1.
How to complete the Initial CS-MARS Configuration? Please choose the proper order.
1. Connect the video and the keyboard to the CS-MARS backplane.
2. Log into CS-MARS using the factory default username and password.
3. Set the IP address for your CS-MARS interface.
4. Power on the CS-MARS device.
5. Set the desired date.
6. Set the time zone or synchronize to an NTP server.
7. Set the desired time.
8. Change the default username and password.
9. Ensure connectivity between your CS-MARS device and your administrative management workstations.
2.
CS-MARS supports the following types of equipment?
3.
Match the correct relationship between the description and each item.
1. This is exclusive to hosts and software applications running on hosts.
2. It is used to either connect to the device for network-based administrative sessions or connect to a remote server on which a file containing the device's configuration is stored.
3. It is the source IP address of event messages, logs, notifications, or traps that originate from the device.
4. It refers to the administrative protocol that Cisco Security MARS uses to access a reporting device or mitigation device.
4.
When you added your routers to the CS-MARS database, if you elected to use SNMP, you must also enable SNMP on the routers themselves. What are the primary purposes?
5.
The following is a question that you need to answer. You can click on the Question button to the left to view the question and click on the MARS GUI Screen button to the left to capture the MARS GUI screen in order to answer question. While viewing the GUI screen capture, you can view the complete screen using the left/right scroll bar on the bottom of the GUI screen. Choose the correct answer from among the options. MARS GUI Screen Which statement can best describe the System Inspection Rule displayed on the MARS GUI screen?
6.
Which option is correct with regard to authenticating Cisco Security MARS accounts with external AAA servers?
7.
While creating queries in Cisco Security MARS, which benefit is of using the dollar variable (as in $TARGET01)?
8.
The Cisco Security Monitoring, Analysis, and Response System (Cisco Security MARS) is an appliance-based, all-inclusive solution that provides unmatched insight and control of your existing security deployment. What Cisco Security MARS event information derived from the reporting device raw message is not passed to Cisco Security Manager to perform Cisco Security Manager policy lookup?
9.
Once data archiving has been enabled on the Cisco Security MARS appliance when does archiving initially occur?
10.
Match the correct relationship between the Cisco Security MARS terms and their definitions.
1. queries
2. events
3. sessions
4. incidents
5. rules