MA0-104 · Question #18
The analyst has created a correlation rule to correlate events from Anti-Virus (AV>, Network Intrusion Prevention (NIPS) and the firewall. While reviewing just firewall events, the analyst notices a…
The correct answer is A. data -source events. Malware performing a network enumeration scan will be visible at the McAfee SIEM as
Question
The analyst has created a correlation rule to correlate events from Anti-Virus (AV>, Network Intrusion Prevention (NIPS) and the firewall. While reviewing just firewall events, the analyst notices a large spike in outbound Command and Control traffic, however, the correlation rule is not triggering The analyst then looks at the Network IPS and the Anti- Virus views and notices there are no alerts for this traffic. Which of the following features of NIPS and AV are most likely turned off?
Options
- Adata -source events.
- BApplication Data Monitor (ADM) events.
- CDatabase Event Monitor (DEM) events.
- DEnhanced Log manager (ELM) entries.
How the community answered
(38 responses)- A76% (29)
- B3% (1)
- C8% (3)
- D13% (5)
Explanation
Malware performing a network enumeration scan will be visible at the McAfee SIEM as
Topics
Community Discussion
No community discussion yet for this question.