Exam Code : 050-11-CARSANWLN01
Exam Name : RSA NetWitness Logs & Network Administrator
Vendor Name :
"RSA"
050-11-CARSANWLN01 Dumps
050-11-CARSANWLN01 Braindumps 050-11-CARSANWLN01 Real Questions 050-11-CARSANWLN01 Practice Test
050-11-CARSANWLN01 Actual Questions
killexams.com
RSA NetWitness Logs & Network Administrator
https://killexams.com/pass4sure/exam-detail/050-11-CARSANWLN01
To add an action to the right-click menu in the Investigation Ul. create a
Right-click action
Profile
Context Hub List
Context Menu Action
Parsers can be enabled on which of the following?
Packet Decoder only
Packet Decoder and Log Decoder
Packet Decoder and Log Decoder and Concentrator
Packet Decoder and Log Decoder and Concentrator and Broker
Which of the following choices describes a fundamental unit of network traffic transmitted from one IP device to another?
Packet
Chart
Session
Schedule
What are the data sources available in RSA NetWitness when creating a Reporting Engine rule?
Short, Long, Truncated
IPDB, ODBC, FileReader
Broker, Concentrator, Decoder
NetWitness DB, Warehouse DB, Respond DB
Which of the following rule types relies on two or more events occurring within a specified window of time?
Network Rule
Application Rule
Correlation Rule
BPF Filter Rule
What are the two basic operations you might perform to make use of a Live resource?
move and copy
download and enable
save and apply
subscribe and deploy
Service Groups are used primarily for
grouping metadata from specified hosts
deploying Live resources to specified services
grouping hosts for batch configuration
grouping hosts for monitoring performance in the Health and Wellness view
The NetWitness Trust Model is based on
User ID
User Role
IP address
Hardware address
What are three important things to configure on a Log Decoder'?
Capture Auto-Start. Service Parsers, Capture Interface
Capture Settings. Aggregation Auto-Start. Profile settings
Investigation Settings. Capture Settings. Service Parsers
Aggregation Auto-Start. Capture Settings. Investigation Settings
Where do you define dynamic charts for real-time display in Dashboards?
Default Dashboard
MONITOR > Reports > Manage > Charts
MONITOR > Reports > Charts > View
CONFIGURE > ESA Rules