AA- Day2 Flashcards

(43 cards)

1
Q

Visibility with SPAN and DHCP

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Device Profile Library (DPL) & Device Classification Engine (DCE) Purpose

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Advanced Classification

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Advanced Criteria : Authentication Events

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Advanced Criteria: Events

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Advanced Criteria: Track changes

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Advanced Criteria: User Directory

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Advanced Criteria: Other Device Information 1

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Advanced Criteria: Other Device Information 2

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Quiz

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Criteria Logic

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Add to List

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Whitelisting and Blacklisting

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Commonly Misconfigured Criteria

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Scripts as Actions

A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Reasons for Irresolvable Criteria

A
  1. Non existent property for the endpoint

> Testing for a windows property on non-windows devices

> Looking for a property on an unmanaged device such as a security camera

  1. Inability to access the endpoint due to

> Network issues

> Incorrect credentials

  1. Endpoint is outside of the deployment’s IP Assignments
  2. Endpoint is not part of the Internal Network
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Setting Counters

A

This Counters action is helpful for policy testing and enforcement

Example: On 1st incident of matching AV not updated we send a notification. On the 2nd incident of matching we block or quarantine the device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

“ACtion” Scheduling

A

scheduling an action is useful when e.g. you run muliple scripts and you need to run them after each other and not all at the same time

19
Q

Key Policy Errors to Avoid

22
Q

FLEXX Lincesing Model

23
Q

Resilience and HA Licensing

24
Q

Options to transition to FLEXX Licensing

A
  • Hardware Refresh
  • Upgrade
  • Migrate
25
Upgrade Preperation (for Licensing to FLEXX migration)
26
ForeScout Upgrade: - From Gui - From CLI
27
Module Licensing when Upgrading
28
Migrating to FLEXX licensing - Steps
29
Quizz
30
Quizz
31
Extended Modules - Notes
32
Available Module Categories
- Advanced Threat Protection (ATD) - Endpoint Protection Platform (EPP) - Mobile Device Management (MDM) - Open Integration Module (OIM):data exchange - Security Information and Event Management (SIEM) - Vulnerability Management (VM) - Privileged Access Management (PAM) - IT SErvice Management (ITSM) - Next Generation Firewall (NGFW) - Client Management Tool (CMT)
33
Extended Modules - Deployment steps (1)
34
Extended Modules - Deployment steps (2)
35
quizz
36
Backups - System Components
37
Backup - One Time
38
Backups - Scheduled Automatic (1/3): Configure Backup Server
39
Backups - Scheduled Automatic (2/3): Configure Encryption Password
40
Backups - Scheduled Automatic (3/3): Set Schedule and back up parameters
41
Backups - Restorin a System Backup
42
Backup Restore - EM Component (1/2)
43
Backup Restore - EM Component (2/2)