HP0-A116 Exam Questions
179 real HP0-A116 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1
ESM components fail to consistently restart after a system reboot and require individual intervention with repeated arcsight_services component restart commands. Which log file off...
- Question #2
Of the 17 event field groups defined in the ArcSight Event Schema, in which group can data fields describing an event's importance as assessed by ArcSight ESM be found?
- Question #3
How do asset categorization and event categorization relate to each other?
- Question #4
In ESM, what allows contextual information to be added to an individual event or group of events in support of workflow or operational metrics?
- Question #5
The Packages view in the ArcSight Console Navigator provides access to all discrete resources that are part of a package in a single view. The dependency view toggle in the Package...
- Question #6
What is an example of an event-based Data Monitor?
- Question #7
What stores information about logons, user actions, and the resulting events in the most concise way?
- Question #8
What are functions of Query-Viewers? (Select two.)
- Question #9
Which type of event is displayed in an Active Channel with the following Inline Filter applied? Category Behavior = /Authentication/Verify Category Outcome = /Failure
- Question #10
What is the default port used when connecting to the ArcSight Web interface?
- Question #11
What is a good way for an operator or analyst to quickly determine which events must be addressed first?
- Question #12
What are valid actions for a rule to take? (Select two.)
- Question #13
What are capabilities of the ArcSight Manager? (Select two.)
- Question #14
What is a bundle?
- Question #15
Which user role is responsible for building content within ESM?
- Question #16
When specifying the attributes of a new Active List, you can set TTL days, hours, and minutes. What is TTL?
- Question #17
What do you use to establish identity, ownership, and criticality of the assets you have installed on your network?
- Question #18
What do the start and end times associated with a notification destination indicate?
- Question #19
Preserve Raw Events, Turbo Mode, and Limit Event Processing Rate are all examples of which type of Connector options?
- Question #20
Which process uncovers the relationship between events, infers the significance of those relationships, prioritizes them, and then provides a framework for taking action?
- Question #21
Which file types MUST be included in an Oracle backup? (Select two.)
- Question #22
Which statements are true about escalation levels? (Select two.)
- Question #23
Under which circumstances does a Connector use its cache? (Select two.)
- Question #24
What must be done first to restore the database from an online backup?
- Question #25
Which components does a Network Model include? (Select two.)
- Question #26
Which statement is true about SmartConnectors and FlexConnectors?
- Question #27
Which host user should own the .tararchive from which the ArcSight ESM Suite bin file containing ESM components, and installation and configuration wizards is extracted?
- Question #28
Which statements are true about user groups? (Select two.)
- Question #29
Which procedure allows you to terminate a session within a Session List? (Select two)
- Question #30
Which statements are true about assets? (Select two.)
- Question #31
Which resources can be displayed in the ArcSight Web interface? (Select two.)
- Question #32
When exporting search results, what does the "Save to ArcSight Command Center" option do?
- Question #33
With regard to SmartConnectors, what is roll back?
- Question #34
What can you use to change the stage of a Case?
- Question #35
Which resource defines what a report will look like when generated?
- Question #36
If a username and password are used for authenticating a remote peer, when would you need to use those credentials a second time?
- Question #37
Where are the resource settings located that determine ArcSight ESM User Password Policy?
- Question #38
Which output formats are available when running a report? (Select two.)
- Question #39
Which resources are optional ArcSight compliance solutions delivered as packages? (Select two.)
- Question #40
When configuring the ArcSight Database, what is the result of setting the offline archive period (Days) to Zero?
- Question #41
Which command is used to add a secondary destination to a Connector's configuration?
- Question #42
What are the three types of Data Monitors?
- Question #43
In network modeling, which resource is used by MSSP or by users with different cost centers?
- Question #44
Which command is used to check the status of the TNS Listener?
- Question #45
What do the start and end times associated with a notification destination indicate?
- Question #46
Which statement is true about inline filters?
- Question #47
There are 17 event field groups defined in the ArcSight Event Schema. In which group would you look for data fields describing an event's importance as assessed by ArcSight ESM?
- Question #48
Which statements are true about Session Lists? (Select two)
- Question #49
When using the Query Editor, three sub-tabs provide the options you need to properly set up the query. What information do these sub-tabs require?
- Question #50
What is the effect of the constraints used in an event search query?