ens Flashcards
(38 cards)
What is XDR?
Platform that integrates, correlates, and contextualizes data and alerts from multiple security prevention, detection and response components.
What is ENS?
Flexible, unified solution that protects devices and endpoints at the network edge, empowering your organization to address complex,, distributed security issues thoroughly, efficiently and quickly.
What components make up ENS?
Firewall, Threat Prevention, Adaptive Threat Protection, Web Control
what is Threat Prevention?
prevents threats from accessing systems, scnas files automatically when they are accessed and runs targeted scans for malware on vlient systems.
What is Firewall?
Monitors network and internet traffic
What is web control?
web filtering and browser protection
What is ATP?
Trace and alert on suspicious activity.
Hunt on all endpoints and take actions immediately .
What are the 4 main platforms ENS supports?
ePO on-prem, MVISION ePO, ePO Cloud, ENS Client UI.
what is TIE (threat Intelligence Exchange)?
oiptional component that optimizes threat prevention by narrowing the gap from malware encounters to containment down to milliseconds.
What is the information TIE provides?
Local and global file reputation
Local and contextual info
Certificate reputation
External Reputation Sources
What is quarantine?
Quarantines affected items, attempt to clean or repair them, or automatically delete them.
What are Firewall rule groups?
Organize Firewall rules for easy management enabling you to apply rules manually or on a schedule, and to only process traffic based on connection type.
T/F
The DXL is required for communication to the TIE server.
True
What is the DXL?
Framework that allows for bidirectional communicastion between endpoints and on a network.
What is the block and allow list?
prevent users from visiting specific URLS or domains oe alway sallow access to sites important to business.
What is rating actions and web category blocking?
Use safety ratings ta nd web categories defined by Trellix to control user access to sites, pages and downloads
What is secire seatch?
automaticaly block risky sites rfom appearing in search results based on safvety rating.
What are site reports?
details show how the safety rating was calc. based on types of threats detected, test results, and other data.
What are some of the threats that ENS can provide protection from?
Malware, suspicious files, suspicious communications, unsafe websites, etc.
What is the workflow for a first time installation?
- Install software server side by checking in the desired product package file to the ePO server
- Update ePO server with the latest content files required for Endpoint Security: AMCore, Exploit Prevention, and ATP content Files
- Deploy the client software with default or custom settings to managed systems either:
a. Remotely with deployment tasks
b. Locally on managed systems with an installation URL - Verify that the client software is installed and up to date on all managed systems
- Configure settings as needed
What is the workflow for an upgrade?
- Confirm that your upgrade path is supported
- Check in the product package files and the McAfee Agent package files (if required) to the ePO server
- Upgrade McAfee Agent, if required
- Manually update your ePO server with the latest content files required for Endpoint Security: Amcore, Exploit Prevention, and ATP content files
- Deploy the client software with default or custom settings to managed systems in one of these ways:
a. Remotely with deployment tasks
b. Locally on managed systems with an installation URL - Verify that the client software is installed and up to date on all managed systems
- Configure settings as needed
What additional steps need to be taken whe upgrading legacy software w/ migrated settings
-Review and prepare legacy settings
-Migrate settings with Endpoint Migration Assistant
-Verify that your settings migrated correctly
What does the Endpoint Upgrade Assistant do?
Upgrade all the systems that meet requirements with a single deployment task, and to plan deployments that ensure compatibility between Endpoint Security and other McAfee products running on managed systems
Before you deploy ENS to a production environment, what should be done first?
You need to deploy the software you plan to install in a test environment or to a test group, then verify the results before deploying it to the larger environment. Testing lets you verify that endpoints upgrade as expected, and make changes as needed, before deploying upgrades to all endpoints