Exam Number/Code: 642-544
Exam name: Implementing Cisco Security Monitoring, Analysis and Response System
We provide 100% pass guarantee with our products. That is because we have 100% trust in the abilities of our professional and experience product team, and our record is a proof of that.
How do we maintain 100% Guarantee on Products?
We
at CramBible are committed to our customer's success. Our products are
created with utmost care and professionalism. We utilize the experience
and knowledge of a team of industry professionals from leading
organizations all over the world.
'Success of our customers is our success'
We
understand that your time is precious and our products are intended to
help utilize it in an efficient way. Senior IT professionals craft the
products with great efforts. We strive towards continuous improvement of
our products and service. Customers are really happy with our products but
if one of our customers does not succeed in an exam we fully accommodate
at Single E-mail notification. Additionally we review that product
instantly.
Failing an Exam won't damage you financially as we provide 100% claim for your payment. On request we can provide refund. Think again! What do you have to lose?
Moneyback guarantee:
Simple and Easy! To take
advantage of the guarantee, simply contact Customer Support, requesting
the exam you would like to claim. Send us a scanned copy of your failed
exam and we will promptly proceed to Refund.
CramBible.com Guarantee insures your Success Otherwise Get Moneyback!
3CB is your source for the IT Exam 642-544 exam. With our 642-544 Exam Resources, you can be rest assured that you will Pass your 642-544 Exam on Your First Try. Our Exams are written and formatted by Top senior IT Professionals working in today is prospering companies and data centers. All of our practice exams including the 642-544 exam guarantee you success on your First Try. 642-544 is a challenging exam,with our 642-544 study guide,you can feel safe with our question and answer that will help you in obtaining your successful completion of your 642-544 exam.
642-544 In Summary:
1) There are basically six steps that you should follow to earn your way to certification, namely:
2) Decide which certification is right for you - Get a certification overview
3) Gain hands-on experience with products - View requirements for specific certifications
4) Expand your experience with training -Make use of training materials. There are excellent PDF format materials available from 3cb.com, prepared by experts on their staff.
5) Know what to expect on exams - Review a good study guide.
6) Take your required exam - You can register at either Prometric or Pearson VUE test centers.
7) Free Update for 90-days.
Commitment to this Success:
At this we are committed to you ongoing success. this exams and questions are constantly being updated and compared to industry standards.
Will I pass using your Q & A Product?
Yes crambible
Question and Answers Product is enough to pass the Exam. We recommend a 7
day study time for the candidates for any up-coming Exams.it will help you in
evaluating your preparation before Actual Exam.
How to download Products?
Products can be downloaded
very easily from the Member's Account after logging in. Click on the Order Code or "view" button
and begin download.
What is the format of your products?
Adobe Acrobat PDF files.The guides you download are in rar format originally. rar files are "archives" used for distributing and storing files. So you need an winrar tool 3.0 plus version to extract PDF files from the rar files first before being able to read the PDF guides with Acrobat Reader.
Forget Password?
Please visit Password Recovery.
We'll send you an e-mail message containing new password.
How can I get Discount?
We have combined multiple exam
products for maximum savings; Value Packs are a good way of getting
Discounted Products. However, if you are purchasing 3 or more mixed
products in a single invoice e-mail sales@3cb.com and they will
provide you with a special Discount Price.
What if I fail?
Don't worry about failing; you're
protected by Exam refund guarantee. crambible preparation materials
ensure your success. But if by any undue situation you fail to pass the
corresponding Exam you can claim for refund Guarantee. Click Here
for more details.
What
if I need assistance?
You can always contact Customer Support
or a member of our sales team using either of the following email
contacts:
web@3cb.com
Sales@3cb.com
1. Select Product & Add to Cart
Through "Search" or "Product" to find the subject which you needed, click the button "Add to cart", and add the Q&A to the cart.
2. Login to CramBible
Click "Sing up" on top left corner on website page, becomes the formal member of this website. (the registered users, can click the "login" directly, and then load the website.)
3. Payment
Payment with CramBible is safe, brisk and easy. CramBible provides a secure method of accepting Credit or Debit card Payments through a number of choices such as Visa, MasterCard, and American Express. 2CheckOut, PayPal, Western Union also available.
4. Download
Once the Payment is confirmed, you can access the products instantly in your login.
Enjoy free product and exam updates for the life of your subscription.
Robin at March-3rd 2010
I have passed in my 642-544 Exam in first sitting. Thanks
This webdemo is just a demo data, only for reference and learning, there is no other purposes.
642-544
THE TOTAL NUMBER OF QUESTIONS IS 49
QUESTION NO: 1 Refering to the rule shown on the MARS GUI screen, which
two of the following statements are correct?(Choose two.)
A. This rule will fire if the offset 1 condition occurs "OR" if the offset 2 condition occurs.
B. This rule will fire if the offset 3 condition occurs.
C. The expressions between cells are "AND' while the expressions between items in the
same cell are "OR".
D. This is a user-defined rule.
E. This rule can be deleted after changing its status to "inactive."
Answer: B, C
QUESTION NO: 2 To configure a Microsoft Windows IIS server to publish logs
to the Cisco Security MARS, which log agent is installed and configured on the
Microsoft Windows IIS server?
A. pnLog agent
B. Cisco Security MARS agent
C. SNARE
D. None. Cisco Security MARS is an agentless device.
Answer: C
QUESTION NO: 3 Drop
642-544
Answer: Pending. Send your suggestion to web@crambible.com
QUESTION NO: 4 A Cisco Security MARS appliance cannot access certain devices
through the default gateway. Troubleshooting has determined that this is a Cisco
Security MARS configuration issue. Which additional Cisco Security MARS
configuration will be required to correct this issue?
A. use the Cisco Security MARS GUI or CLI to enable a dynamic routing protocol
B. use the Cisco Security MARS CLI to add a static route
C. use the Cisco Security MARS GUI to configure multiple default gateways
D. use the Cisco Security MARS GUI or CLI to configure multiple default gateways
Answer: B
QUESTION NO: 5 Which action enables the Cisco Security MARS appliance to
ignore false-positive events by either dropping the events completely, or by just
logging them to the database?
A. creating system inspection rules using the drop operation
B. creating drop rules
C. inactivating the rules
D. inactivating the events
E. deleting the false-positive events from the Incidents page
F. deleting the false-positive events from the Event Management page
642-544
Answer: B
QUESTION NO: 6 Which three of the following statements are correct
regarding the Query shown on the MARS GUI screen?(Choose three.)
A. Query will match any source IP address.
B. Query will only match a source IP address of 10.10.10.10.
C. Query will only match a destination IP address range from 10.1.1.1 to 10.1.1.25.
D. Query will only match a destination IP address of 10.1.1.1 OR 10.1.1.25.
E. Query will only not match any services since both TCP-highPort and
UDP-highPort service groups are specified in the Service field.
F. Query will only match any services using the TCP-highPort OR UDP-highPort service
groups.
Answer: A, C, F
QUESTION NO: 7 Which three statements are true about Cisco Security MARS
rules? (Choose three.)
A. There are three types of rules.
B. Rules can be saved as reports.
C. Rules can be deleted.
D. Rules trigger incidents.
E. Rules can be defined using a seed file.
F. Rules can be created using a query.
Answer: A, D, F
QUESTION NO: 8 Which two are required to enable Cisco Security MARS Level 3
operations? (Choose two.)
A. global controller
B. vulnerability scanning
C. NetFlow
D. SNMP community string
E. administrative access to the device
F. Cisco Security Manager
Answer: D, E
642-544
QUESTION NO: 9 What is a zone?
A. A zone represents all the local controllers each global controller is monitoring.
B. A zone is a logical partition within a local controller. Configuring zones allows the
local controller to scale to cover large networks.
C. A zone is an area of a customer network related to one local controller. Each local
controller represents a specific zone.
D. Each zone within the global controller is configured and managed independently.
E. Each zone within the local controller is configured and managed independently.
Answer: C
QUESTION NO: 10 In what two ways can the Cisco Security MARS present the
incident data to the user graphically from the Summary Dashboard? (Select two)
A. event type group matrix
B. incident firing information
C. path information
D. compromised topology information
E. incident vector information
F. system-confirmed true positive information
Answer: C, E
QUESTION NO: 11 Which two of the following statements are TRUE when you
configure the pnreset command on the Cisco Security MARS? (Choose two.)
A. erases the license file
B. sends Cisco IOS data from the Cisco Security MARS database to a network file server
C. enables you to view the status of the Cisco Security MARS processes and how
long the processes have been active
D. sets the debug level that is reported in the logs
E. lets you add or delete disks in the Cisco Security MARS devices that support RAID
configurations without powering down the devices
F. clears, sets, and initializes database structures
Answer: A, F
QUESTION NO: 12 Refer to the exhibit. The Service variables defined are
used for what purpose?
Know what your next step is on the Related certification path.
Other promising certifications to advance and enhance your certification