1.
Once data archiving has been enabled on the Cisco Security MARS appliance when does archiving initially occur?
2.
Match the correct relationship between the Cisco Security MARS terms and their definitions.
1. queries
2. events
3. sessions
4. incidents
5. rules
3.
Which attack can be detected by Cisco Security MARS by use of NetFlow data?
4.
Which option is correct about the case management feature of Cisco Security MARS?
5.
Which protocol is used by Juniper NetScreen IDP to exchange IPS events with the Cisco Security MARS?
6.
Observe the following items carefully, what enables the Cisco Security MARS appliance to profile network usage and detect statistically significant anomalous behavior from a computed baseline?
7.
Which method can be used by the Cisco Security MARS appliance to perform IP address correlation (that is, map IP address translation) across NAT and PAT boundaries?
8.
Which description is correct with regard to Cisco Security MARS and Cisco IPS signature support?
9.
What will occur when you try to run a Cisco Security MARS query that will take a long time to complete?
10.
According to the following diagram displayed on the MARS GUI screen, can you tell me the reason that the Push function is not enabled (grayed out)?