here]

Answer: When adding an event rule, you need assign a name to the event rule, define the event filter criteria, assign the event rule action, and define the event rule threshold and interval.

10.

What device statistical categories can you view using Security Monitor?

[click here]

Answer: Using Security Monitor, you can view the following device statistical categories: Analysis Engine, Authentication, Event Server, Event Store, Host, Logger, Network Access Controller, Transaction Server, Transaction Source, and Web Server.

11.

What are your two options when deleting rows from the Event Viewer, and how are they different?

[click here]

Answer: When deleting rows from the Event Viewer, you can choose Delete From This Grid (which removes the rows from only the current Event Viewer) or Delete From Database (which removes the events from all instances of the Event Viewer, both current and future).

12.

What is the default expansion boundary?

[click here]

Answer: The default expansion boundary specifies the default number of columns in which the cells of a new event are expanded. By default, only the first field of an event is expanded.

13.

Which report template would you use to find out which systems have launched the most attacks against your network in a specified time period?

[click here]

Answer: To identify the systems that have launched the most attacks against your network in a specified time period, you would use the IDS Top Sources Report template.

14.

What icons are used to indicate alarm severity?

[click here]

Answer: The icons used to display alarm severity are a red exclamation point for high severity alerts, a yellow flag for medium severity alerts, and no icon for low severity alerts.

15.

What does the Blank Left check box do when configured as your cell preference?

[click here]

Answer: The Blank Left check box causes the Event Viewer display to show blank columns (after the first row) in which multiple rows have the same value for that column.



CCSP IPS Exam Certification Guide
CCSP IPS Exam Certification Guide
ISBN: 1587201461
EAN: 2147483647
Year: 2004
Pages: 119
Authors: Earl Carter

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net