Professional Documents
Culture Documents
HP
Exam HP0-A116
HP ArcSight ESM 6.5 Security Administrator and Analyst
Version: 6.0
When can the online partition compression task fail? (Select two.)
Answer: B,C
Question No : 2
A. Assurance
B. Asset Priority
C. Seriousness
D. Model Confidence
Answer: D
Question No : 3
Which functions are on the right-click menu for an event in the ConsoleViewer panel?
(Select two.)
A. Correlate Events
B. Show Event Details
C. Show Event Chart
D. Annotate Events
E. Prioritize Events
Answer: C,E
Question No : 4
Answer: B
Question No : 5
A. present detailed comparisons of report elements, not possible with the reporting tool
B. provide a baseline analysis of events against which future queries can be compared
C. determine which devices are off-line at any given point in time by querying their status
D. display the Boolean logic behind filters and rules
E. provide a quick way to run SQL queries and identify trends without running reports
Answer: B,E
Question No : 6
Which four basic Event Search elements affect what is displayed in the Search results?
Answer: A
Question No : 7
A. the amount of time to allow before compressing event data for storage
Answer: B
Question No : 8
A. Paused Connectors are responding to the Manager but not sending or caching events.
B. Paused Connectors are responding to the Manager but events are being cached.
C. Paused Connectors are responding to the Manager and sending events.
D. Paused Connectors are not responding to the Manager.
Answer: B
Question No : 9
Answer: B
Question No : 10
The Packages view in the ArcSight Console Navigator provides access to all discrete
resources that are part of a package in a single view. The dependency view toggle in the
Package tree header shows required packages, which are packages on which other
packages depend. What is the visual indicator of this dependency?
Answer: A
Question No : 11
Answer: A,C
Question No : 12
Which Event Schema group contains data fields, which describe the connector reporting an
event?
A. Event
B. Device
C. Source
D. Agent
Answer: D
Question No : 13
Which statements are true about event lifecycle data collection and the event processing
phase? (Select two.)
Question No : 14
Answer: B
Question No : 15
A. It is not required.
B. It is required if users will be accessing ESM through a web browser.
C. It should always be installed on the same server as the ArcSight Manager.
D. It can be used to create rules and view reports.
Answer: B
Question No : 16
Answer: B
A. Notifications
B. Cases
C. Annotations
D. Stages
Answer: D
Question No : 18
Answer: A
Question No : 19
Answer: B
Question No : 20
Question No : 21
When specifying the attributes of a new Active List, you can set TTL days, hours, and
minutes. What is TTL?
Answer: C
Question No : 22
There are three types of ArcSight SmartConnectors. Which type is used primarily to
execute commands on a device to retrieve, modify, or analyze its configuration?
A. Event Connectors
B. Scanner Connectors
C. CounterACT Connectors
D. SNMP Connectors
Answer: C
Question No : 23
A. from within the Manager's server.properties file by using the System Global Variable link
B. from the Fields and Global Variable tab in the Field SetResource or by promoting a
Local Variable
C. from the System Tools menu by using the Create System Global Variable option
D. from the Local Variables tab of the Filter Resource and only by promoting a Local
Variable
Question No : 24
Answer: A
Question No : 25
ESM components fail to consistently restart after a system reboot and require individual
intervention with repeated arcsight_services component restart commands. Which log file
offers troubleshooting information that will help resolve this issue?
A. monit.log
B. server.log
C. arcsight_services.log
D. server.status.log
Answer: A
Question No : 26
Active Channel views and Dashboard views are examples of ArcSight Console Viewer
Panel views. Which other views are associated with the Viewer Panel? (Select two)
A. Simple views
B. Asset views
C. Results views
D. Resource views
E. Combined views
Question No : 27
Which ArcSight Solution works as a GPS for privileged user activity that identifies unusual
hehavior?
A. ThreatDetector
B. Pattern Discovery
C. IdentityView
D. ldentityCorrelation
Answer: B
Question No : 28
A. Knowledge Base
B. Templates
C. Annotations
D. Rules
Answer: C
Question No : 29
A. moving average
B. rules partial match
C. last n events
D. session reconciliation
Answer: C
Answer: D
Question No : 31
Which type of event is displayed in an Active Channel with the following Inline Filter
applied?
A. Logout events
B. Login Success events
C. Login Failure events
D. Account Locked events
Answer: C
Question No : 32
Which statements are true about results in Query Viewers? (Select two.)
Question No : 33
In network modeling, what is a set of nodes with similar characteristics that have IPs
enumerated one after the other?
A. IP group
B. asset group
C. asset range
D. IP range
Answer: C
Question No : 34
A. event-based
B. non-event-based
C. correlation
D. system status
Answer: C
Question No : 35
Answer: C
Where are the resource settings located that determine ArcSight ESM User Password
Policy?
Answer: B
Question No : 37
Answer: A
Question No : 38
Answer: C
Question No : 39
Answer: A
Question No : 40
Which resource defines what a report will look like when generated?
A. layout
B. query
C. template
D. form
Answer: C
Question No : 41
A. They maintain search criteria within the range of data specified by the filter
B. They provide a shorthand view when defining field sets.
C. They limit the range or focus of data sources to be searched.
D. They establish the time range for the search query
Answer: C
Question No : 42
By default, which TCP/IP port is used by ArcSight Command Center to communicate with a
web browser client?
A. 1521
Answer: C
Reference:
http://eromang.zataz.com/2011/06/26/arcsight-logger-and-smartconnectors-questions-and-
answers/
Question No : 43
Answer: A
Question No : 44
Answer: A
Question No : 45
A. categorization
B. aggregation
C. correlation
D. filtration
Answer: C
Question No : 46
A. Join rules link simple rules together; chained rules link join rules.
B. Join rules use Session Lists; chained rules use Active Lists.
C. Chained rules may or may not be join rules that also use Active Lists or rely on
Correlation events generated by other rules.
D. Chained rules result in detailed chains; join rules result in simple chains.
Answer: C
Question No : 47
What is the impact of checking Auto Update on the Search Results header, and selecting a
time of 2 minutes?
A. The time span for this search to complete is limited to 2 minutes, and the current results
are displayed.
B. The current field set is refreshed, and any results that changed in the grid are flagged
with a highlight.
C. The current search query is rerun every 2 minutes following selection of the Auto Update
check box
D. ArcSight Command Center checks for any new software updates occurring in the
previous 2 minutes.
Answer: B
From where are the local ArcSight Console Preference Settings accessed?
A. File Menu
B. Edit Menu
C. Tools Menu
D. View Menu
Answer: C
Question No : 49
What stores information about logons, user actions, and the resulting events in the most
concise way?
A. Event annotations
B. Session Lists
C. Active Lists
D. Cases
Answer: B
Question No : 50
Which pairs of resources can be displayed in the ArcSight Web interface? (Select two.)
Answer: C,E
Question No : 51
Answer: B
Question No : 52
Answer: B
Question No : 53
A. assets
B. destinations
C. zones
D. file resources
Answer: A,C
Question No : 54
What do you use to establish identity, ownership, and criticality of the assets you have
installed on your network?
Answer: C
Question No : 55
A. zone
B. network
C. Asset Range
D. Network Range
Answer: A
Question No : 56
Answer: B,E
Question No : 57
When is it useful to schedule rules rather than have them run in real time?
Answer: C
Question No : 58
Which procedure allows you to terminate a session within a Session List? (Select two)
Answer: A,E
Question No : 59
Which ArcSight ESM user type provides full privileges to use the Command Center, the
ArcSight Console, the Arcsight Web client, and all tools?
A. Web User
B. Normal User
C. Connector Installer
D. Management Tool
Answer: B
Question No : 60
Answer: B
Question No : 61
Answer: A,D
Question No : 62
A. user groups organized to explore and share ideas for extending ArcSight ESM
capabilities
B. coordinated resources that provide monitoring, analysis, and reporting capabilities
C. categories of resources used for monitoring ArcSight system health and status
D. packages that are installed but cannot be modified
Answer: B
Question No : 63
Answer: A
Question No : 64
Which statements are true about SmartConnectors and batching? (Select two.)
Answer: A,C
Question No : 65
During your ESM installation and configuration, none of the Foundation Packages were
selected in the Configuration Wizard. What should you do to install the Foundation
Packages?
A. Manually upload the Foundation Packages to ESM using .arb files exported from
another ESM instance
B. Reapply the ESM product license from Arc Sight Command Center to install the the
Foundation Packages
C. Rerun the Configuration Wizard using Manager setup and select the Foundation
Packages to install
D. Install the Foundation Packages from the ArcSight Console Resource Navigator right-
click menus
Answer: D
Reference:
https://h10120.www1.hp.com/expertone/datacard/Exam/HP0-A116
Question No : 66
A. .xml file
B. .exe file
C. .msc file
D. .arb file
Answer: D
Question No : 67
Answer: C
Question No : 68
What is the procedure to reset all ArcSight Console preferences back to default?
Answer: B
Question No : 69
Answer: B
Question No : 70
What happens when a Connector upgrade that was initiated from within the ArcSight
Console fails?
Answer: A
Question No : 71
Which TCP/IP port is the default when a web browser is used to connect to the ArcSight
Command Center?
A. 443
B. 6443
C. 9443
D. 8443
Answer: D
Question No : 72
Besides managing user accounts, user groups, event storage, and notifications, what else
does the ArcSight Command Center allow you to do?
A. Update the ESM product license, and access the ArcSight Web interface.
B. Status Connectors, configure authentication; monitor events and resources from
Dashboards, and update the ESM product license.
Answer: B
Question No : 73
What is the default port used by the ArcSight ESM Console to connect to the ArcSight
Manager?
A. TCP 8443
B. UDP 8443
C. TCP 9443
D. UDP 9443
Answer: A
Question No : 74
Answer: B
Question No : 75
A. displaying the Boolean logic and conditions linkage behind filters ana rules criteria
B. providing a baseline analysis of events against which future queries can be compared
C. determining which devices are off-line at any given point in time by querying their status
Answer: B,D
Question No : 76
What must be done first to restore the database from an online backup?
Answer: B
Question No : 77
Under which circumstances does a Connector use its cache? (Select two.)
Answer: A,D
Question No : 78
Question No : 79
A. a format into which event data is normalized prior to persistence into storage
B. a collection of SmartConnectors that provide data to the ArcSight Manager
C. a set of events with a common format, collected over a user-defined time period
D. a map correlating IP addresses with devices to designate the source of events
Answer: C
Question No : 80
Answer: C
Question No : 81
What is the default port used when connecting to the ArcSight Web interface?
A. TCP 9443
B. UDP 9443
C. TCP 8443
D. UDP 8443
Answer: A
A. ArcSight Manager
B. ArcSight Console
C. ArcSight Web Server
D. ArcSight Database
Answer: A
Question No : 83
A. zones
B. assets
C. devices
D. customers
E. networks
Answer: D,E
Question No : 84
Answer: D
Question No : 85
What is the default port used to connect the ArcSight Manager to the ArcSight ESM
A. 443
B. 1443
C. 1521
D. 8443
Answer: C
Question No : 86
Which method is used to back up an Oracle database without shutting down the database?
A. sequential backup
B. standalone backup
C. online backup
D. offline backup
Answer: C
Question No : 87
Answer: D
Question No : 88
When using the Query Editor, three sub-tabs provide the options you need to properly set
up the query. What information do these sub-tabs require?
A. when the query should be run; which format the query output should take; how many
Answer: D
Question No : 89
Which functions are on the right-click menu for an event? (Select two.)
A. Correlate Events
B. Show Event Details
C. Annotate Events
D. Prioritize Events
Answer: B,C
Question No : 90
If a username and password are used for authenticating a remote peer, when would you
need to use those credentials a second time?
Answer: D
Question No : 91
Preserve Raw Events, Turbo Mode, and Limit Event Processing Rate are all examples of
which type of Connector options?
Answer: A
Question No : 92
A. ARC_EVENT_DATA
B. ARC_SYSTEM_INDEX
C. ARC_SYSTEM_DATA
D. ARC_EVENT_INDEX
Answer: C
Question No : 93
There are 17 event field groups defined in the ArcSight Event Schema. In which group
would you look for data fields describing an event's importance as assessed by ArcSight
ESM?
A. Category
B. Threat
C. Attacker
D. Event
Answer: B
Question No : 94
During Connector install, which statement is true about the ArcSight Manager's host name
or IP address?
A. It must match the host name or IP address in the ArcSight Manager's SSL certificate.
Answer: A
Question No : 95
A. send notification
B. execute command
C. generate report
D. add to filter
Answer: A,B
Question No : 96
A. Query
B. Layout
C. Form
D. Template
Answer: A
Question No : 97
One of the benefits of SSL technology is authentication. What does authentication do?
Question No : 98
You want your Active Channel to automatically display new events as they arrive at ESM.
Which time parameter should you use to accomplish this?
Answer: C
Question No : 99
Answer: B
Question No : 100
What do the start and end times associated with a notification destination indicate?
A. the period of time the system will wait for a notification response
B. the period of time during which the destination is expected to respond
C. the period of time during which the notification can be sent
D. the period of time during which the notification can be received
Answer: C
Question No : 101
Active Channel views and Dashboard views are examples of Viewer Panel views. Which
other views are associated with the Viewer Panel? (Select two.)
A. Asset views
B. Resource views
C. Combined views
D. Simple views
E. Results views
Answer: B,E
Question No : 102
You want your Active Channel to automatically display new events as they arrive at ESM.
Which time parameter you use to accomplish this?
A. Continuously Evaluate
B. Evaluate Continuously from Attach Time
C. Evaluate $NOW-1h
D. Evaluate Once at Attach Time
Answer: C
Question No : 103
Using SSL technology, information can be communicated over an encrypted channel. What
is SSL?
Answer: A
Which visualization display functions are possible with Dashboards? (Select two.)
A. fade in/out
B. slide show
C. annotate
D. zoom in/out
E. crop
Answer: B,D
Question No : 105
A. evaluates the event stream and creates Correlation events when anomalies are
discovered
B. monitors and displays rule and filter data flow thresholds and latencies
C. summarizes and displays event-based Data Monitor statistics
D. monitors and displays ArcSight ESM system and platform status
Answer: D
Question No : 106
Which ArcSight Foundation should you use to identify traffic and bandwidth usage?
A. Configuration Monitoring
B. Intrusion Monitoring
C. ArcSight Administration
D. Network Monitoring
Answer: D
Question No : 107
A. SmartConnectors
B. events
C. resources
D. nodes
Answer: A
Question No : 108
What must be done to a local Variable before it can be used with multiple resources?
A. It must be renamed.
B. It must be copied.
C. It must be moved it to a new resource.
D. It must be promoted to a Global Variable.
Answer: D
Question No : 109
Answer: B,E
Question No : 110
Which key pair types are valid selections when using the Manager Setup Wizard to create
an SSL key pair? (Select two.)
Answer: B,C
Question No : 111
Which resources can be displayed in the ArcSight Web interface? (Select two.)
Answer: A,C
Question No : 112
Using SSL technology, information can be communicated over an encrypted channel. What
is SSL?
Answer: C
Question No : 113
A. Administrator
B. Analyst
C. Author
Answer: C
Question No : 114
Answer: C
Question No : 115
Which are operators in the ArcSight Common Conditions Editor (CCE)? (Select two.)
A. ELSE
B. AND
C. OR
D. IF
Answer: B,C
Question No : 116
Answer: C
You are unable to see events from a specific device in the Console. The Active Channel
filters are not the cause. Which component should you examine next in order to
troubleshoot this issue?
A. Database
B. SmartConnector
C. Console
D. Device
Answer: B
Question No : 118
In network modeling, which resource is used by MSSP or by users with different cost
centers?
A. networks
B. zones
C. customers
D. asset groups
Answer: C
Question No : 119
What is a good way for an operator or analyst to quickly determine which events must be
addressed first?
Answer: A
Question No : 120
A Composite Solution With Just One Click - Certification Guaranteed 40
HP HP0-A116 : Practice Test
Which components does a Network Model include? (Select two.)
A. assets
B. data monitors
C. dashboards
D. zones
Answer: A,D
Question No : 121
A. FlexConnectors
B. SmartConnectors only
C. the Manager only
D. both SmartConnectors and the Manager
Answer: C
Question No : 122
Which statement is true about how filters are applied by the Connector or by the Manager?
A. When filters are applied by either the Connector or the Manager, events that match the
filter conditions are selected and forwarded for further processing.
B. When filters are applied by either the Connector or the Manager, events that match the
filter conditions are excluded and are not forwarded for further processing.
C. Events that match the Connector filter are excluded and not forwarded further; events
that match the Manager filter are selected for further analysis.
D. Events that match the Connector filter are included and forwarded to the Manager;
events that match the Manager filter are excluded.
Answer: C
Question No : 123
Answer: B
Question No : 124
A. Correlate
B. Concatenate
C. Substring
D. Find
Answer: B
Question No : 125
Report run start time, output format for report results, email distribution for report results,
and report filters are all examples of what?
A. report parameters
B. report formats
C. report data sources
D. report attributes
Answer: A
Question No : 126
A. They are started and stopped independently of the other ArcSight component services.
B. The order in which they are started and stopped is based on event flow.
C. How they are started and stopped depends on whether or not the ArcSight Manager is
running.
D. They are started and stopped in conjunction with the Oracle database services.
Answer: A
Question No : 127
What do the start and end times associated with a notification destination indicate?
A. the period of time that the system waits for a notification response
B. the period of time during which the notification can be received
C. the period of time during which the destination is expected to respond
D. the period of time during which the notification can be sent to the destination
Answer: D
Question No : 128
Answer: A
Question No : 129
Using ESM 6.5 ArcSight Command Center, which drill down type is available?
Answer: B
Question No : 130
The ArcSight Web release version must be the same version as what?
A. ArcSight Manager
B. ArcSight Database
C. ArcSight SmartConnectors
D. ArcSight Console
Answer: A
Question No : 131
A. They always have Start Time, End Time, and Creation Time fields.
B. They must have a key field and a time value.
C. They can share entries with other Session Lists.
D. They can be used as a basis for Trend Queries.
E. They can be used to populate Active Lists.
Answer: C,E
Question No : 132
Which statements are true about user groups and resources? (Select two.)
A. Resources are only visible to a user if the user's group has "Read" permissions for the
resource.
B. A group with "inspect" permission enabled allows all users in that group to edit
Answer: A,C
Question No : 133
Answer: C,D
Question No : 134
What are the three major display components of an Active Channel in the Viewer Panel?
Answer: C
Question No : 135
Answer: A,C
Question No : 136
A. Baselines are created using rules. After the rule is triggered, the resulting action
establishes a baseline against which future rules are evaluated in the Query Viewer.
B. Baselines are created using query results. The baseline from the query is used to create
a new field set definition that can be run against future events.
C. Baselines are created using query results. When a query has one or more baselines
available, you can compare the current results with the baseline.
D. Baselines are created using query results and fed into the Image Editor for the related
Data Monitor.
Answer: C
Question No : 137
A. zones
B. networks
C. devices
D. customers
Answer: B,D
Question No : 138
Answer: B,C
Question No : 139
Answer: C
Question No : 140
A. Event annotations
B. Case Editor
C. Query Viewer
D. Common Conditions Editor
Answer: B
Question No : 141
Which document provides the most detailed instructions for applying an Oracle CPU?
Question No : 142
Which ArcStght Console user settings can be changed in the Preferences Editor?
Answer: D
Question No : 143
Answer: A
Question No : 144
Answer: B,D
What does the ArcSight Manager use to automatically establish identity, ownership, and
criticality of the assets installed on a network?
A. Asset Types
B. Asset Groups
C. Asset Categories
D. Asset Ranges
Answer: C
Question No : 146
Which command should you use to configure notification acknowledgements after the initial
configuration of ArcSight ESM?
A. arcsight managersetup
B. arcsight notifysetup
C. arcsight notifyconfig
D. arcsight setupnotify
Answer: A
Question No : 147
Answer: D
Question No : 148
Answer: A,D
Question No : 149
When exporting search results, what does the "Save to ArcSight Command Center" option
do?
A. automatically exports the file to the Administration > Saved Searches > Saved Search
Files path
B. opens a dialog allowing the user to specify a download location on the browser host
system
C. opens the appropriate output format application to view and optionally save the results
on the user's host
D. automatically exports the file to the ESM host <arcsight
home>/logger/userdata/savedsearch directory
Answer: A
Question No : 150
A. They can store data over longer periods of time than rules or Data Monitors.
B. They can incur processing overhead if not properly scheduled.
C. They always include start time and end time fields.
D. They can be manually populated using the right-click context menu.
E. They can neither be exported nor imported.
Answer: A,C
Question No : 151
A Composite Solution With Just One Click - Certification Guaranteed 50
HP HP0-A116 : Practice Test
Which statement best describes how baselines are established and used in Query
Viewers?
A. Baselines are created using query results, which are fed into the Image Editor for
filtering and display in the related Data Monitor.
B. Baselines are created using rules. After the rule is triggered, the resulting action
establishes a baseline against which future rules are evaluated in the Query Viewer.
C. Baselines are created using query results. When a query has one or more baselines
available, you can compare the current results with a baseline.
D. Baselines are created using query results. The baseline from the query is used to create
a new field set definition that can be run against future events.
Answer: B
Question No : 152
A. It accepts correlated, prioritized events from SmartConnectors with instructions from the
ArcSight Console, and writes events to the database.
B. It manages bottlenecks between the connectors, the ArcSight Console, and the ESM
Database.
C. It writes incoming events to the database while simultaneously processing events
through the Correlation engine.
D. It restores the rule definitions that drive the functioning of ArcSight ESM.
Answer: C
Question No : 153
A. arcsight destinations -n
B. arcsight connectorsetup -w
C. arcsight connectionwizard
D. arcsight connector -d
Answer: B
A. generating a report
B. executing a command
C. sending a notification
D. Creating a vulnerability
E. adding a condition to a filter
Answer: C,E
Question No : 155
A. table files
B. data files
C. program files
D. configuration files
Answer: B,D
Question No : 156
What is a bundle?
Answer: D
Question No : 157
Answer: B
Question No : 158
What is the name of the resource you can use to override the default ArcSight mapping IP
addresses to geographic regions?
A. zones
B. destinations
C. locations
D. categories
Answer: C
Question No : 159
Which processes occur in the first phase of the event lifecycle? (Select two.)
Answer: B,E
Question No : 160
Of the 17 event field groups defined in the ArcSight Event Schema, in which group can
data fields describing an event's importance as assessed by ArcSight ESM be found?
A. Category
Answer: B
Question No : 161
When configuring the ArcSight Database, what is the result of setting the offline archive
period (Days) to Zero?
Answer: B
Question No : 162
Which output formats are available when running a report? (Select two.)
A. XML
B. HTML
C. PDF
D. JPEG
Answer: B,C
Question No : 163
Which ArcSight ESM Resource enables you to perform live monitoring of events?
A. Cases
B. Active Channels
C. Stages
D. Knowledge Base
Question No : 164
Answer: A
Question No : 165
A. lsnrctl status
B. listener status
C. tnsstat
D. oralistener status
Answer: A
Question No : 166
Which ArcSight Foundation should you use to identify and analyze unexpected
modifications to systems, devices, or applications?
A. Configuration Monitoring
B. Intrusion Monitoring
C. ArcSight Administration
D. Network Monitoring
Answer: A
Question No : 167
Answer: D
Question No : 168
Answer: B
Question No : 169
A. The rule can be replayed and verified against real-time events in the Active Channel.
B. The rule can be replayed against historical events in the Active Channel.
C. The rule cannot be tested with the Active Channel because it will create additional
invalid Correlation events.
D. The rule can only be tested with an Active Channel by an administrator.
Answer: B
Question No : 170
A. user directory
B. config directory
C. properties directory
D. jre directory
Answer: B
Question No : 171
How can you restore a new ArcSight Web installation to a previous configuration?
A. copy the old ArcSight Web installation's config directory and cacerts file into the new
installation
B. copy the ArcSight Manager's config directory into the new installation
C. manually reconfigure the new installation
D. connect to the Manager and download the saved configuration
Answer: A
Question No : 172
During which process is the first user created for access to ESM?
Answer: B
Question No : 173
Answer: A
Question No : 174
Answer: A
Question No : 175
Report run start time, output format for report results, email distribution for report results,
and report filters are all examples of what?
A. report parameters
B. report formats
C. report data sources
D. report attributes
Answer: C
Question No : 176
Answer: B
Question No : 177
What is the name of the resource you can use to override the default ArcSight mapping of
IP addresses to geographic regions?
A. zones
B. destinations
C. locations
D. categories
Answer: C
Question No : 178
Answer: B,D
Question No : 179
Which tools are used to view events in ArcSight ESM? (Select two.)
Answer: A,C