ArcSight Quiz

ArcSight Quiz

 



ArcSight Quiz contain set of 10 MCQ questions for ArcSight MCQ which will help you to clear beginner level quiz.



1. Filter condition statements are constructed using ArcSight’s Boolean Logic Editor, mostly known as?

  1. Common Conditions Editor
  2. Vi Editor
  3. VCE
  4. Event editor

2. Data Monitors

  1. Display summaries of events, Assets, and ESM status
  2. Display event data in numerous viewing layouts
  3. Both A and B
  4. None of the above

3. investigation option in arcsight console .

  1. Web Search
  2. Whois
  3. ping
  4. All of the above

4. The Manager handles the logic used to process events as objects called resources

  1. True
  2. False

5. Functions available for grouping and sorting.

  1. Count
  2. Min
  3. Total
  4. Both A and C

6.  _____ are entries in an event-tracking system used to track, investigate, and resolve suspicious events.

  1. Cases
  2. Events
  3. Rules
  4. Triggers

7.  Report Formats.

  1. rtf
  2. xlsx
  3. .bat
  4. .doc

8. Captured views or summaries of data that you can view in multiple formats using either ESM Console or ArcSight Web.

  1. Reports.
  2. Rules
  3. Forms
  4. Views

9.  Types of Rule triggers.

  1. Event
  2. Threshold
  3. Time
  4. All of the Above

10.  In the Active Channel Editor under Filter tab, you can specify an unnamed condition that is applied only to the current active channel.

  1. True
  2. False