Novell Identity and Security PartnerNet Specialization: Sentinel 6.1 認定 050-728 試験問題:
1. When is Referential data added?
A) In active views
B) After it enters the database
C) At the correlation engine
D) Before it enters the message bus
2. You deploy a correlation rule that looks for 5 failed logins from the same user within 2 minutes. Sentinel receives 5 failed logins from the same user within 1 minute and creates a correlated event. Another failed login ("event X") is received from the same user 10 seconds later. What happens to this event?
A) Event X is added to the initial correlated event.
B) Event X is tagged as a duplicate event and stored in the database
C) Event X is ignored by the Correlation Engine
D) Event X is considered the first failed login in what may become a new correlated event if two more failed logins are received from the same user
3. Which Sentinel objects can contain one or more events? (Choose 2)
A) Ticket
B) Integrator
C) Correlation event
D) Collector
E) Incident
4. Which actions does the Right click option on events within an Active View allow an Administrator to perform? (Choose 3)
A) Create Incident
B) Create iTRAC template
C) Display DAS statistics
D) Email
E) Add to Incident
F) Connect to advisor
5. Which feature allows you to dynamically filter and drill down in a set of historical events?
A) Raw Data Tap
B) Historical Event Query
C) Crystal Reports on Analysis tab
D) Active Browser
質問と回答:
質問 # 1 正解: B | 質問 # 2 正解: B | 質問 # 3 正解: D、E | 質問 # 4 正解: A、D、E | 質問 # 5 正解: B |