nerdexam
IBM

C2150-606 · Question #5

A Guardium administrator must configure real time policy alerts to be sent to a remote SIEM for every SQL statement run on a sensitive object. There is no requirement for the data to be viewed or…

The correct answer is C. Alert Daily. Guardium Version 9 introduced a new policy rule action - ALERT ONLY. This rule action will populate only the message tables and constructs. It will no longer populate Policy Violations tables. With this policy rule action logging Policy Violations in IBM InfoSphere Guardium can…

Rule and Offense Management

Question

A Guardium administrator must configure real time policy alerts to be sent to a remote SIEM for every SQL statement run on a sensitive object. There is no requirement for the data to be viewed or reported on in the Guardium appliance. Which policy action would achieve that task and store the least amount of data in the Guardium internal database?

Options

  • ALog Only
  • BAlert Only
  • CAlert Daily
  • DAlert Per Match

How the community answered

(24 responses)
  • A
    17% (4)
  • B
    4% (1)
  • C
    71% (17)
  • D
    8% (2)

Explanation

Guardium Version 9 introduced a new policy rule action - ALERT ONLY. This rule action will populate only the message tables and constructs. It will no longer populate Policy Violations tables. With this policy rule action logging Policy Violations in IBM InfoSphere Guardium can be avoided. Alert Only - action that will write to message and message_text tables. This action permits all policy violation notifications to be sent to a remote destination. Designed to improve Guardium integration with other database security solutions. Not C: Alert Daily sends notifications only the first time the rule is matched each day. 01.ibm.com/support/knowledgecenter/SSMPHH_9.5.0/com.ibm.guardium95.doc/protect/topics/rul

Topics

#policy actions#SIEM integration#alert configuration#SQL monitoring

Community Discussion

No community discussion yet for this question.

Full C2150-606 Practice