1.
Which Sentinel objects can be imported into Sentinel Control Center interface? (Choose 2)
2.
The Sentinel Correlation Engine Architecture is made up which components? (Choose 2)
3.
Which actions are applicable as an iTRAC step? (Choose 4)
4.
What operators can only be used when using the Custom/Freeform option in correlation wizard? (Choose 3)
5.
What does a red line indicate in the tabular part of an active view?
6.
Which statement is true regarding roles used by ITRAC?
7.
You create and deploy a correlation rule with a Create incident action that also indicates an iTRAC workflow. After having the rule on for an hour, you find that the system has created several hundred workflow processes. What steps can you take to address this problem? (Choose 2)
8.
Which Incident field provides a GUI option to configure the items in the drop-down list?
9.
When using the Correlation rule Wizard, which option would you select to create the RuleLG filter (e.rv32=*FW* and e.Severity = 3)
10.
What happens when a user accepts a worklist item assigned to an iTRAC role?