nerdexam
McAfee

MA0-104 · Question #18

The analyst has created a correlation rule to correlate events from Anti-Virus (AV>, Network Intrusion Prevention (NIPS) and the firewall. While reviewing just firewall events, the analyst notices a…

The correct answer is A. data -source events. Malware performing a network enumeration scan will be visible at the McAfee SIEM as

Magento Admin HTML

Question

The analyst has created a correlation rule to correlate events from Anti-Virus (AV>, Network Intrusion Prevention (NIPS) and the firewall. While reviewing just firewall events, the analyst notices a large spike in outbound Command and Control traffic, however, the correlation rule is not triggering The analyst then looks at the Network IPS and the Anti- Virus views and notices there are no alerts for this traffic. Which of the following features of NIPS and AV are most likely turned off?

Options

  • Adata -source events.
  • BApplication Data Monitor (ADM) events.
  • CDatabase Event Monitor (DEM) events.
  • DEnhanced Log manager (ELM) entries.

How the community answered

(38 responses)
  • A
    76% (29)
  • B
    3% (1)
  • C
    8% (3)
  • D
    13% (5)

Explanation

Malware performing a network enumeration scan will be visible at the McAfee SIEM as

Topics

#correlation rule#NIPS#command and control traffic#data source events

Community Discussion

No community discussion yet for this question.

Full MA0-104 Practice