ens Flashcards

1
Q

What is XDR?

A

Platform that integrates, correlates, and contextualizes data and alerts from multiple security prevention, detection and response components.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is ENS?

A

Flexible, unified solution that protects devices and endpoints at the network edge, empowering your organization to address complex,, distributed security issues thoroughly, efficiently and quickly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What components make up ENS?

A

Firewall, Threat Prevention, Adaptive Threat Protection, Web Control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what is Threat Prevention?

A

prevents threats from accessing systems, scnas files automatically when they are accessed and runs targeted scans for malware on vlient systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is Firewall?

A

Monitors network and internet traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is web control?

A

web filtering and browser protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is ATP?

A

Trace and alert on suspicious activity.
Hunt on all endpoints and take actions immediately .

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 4 main platforms ENS supports?

A

ePO on-prem, MVISION ePO, ePO Cloud, ENS Client UI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is TIE (threat Intelligence Exchange)?

A

oiptional component that optimizes threat prevention by narrowing the gap from malware encounters to containment down to milliseconds.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the information TIE provides?

A

Local and global file reputation
Local and contextual info
Certificate reputation
External Reputation Sources

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is quarantine?

A

Quarantines affected items, attempt to clean or repair them, or automatically delete them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are Firewall rule groups?

A

Organize Firewall rules for easy management enabling you to apply rules manually or on a schedule, and to only process traffic based on connection type.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

T/F
The DXL is required for communication to the TIE server.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the DXL?

A

Framework that allows for bidirectional communicastion between endpoints and on a network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the block and allow list?

A

prevent users from visiting specific URLS or domains oe alway sallow access to sites important to business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is rating actions and web category blocking?

A

Use safety ratings ta nd web categories defined by Trellix to control user access to sites, pages and downloads

17
Q

What is secire seatch?

A

automaticaly block risky sites rfom appearing in search results based on safvety rating.

18
Q

What are site reports?

A

details show how the safety rating was calc. based on types of threats detected, test results, and other data.

19
Q

What are some of the threats that ENS can provide protection from?

A

Malware, suspicious files, suspicious communications, unsafe websites, etc.

20
Q

What is the workflow for a first time installation?

A
  1. Install software server side by checking in the desired product package file to the ePO server
  2. Update ePO server with the latest content files required for Endpoint Security: AMCore, Exploit Prevention, and ATP content Files
  3. Deploy the client software with default or custom settings to managed systems either:
    a. Remotely with deployment tasks
    b. Locally on managed systems with an installation URL
  4. Verify that the client software is installed and up to date on all managed systems
  5. Configure settings as needed
21
Q

What is the workflow for an upgrade?

A
  1. Confirm that your upgrade path is supported
  2. Check in the product package files and the McAfee Agent package files (if required) to the ePO server
  3. Upgrade McAfee Agent, if required
  4. Manually update your ePO server with the latest content files required for Endpoint Security: Amcore, Exploit Prevention, and ATP content files
  5. Deploy the client software with default or custom settings to managed systems in one of these ways:
    a. Remotely with deployment tasks
    b. Locally on managed systems with an installation URL
  6. Verify that the client software is installed and up to date on all managed systems
  7. Configure settings as needed
22
Q

What additional steps need to be taken whe upgrading legacy software w/ migrated settings

A

-Review and prepare legacy settings
-Migrate settings with Endpoint Migration Assistant
-Verify that your settings migrated correctly

23
Q

What does the Endpoint Upgrade Assistant do?

A

Upgrade all the systems that meet requirements with a single deployment task, and to plan deployments that ensure compatibility between Endpoint Security and other McAfee products running on managed systems

24
Q

Before you deploy ENS to a production environment, what should be done first?

A

You need to deploy the software you plan to install in a test environment or to a test group, then verify the results before deploying it to the larger environment. Testing lets you verify that endpoints upgrade as expected, and make changes as needed, before deploying upgrades to all endpoints

25
Q

What consideration needs to be made prior to deploying ATP?

A

If you plan to install Endpoint Security ATP, decide whether to integrate it with the optional TIE server

26
Q

What are some general considerations to be made prior to the deployment of ENS?

A

-How it will be deployed (platform software, third-party tools, or an installation URL)

-Management Strategy

-Update Strategy

-Whether or not you will use Migration Assistant and Upgrade Assistant

27
Q

T/F: You need to uninstall existing legacy Virus Detection and Firewall products prior to the deployment of ENS.

A

False, You don’t need to uninstall existing virus-detection and firewall products on systems before installing Endpoint Security. The installation wizard detects these products and resolves most conflicts automatically

If incompatible virus detection or firewall software is installed - The wizard tries to uninstall the software. If it can’t, it prompts the user to cancel the installation, uninstall the incompatible software manually from the Windows Control Panel, then resume the installation where it left off

28
Q

T/F: The ENS Install wizard will disable the Windows firewall automatically to prevent conflicts.

A

F

29
Q

If Common Event Enabler (CEE)/Common AntiVirus Agent (CAVA) is running, what does this mean for ENS.

A

You can install ENS with CAVA support by using a command line option.

This disables the blocking cache in the OAS, increases the number of OAS scanning threads to 200, and enables network scanning.

These setting changes are needed for OAS to scan all files from CAVA

30
Q

What happens if HIPS is installed when you attempt to deploy ENS?

A

ENS firewall replaces HIPS firewall, and you can optionally migrate your Firewall settings to the new firewall.

HIPS (without its firewall module) can run side by side with ENS

Note: you are not required to upgrade to ENS firewall or migrate your settings. You can continue to run the HIPS firewall after installing ENS firewall. Whenever HIPS Firewall is installed and enabled, ENS firewall is disabled even if enabled in the policy settings

31
Q

What is the compatibility like with McAfee Client Proxy and ENS

A

If McAfee Client Proxy is installed - Web Control disables itself automatically if it detects a web gateway appliance or if McAfee Client Proxy is installed and in redirection mode

32
Q

What is the compatibility like with McAfee Application Control and McAfee Change Control

A

If McAfee Application Control and McAfee Change Control are running - The system stops responding (hangs) when memory protection features in McAfee Application Control, McAfee Change Control 8.x or 7.x and Endpoint Security or Host Intrusion Prevent are running at the same time.

33
Q

What should you do if you need to run ENS on a system with Application Control and Change Control

A
  • Installation order - Install ENS first, then Application Control and Change Control.
  • If already installed - Disable the Memory protection and Script as Updater features in Application Control and Change Control. See KB81465 for more information.
34
Q

What are the tasks that should be done before installing ENS?

A

-Make sure that systems meet requirements
-Make sure that other products are compatible with Endpoint Security
-Make sure that the software you want to upgrade is supported
-Review settings you want to save
-Run McAfee GetClean
-Run McAfee SysPrep

35
Q

What does the ENS Package Designer do?

A

Endpoint Security Package Designer steps through the process of creating a custom installation file, which you can deploy to managed systems using ePO or third party software

36
Q

What does the ENSConfigTool do?

A

ENS config tool allows you export all policy settings from select product modules to a location that you specify

It is located in the ENS platform folder

37
Q

What does the Migration Assistant Tool do?

A

Use this tool to save (or migrate) settings and assignments for legacy products when upgrading to ENS

38
Q

What does the Upgrade Assistant Tool do?

A

Simplifies and automates many of the tasks required to upgrade managed systems to ENS in complex environments

-Analyze managed systems
-Identify the systems that are ready to upgrade
-Plan, implement, and track product upgrades throughout your environment
-Maintain compatibility on systems running multiple McAfee products and versions
-Deploy using ePO or third party tools