Q1. Which RSA NetWitness component captures and parses data off the wire?
A.Packet Decoder
B. Broker
C. Concentrator
D. Log Decoder
Correct Answer: A
Q2. Which RSA NetWitness component indexes metadata extracted from network or log data and makes it available for querying?
A.Broker
B. Informer
C. Spectrum
D. Concentrator
Correct Answer: D
Q3. To create meta keys that will appear in the Investigation view, you would most commonly edit configuration files on the
A.Packet Decoder
B. Concentrator
C. Broker
D. Log Decoder
Correct Answer: B
Q4. Parsers can be enabled on which of the following?
A.Packet Decoder only
B. Packet Decoder and Log Decoder
C. Packet Decoder and Log Decoder and Concentrator
D. Packet Decoder and Log Decoder and Concentrator and Broker
Correct Answer: B
Q5. To enable reporting alerts to be sent to the Respond interface, you would
A.set up an output action in the Report Engine configuration
B. change the capture interface in Reporting sources
C. configure forwarding of alerts in the Reporting Engine configuration
D. set up an output action in a Report
Correct Answer: C
$ 39
Reviews
There are no reviews yet.