Posts Tagged: ST0-085 Answers

Official 2014 Symantec ST0-085 Dump Free Download(191-200)!

QUESTION 191What is the correct Symantec Security Information Manager incident identification pipeline? A.    collection –> normalization –> rule processing –> attack tracing –> correlation to vulnerabilities “Pass Any Exam. Any Time.” – www.actualtests.com 21Symantec ST0-085 Exam–> incident prioritizationB.    normalization –>…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(181-190)!

QUESTION 181“Pass Any Exam. Any Time.” – www.actualtests.com 2Symantec ST0-085 ExamWhat is the purpose of the critical business assets management feature? A.    It enables automatic identification and prioritization of security threats that impact business- critical applications.B.    It obtains an overview…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(171-180)!

QUESTION 171When should a Symantec Security Information Manager database be restored?“Pass Any Exam. Any Time.” – www.actualtests.com 67Symantec ST0-085 Exam A.    when false-positive data is confirmed to exist in the databaseB.    when there is a hardware failureC.    when the database…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(161-170)!

QUESTION 161On the Symantec Security Information Manager Conditions tab, which two conditions need to be met for a rule to be triggered? A.    Incident TypeB.    Event CriteriaC.    Rule TypeD.    Device EffectedE.    Applicable Licenses Answer: BC QUESTION 162If a conclusion does…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(151-160)!

QUESTION 151The Correlation Manager component of Symantec Security Information Manager performs automated real-time event ______. A.    correlation, aggregation, filtering, and incident creationB.    correlation, asset table analysis, event creation, and user inputC.    correlation, agitation, filtering, and incident managementD.    correlation, aggregation, asset…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(141-150)!

QUESTION 141Which option allows events to be ignored by the Correlation Rules and be no longer processed? A.    Bypass RulesB.    ConditionsC.    CriteriaD.    Event Filters Answer: D QUESTION 142“Pass Any Exam. Any Time.” – www.actualtests.com 57Symantec ST0-085 ExamWhich option in the…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(111-120)!

QUESTION 111You are installing the Symantec Security Information Manager Agent on a Windows platform. A.    c:\Symantec\logB.    c:\Program Files\Symantec\logC.    c:\Program Files\Symantec\sesa\agent\logD.    c:\Symantec\agent\log Answer: C QUESTION 112When installing the Symantec Security Information Manager Agent and Collector on a Windows platform, which command…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(101-110)!

QUESTION 101When troubleshooting the installation of Symantec Security Information Manager (SSIM), the “status” console command displays the status of which critical SSIM service? A.    Information ManagerB.    DB2 databaseC.    Tomcat servlet engineD.    Apache web server Answer: B QUESTION 102When troubleshooting the…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(81-90)!

QUESTION 81What is the difference between Symantec Security Information Manager (SSIM) on-box and off- box collectors?“Pass Any Exam. Any Time.” – www.actualtests.com 36Symantec ST0-085 Exam A.    Off-box collectors are installed on the SSIM products and on-box collectors are installed on…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(71-80)!

QUESTION 71Symantec Security Information Manager automatically escalates security events into incidents based on a number of pre-defined and user-defined _____. A.    rulesB.    eventsC.    incidentsD.    tickets Answer: A QUESTION 72“Pass Any Exam. Any Time.” – www.actualtests.com 33Symantec ST0-085 ExamOnce all rules…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(61-70)!

QUESTION 61Once data is archived and removed from Symantec Security Information Manager, what allows you to access that data? A.    Event Archive ViewerB.    Incident Archive ViewerC.    Correlated Event ViewerD.    Archive Log Viewer Answer: A QUESTION 62Which Symantec Security Information Manager…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(51-60)!

QUESTION 51For which two does Symantec Security Information Manager automatically create values when you manually create a new incident? (Select two.)“Pass Any Exam. Any Time.” – www.actualtests.com 26Symantec ST0-085 Exam A.    Event CreatorB.    Incident CreatorC.    Help desk ticketD.    Rule NameE.   …Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(31-40)!

QUESTION 31Which two default administrative user accounts are created during the installation of Symantec Security Information Manager? (Select two.) A.    Root AdministratorB.    Domain AdministratorC.    SES AdministratorD.    System Administrator E. Local Administrator Answer: BC QUESTION 32When are the effective privileges of…Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(21-30)!

QUESTION 21Which console utility should be used to view the number of dropped packets on the network interface when troubleshooting performance problems on the Symantec Security Information Manager system? A.    ifconfigB.    mii-toolC.    psD.    top Answer: A QUESTION 22“Pass Any Exam….Continue Reading →

Official 2014 Symantec ST0-085 Dump Free Download(1-10)!

QUESTION 1Which database houses incidents and summary data? A.    OracleB.    MySQLC.    MSSQLD.    IBM DB2 Answer: C QUESTION 2Which component sends events to the Event Service for processing? A.    the Symantec Security Information Manager (SSIM) collectorB.    the Symantec Security Information Manager…Continue Reading →