What are functions of Query Viewers? (Select two.)
A. present detailed comparisons of report elements, not possible with the reporting tool
B. provide a baseline analysis of events against which future queries can be compared
C. determine which devices are off-line at any given point in time by querying their status
D. display the Boolean logic behind filters and rules
E. provide a quick way to run SQL queries and identify trends without running reports
In ESM, what allows contextual information to be added to an individual event or group of events in support of workflow or operational metrics?
A. Knowledge Base
B. Templates
C. Annotations
D. Rules
What does a Network Model include? (Select two.)
A. assets
B. destinations
C. zones
D. file resources
When is it useful to schedule rules rather than have them run in real time?
A. when a network device is down
B. when events are occurring less frequently than usual
C. when you anticipate a worm or virus attack
D. when you need to minimize impact on system performance
What is an example of an event-based Data Monitor?
A. rules partial match
B. last n events
C. session reconciliation
D. moving average
Under which circumstances does a Connector use its cache? (Select two.)
A. when a burst of events exceeds what the Manager can handle
B. when the Connector is performing a service restart
C. when the Connector is stopped or disabled
D. when the Connector cannot communicate with its destination
E. when the Connector cannot communicate with the event source
Preserve Raw Events, Turbo Mode, and Limit Event Processing Rate are all examples of which type of Connector options?
A. Processing options
B. Aggregation options
C. Filter conditions
D. Preservation options
Using ESM 6.5 ArcSight Command Center, which drill down type is available?
A. query viewer drilldowns into other query viewers only
B. query viewer drilldowns into channels, reports, dashboards, or other query viewers
C. dashboard drilldowns into channels, reports, query viewers, or other dashboards
D. dashboard drilldowns into other dashboards only
What is the primary function of the ArcSight Manager?
A. It accepts correlated, prioritized events from SmartConnectors with instructions from the ArcSight Console, and writes events to the database.
B. It manages bottlenecks between the connectors, the ArcSight Console, and the ESM Database.
C. It writes incoming events to the database while simultaneously processing events through the Correlation engine.
D. It restores the rule definitions that drive the functioning of ArcSight ESM.
Which file types MUST be included in an Oracle backup? (Select two.)
A. table files
B. data files
C. program files
D. configuration files