1.
Which item is the best practice to follow while restoring archived data to a Cisco Security MARS appliance?
2.
What is the reporting IP address of the device while adding a device to the Cisco Security MARS appliance?
3.
Which statement best describes the case management feature of Cisco Security MARS?
4.
Here is a question that you need to answer. You can click on the Question button to the left to view the question and click on the MARS GUI Screen button to the left to capture the MARS GUI screen in order to answer the question. While viewing the GUI screen capture, you can view the complete screen by use of the left/right scroll bar on the bottom of the GUI screen. Choose the correct answer from among the options. What actions will you take to configure the MARS appliance to send out an alert when the system rule fires according to the MARS GUI screen shown?
5.
Which action enables the Cisco Security MARS appliance to ignore false-positive events by either dropping the events completely or by just logging them to the database?
6.
Which additional steps should you take after manually adding the BR-FW-1 device shown in the MARS GUI screen?
7.
Which incident type is pushed from a local controller to a global controller?
8.
Which statement about the Cisco Security MARS maintenance procedure is true?
9.
Global Controller is a master unit that allows for global management of one or more Local Controllers. Is correct?
10.
Which log agent is installed and configured on the Microsoft Windows IIS server to configure a Microsoft Windows IIS server to publish logs to the Cisco Security MARS?