esnlalan
Test por , creado hace más de 1 año

McAfee Advance Threat Defense - Training Quiz

115
0
0
esnlalan
Creado por esnlalan hace más de 9 años
Cerrar

McAfee Advance Threat Defense - Training Quiz

Pregunta 1 de 36

1

Define Malware ?

Selecciona una de las siguientes respuestas posibles:

  • Legitimate tool required for daily operation on windows system

  • Malicious software designed to steal information from owner machine

  • Key-logger

Explicación

Pregunta 2 de 36

1

Which of the following is not a valid Virus Type with reference to computers? ( Choose correct Answer)

Selecciona una de las siguientes respuestas posibles:

  • Multipartite Virus

  • Stealth Virus

  • MERS

  • Polymorphic Virus

Explicación

Pregunta 3 de 36

1

Which of the below best describes Static Analysis of Malware ?

Selecciona una de las siguientes respuestas posibles:

  • Excellent procedure for malware analysis since user does not need to take any event action or execute the file

  • User has to perform Action like event execution for the malware to note its behaviour

  • user should just wait for malware timer to expire and analyze result

Explicación

Pregunta 4 de 36

1

Which of the following is a characteristic of a Trojan?

Selecciona una de las siguientes respuestas posibles:

  • Automatically infects and spreads from computer to compute

  • Appears as a useful program to encourage propegation

  • Can only be spread through a network

  • Cannot be spread via social media

Explicación

Pregunta 5 de 36

1

which of the following below product ATD cannot be integrated with ?

Selecciona una de las siguientes respuestas posibles:

  • McAfee Web Gateway

  • McAfee NSP

  • McAfee Firewall Enterprise

  • McAfee Email Gateway

Explicación

Pregunta 6 de 36

1

Which of the following below statement best describes Static Analysis on MATD Policy ?

Selecciona una de las siguientes respuestas posibles:

  • Static malware analysis utilizes the computational capabilities of the platform to do in moments what a team of researchers could take weeks to accomplish. During static analysis any packed malware is unpacked. Often malware is packed to compress and modify the mal- ware in an attempt to frustrate efforts to analyze it. ATD has phenom- enal success in unpacking malware. The malware code is disassem- bled and reviewed to determine what would happen if the malware was successful in its function. It is important to note that the static analysis is much more than just header analysis

  • Static analysis involves running malware in sandbox environment and extract malicious code out of the file and report to the administrator

  • Static analysis is unique feature of MATD device to perform malware analysis on the malicious file with the help of GAM and GTI only . This identifies the code from the subject file and alert the administrator accordingly.

Explicación

Pregunta 7 de 36

1

Define McAfee GTI ?

Selecciona una de las siguientes respuestas posibles:

  • GTI is McAfee Appliance that can be used with McAfee Products to provide reputation based feature to customer network and information exchange

  • Global threat input

  • GTI is reputation database online available and cant be used with McAfee products

  • Global Threat Intelligence is McAfee’s cloud-based security offering. Using thousands of McAfee intelligent agents and devices, confiden- tial data can be correlated about suspicious files to quickly identify malware and determine changes in the threat landscape. These re- sults can be quickly disseminated throughout the cloud to inhibit the spread of infection

Explicación

Pregunta 8 de 36

1

Which of the below file type is not supported by ATD appliance ?

Selecciona una de las siguientes respuestas posibles:

  • .exe

  • .pub

  • .apk

  • .zip

  • .rar

Explicación

Pregunta 9 de 36

1

Which of the below is Supported OS for ATD VM Creation

Selecciona una de las siguientes respuestas posibles:

  • Windows ME

  • Windows 3.1

  • Windows 10

  • Windows 7 Professional (32bit)

  • None of The Above

Explicación

Pregunta 10 de 36

1

Which of the following is supported language for Windows VM on ATD device ?

Selecciona una de las siguientes respuestas posibles:

  • Arabic

  • Bangla

  • Malay

  • Japanese

Explicación

Pregunta 11 de 36

1

Which of the below is the correct order of ATD Static Analysis scan ?

Selecciona una de las siguientes respuestas posibles:

  • Local Whitelist -->Local Blacklist -->(GAM Emulation)-->GTI Reputation-->Sandbox

  • Local Whitelist -->Local Blacklist -->(sandbox)-->PDF SCAN- Emulation

  • Local Whitelist -->Local Blacklist -->(GAM Emulation)-->GTI Reputation-->MEG

  • Local Whitelist -->Local Blacklist -->(GAM Emulation)-->GTI Reputation-->McAfee AV Scan

Explicación

Pregunta 12 de 36

1

Which port is used for SSH into ATD Appliance ?

Selecciona una de las siguientes respuestas posibles:

  • 21

  • 22

  • 2211

  • 2222

Explicación

Pregunta 13 de 36

1

Which of the following below is the correct BAUD rate for Serial connection to ATD device ?

Selecciona una de las siguientes respuestas posibles:

  • 115000

  • 38400

  • 119200

  • 115200

Explicación

Pregunta 14 de 36

1

Which of the following is correct command to set ATD appliance name( CLI) ?

Selecciona una de las siguientes respuestas posibles:

  • Set Appliance Name

  • Set Name

  • Set sensor name

Explicación

Pregunta 15 de 36

1

Which is the default credential for ATD web admin console login ?

Selecciona una de las siguientes respuestas posibles:

  • admin123

  • admin123$

  • admin

Explicación

Pregunta 16 de 36

1

What of the following mode is currently supported for deployment of ATD appliance ?

Selecciona una de las siguientes respuestas posibles:

  • Inline mode

  • SPAN MODE

  • Standalone mode

  • TAP MODE

Explicación

Pregunta 17 de 36

1

which of the following below is correct credential for CLI login to ATD ( Above Version 3.2.0) ?

Selecciona una de las siguientes respuestas posibles:

  • atdadmin/atdadmin

  • admin/admin

  • cliadmin/atdadmin

Explicación

Pregunta 18 de 36

1

Which of the following below command can be used to view ATD Appliance details ( System IP, Software Version )?

Selecciona una de las siguientes respuestas posibles:

  • Status

  • show system status

  • show

Explicación

Pregunta 19 de 36

1

What is the result of the command "Factorydefault" ?

Selecciona una de las siguientes respuestas posibles:

  • Wipes all default configuration and keeps network configuration only

  • Rest admin credentials and removes all the VM images/profile

  • Resets the active disk to defaults. This deletes all IP addresses, results, logs and VM’s on the active disk and restores it with the backup disk

Explicación

Pregunta 20 de 36

1

What is the maximum number of VM supported on ATD 6000 Appliance ?

Selecciona una de las siguientes respuestas posibles:

  • 30

  • 45

  • 50

  • 60

Explicación

Pregunta 21 de 36

1

what does Reset database option do the ATD device configuration (if checked while upgrade)?

Selecciona una de las siguientes respuestas posibles:

  • The Reset Database checkbox will reset all analyzer policies and VM profiles and delete any analysis samples on the ATD appliance. This will NOT remove any virtual machines that have been uploaded to the appliance.

  • The Reset Database checkbox will reset all analyzer policies and VM profiles and delete any analysis samples on the ATD appliance. This will remove virtual machines that have been uploaded to the appliance.

  • The Reset Database checkbox will reset all analyzer policies and VM profiles and delete any analysis samples on the ATD appliance. This will remove virtual machines and user configuration from appliance.

Explicación

Pregunta 22 de 36

1

Command " Copy to backup"

Selecciona una de las siguientes respuestas posibles:

  • is used to backup the active disk to the backup before an upgrade

  • is used to backup the second disk before an upgrade

  • is used to backup the redundant disk before an upgrade

Explicación

Pregunta 23 de 36

1

What is the correct command to add whitelist entry to ATD Appliance ?

Selecciona una de las siguientes respuestas posibles:

  • whitelist entry update

  • whitelist entry add

  • whitelist add

Explicación

Pregunta 24 de 36

1

Can you delete default ATD admin user account ?

Selecciona una de las siguientes respuestas posibles:

  • Yes

  • No

Explicación

Pregunta 25 de 36

1

Which protocol is used for integration with McAfee Web Gateway and ATD ?

Selecciona una de las siguientes respuestas posibles:

  • SMP

  • SAML

  • REST

Explicación

Pregunta 26 de 36

1

What is benefit of ePO integration with ATD device ?

Selecciona una de las siguientes respuestas posibles:

  • ePO provides user name to ATD

  • User Machine MAC Address

  • TARGET OS can be provided to ATD

Explicación

Pregunta 27 de 36

1

ATD Architecture is based on

Selecciona una de las siguientes respuestas posibles:

  • VMWARE

  • HYPER-V

  • Type 1 Hypervisor

Explicación

Pregunta 28 de 36

1

Define Support Bundle ?

Selecciona una de las siguientes respuestas posibles:

  • The support bundle is a .tgz of the system log files, any diagnostic files and some additional miscellaneous log files for McAfee Customer Support. After clicking the button a prompt is given for a McAfee Support Ticket number

  • The support bundle is a .tgz of the system log files, VM image files and some additional information for McAfee Customer Support. After clicking the button a prompt is given for a McAfee Support Ticket number

  • The support bundle is a .tgz of the system log files, audit log files and some additional information for McAfee Customer Support. After clicking the button a prompt is given for a McAfee Support Ticket number

Explicación

Pregunta 29 de 36

1

which of the following is not a default user account on ATD appliance ?

Selecciona una de las siguientes respuestas posibles:

  • admin

  • mwg

  • nsp

  • atdadmin

  • apoadmin

Explicación

Pregunta 30 de 36

1

which of the following is not a default role on ATD appliance ?

Selecciona una de las siguientes respuestas posibles:

  • Admin

  • Web Access

  • Ftp Access

  • Restful Access

  • Telnet Access

Explicación

Pregunta 31 de 36

1

What is real internet mode ?

Selecciona una de las siguientes respuestas posibles:

  • If Internet connectivity is enabled in the analyz- er profile, McAfee Advanced Threat Defense uses this mode. McAfee Advanced Threat Defense provides a real Internet connection through the management port, which is publicly routed as directed by the ATD network configuration. The interface port that ATD uses to connect to the internet using this mode can be designated in ATD 3.2.0 and later.

  • If Internet connectivity is enabled in the analyz- er profile, McAfee Advanced Threat Defense uses this mode. McAfee Advanced Threat Defense provides a real Internet connection through the management port, which is publicly routed as directed by the ATD network configuration. The interface port that ATD uses to connect to the internet using this mode can be designated in ATD 3..0.4 only

  • If Internet connectivity is enabled in the analyz- er profile, McAfee Advanced Threat Defense uses this mode. McAfee Advanced Threat Defense provides a real Internet connection through the management port, which is publicly routed as directed by the ATD network configuration. The interface port that ATD uses to connect to the internet using this mode can be designated in ATD 3.0.5 only

Explicación

Pregunta 32 de 36

1

what is the property used in McAfee Web Gateway ruleset for Anti malware threshold trigger ?

Selecciona una de las siguientes respuestas posibles:

  • Antimalware.Proactive. Absolute

  • Antimalware.Proactive. Minimum

  • Antimalware.Proactive. Probablility

Explicación

Pregunta 33 de 36

1

What is the value of Scan timeout of MWG appliance for ATD analysis results ?

Selecciona una de las siguientes respuestas posibles:

  • 10 hours

  • 10 seconds

  • 20 minutes

  • 5 seconds

  • 10 minutes

Explicación

Pregunta 34 de 36

1

what is minimum version of Web Gateway required to support ATD device ?

Selecciona una de las siguientes respuestas posibles:

  • 7.1.0

  • 7.3.0

  • 7.3.2

  • 7.4.x

Explicación

Pregunta 35 de 36

1

What is maximum supported file size limit for malware analysis (send file) from NSP ?

Selecciona una de las siguientes respuestas posibles:

  • 10 MB

  • 15 MB

  • 20 MB

  • 128 MB

  • 25 MB

Explicación

Pregunta 36 de 36

1

ATD appliances are only involved in the Detection & Analysis step of an Incident Response cycle ?

Selecciona una de las siguientes respuestas posibles:

  • True

  • False

Explicación