Part 5 Flashcards

1
Q

What are the options for VM Ware right click on a machine?

A

Power off
Shutdown guest
Restart guest
Reset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the CNDOSE server use to host and manage its virtual machines?

A

VMware ESX

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What provides database services for HBSS and record systems info, log info, and reports for all HBSS functions within managed computers?

A

MSSQL microsoft sql

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What proactively guards against intrusion by regularly testing the integrity of the network to uncover and fix potential security weaknesses

A

SCCVI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Used by the DoD to scan assets for compliance

A

ACAS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A GUI is available for easy configuration and management of ESX as well as the virtual machines within

A

vSphere client

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Console Tab

A

To access a virtual machine via vSphere client select the virtual machine from the left pane and click the console tab

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

To allow full screen view of a virtual machine within the vSphere client select the virtual machine from the left pane and select the console icon (computer with a green arrow)

A

Console window

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the prefered method of accessing the virtual machines as it is less resource intensive?

A

Microsoft RDP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the automatic startup process?

A

MSSQL
Then ACAS/SCCVI
Then HBSS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are two primary services?

A

SQL Server

SQL Server Agent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is necessary for HBSS

A

MSSQL is required or ePO wont start

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What provides protection against known virus and malware attacks in the real time, protection from blended attacks and on-demand virus scanning and monitoring capabilities

A

McAffee VSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

T or F

McAffee VSE is active, it puts files found into Quarentine

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What gives admins the ability to know when a wodespread infection may be occuring so they will be able to stop the proliferation of a virus on their networks?

A

Consolidated reporting of events detected by VSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Where are VSE logs inside ePO?

A

Menu > Reporting > Threat Event Log

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What provides network admins and security personnel with tools to prevent, detect, track, report, and remediate malicious computer related activities and incidents across all DoD networks and information systems?

A

HBSS - Host Based Security System

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What occurs when a program or process stores more data in memory than is provided for, forcing excess data to overflow into adjacent memory areas?

A

Buffer overflow

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is when a user or organization is deprived of a resource that they would normally expect to have?

A

Denial of Service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What occurs on a network where the attacker captures or redirects the communications between two computers?

A

Man In The Middle MITM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is designed to protect your environment from viruses, worms, and Trojan horses?

A

VSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are the four default permission sets?

A

Executive reviewer
Global reviewer
Group admin
Group reviewer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

Who can assign existinf permission sets when creating or editing user accounts and when creating or editing permission sets?

A

Global Admins

24
Q

What are a group of permissions that can be granted to any user or Active Directory by assigning it to those user accounts?

A

Permission sets

25
Q

Who provides view permissions to dashboards, events, and contacts as well as information relating to the entire System Tree

A

Executive Reviewer

26
Q

Who has view permissions across ePO features?

A

Global Reviewer

27
Q

Where are custom shipboard permission sets created?

A

Global Network Operation Support Center GNOSC

To assign shipboard administrators the appropriate permissions

28
Q

What cannot be renamed or deleted?

A

Lost and Found

29
Q

Tags allow what?

A

Manually tag managed systems

Tag unmanaged systems that have been added to the System Tree

30
Q

What are two types of tags?

A

Criteria based

Tags without criteria

31
Q

How is the GUID created?

A

During the install process of McAfee, using the MAC address and system name

32
Q

What is an agent that can broadcast wake up calls to other McAfee agents located on the same VLAN or subnet?

A

Super Agent

33
Q

What take an active role in the prevention and reporting of attacks?

A

Active point products

34
Q

Host Intrusion Prevention System Subagent

A

Most significant and active component of HBSS

35
Q

Device Control Module

A

Active agent enforces policy in DLP

36
Q

Asset Baseline Monitor

A

Passive

37
Q

Policy Auditor

A

Passive

38
Q

Rogue System Sensor

A

Passive - monitors layer 2 traffic

39
Q

VSE

A

Active

40
Q

How many agents per subnet

A

2

41
Q

Install.sh

/etc/spawar/secure/dns-3.0.xx/epo

Root as owner

A

700

Manually install on non windows systems

42
Q

Framepkg.exe file contains what?

A

All mecessary information that a client will need to install McAffee agent and communicate with the ePO server

43
Q

What 3 key things does ths framework package contain?

A

Drivers
EPO server info
Encryption keys

44
Q

How often is the default policy enforcememt for CND?

A

15 min

45
Q

What will overwrite if already exists?

A

Agent_machinelog_backup.log

46
Q

What CTO enforces HBSS compliance?

A

JTF GNO CTO 12-1016

47
Q

Do we want embark admins to admin their stuff?

A

Yes

48
Q

Pg 1239…

By creatinf permission sets group admins can have all permissions required to administer their individual assets while preventing access to the rest of the ships network

A

True

49
Q

Embarkable remove their agent before coming onboard

A

Ship admin creates system tree and applies policy before objects are added so it is automatically enforced

50
Q

ABM activity and baseline

A

You need a baseline first before activity as activity shows you since baseline differences

51
Q

What is the main HIP service?

A

Firesvc.exe

52
Q

Host DLP agent service that sends events to server?

A

FCAGS.exe

53
Q

What does SADR stand for?

A

Super Agent Distributed Repository

Master repository > SADR > Agent

Every agent server still communicates to shore it does not bypass

54
Q

What dorectory contains policies that have been consolidatwd dor a given module?

A

Comprehensive

55
Q

What 2 HIP are called Multiple instances or stackable policies can be assigned to a single node are called?

A

IPS Rules and Trusted Applications

56
Q

Policy assigned by Inheritance or Assignment are divided into what 3 parts?

A

Site
Single system
Node with multiple policies

57
Q

Assignment locking prevents other users with appropriate permissions at the same level of the system tree from inadvertently replacing a policy

A

True