<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cisco CCSP  Exams &#187; 642-513</title>
	<atom:link href="http://www.ccsp.name/tag/642-513/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ccsp.name</link>
	<description>PassGuide materials:Successful for Cisco Certification or Full Refund for you</description>
	<lastBuildDate>Thu, 09 Sep 2010 08:32:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Testking Cisco CCSP 642-513 Exam</title>
		<link>http://www.ccsp.name/testking-cisco-ccsp-642-513-exam</link>
		<comments>http://www.ccsp.name/testking-cisco-ccsp-642-513-exam#comments</comments>
		<pubDate>Wed, 27 Aug 2008 06:28:24 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>
		<category><![CDATA[642-513]]></category>
		<category><![CDATA[hips]]></category>
		<category><![CDATA[testking]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/testking-cisco-ccsp-642-513-exam/</guid>
		<description><![CDATA[Exam 642-513: Securing Hosts Using Cisco Security Agent Exam (HIPS)
Related Certifications:  CCSP
Number of Questions: 65-75
Duration: 75 minutes
Exam Topics Include:
1.  Describe and deploy the CSA and CSA Management Console (MC) products
2.  Use CSA MC to configure groups, manage hosts, and build policies
3.  Use CSA Management Console to configure rules
4.  Define application [...]]]></description>
			<content:encoded><![CDATA[<p>Exam 642-513: Securing Hosts Using Cisco Security Agent Exam (HIPS)</p>
<p>Related Certifications:  CCSP</p>
<p>Number of Questions: 65-75</p>
<p>Duration: 75 minutes</p>
<p>Exam Topics Include:</p>
<p>1.  Describe and deploy the CSA and CSA Management Console (MC) products</p>
<p>2.  Use CSA MC to configure groups, manage hosts, and build policies</p>
<p>3.  Use CSA Management Console to configure rules</p>
<p>4.  Define application classes and work with variables</p>
<p>5.  Use CSA Analysis and define and generate reports and alerts<span id="more-40"></span></p>
<p>The Securing Hosts Using <a href="http://www.ccsp.name">Cisco Security </a>Agent exam 642-513 HIPS is one of the optional exams associated with the Cisco Certified Security Professional certification.  This exam tests a candidate&#8217;s knowledge and ability to describe, configure, and verify the Cisco Security Agent product.</p>
<p>Let <a href="http://www.certbible.org">TestKing </a>help you to become CCSP certified.  The <a href="http://www.ccsp.name/tag/642-513">TestKing 642-513</a> exam products are designed to maximize your learning productivity and focus only on the important aspects that will help you to pass your exam, the first time.  We will provide you with exam questions and verified answers, with detailed explanations, that reflect the actual exam. These questions and answers provide you with the experience of taking the actual test. Our exam guides are not just questions and answers. Our questions have detailed explanations provided by our certified industry experts, ensuring that you fully understand the questions and the concept behind the questions.<br />
QUESTION NO: 1<br />
Which Agent kit should be installed on the CSA MC?<br />
A. the default Windows Agent kit<br />
B. the default UNIX Agent kit<br />
C. the default CSA Agent kit<br />
D. the Agent kit that is automatically installed<br />
Answer: D<br />
QUESTION NO: 2<br />
What is the purpose of the Compare tool?<br />
A. to save data that has been configured<br />
B. to compare individual rules<br />
C. to compare individual rule modules<br />
D. to compare and merge configurations<br />
Answer: D<br />
QUESTION NO: 3<br />
Which operating system does not allow Query User options?<br />
A. OS2<br />
B. Windows<br />
C. Linux<br />
D. Solaris<br />
E. HPUX<br />
Answer: D<br />
QUESTION NO: 4<br />
Which view within the CSA MC allows users to see a view of event records based on<br />
filtering criteria such as time and severity?<br />
A. Event Summary<br />
B. Event Log<br />
C. Event Monitor<br />
D. Event Sets<br />
E. Event Alerts<br />
Answer: B<br />
QUESTION NO: 5<br />
Which three operating systems are supported for deployment of CSA? (Choose<br />
three.)<br />
A. OS2<br />
B. HPUX<br />
C. Linux<br />
D. Solaris<br />
E. AIX<br />
F. Windows<br />
Answer: C, D, F<br />
QUESTION NO: 6<br />
Which two items make up Agent kits? (Choose two.)<br />
A. groups<br />
B. hosts<br />
C. policies<br />
D. rules<br />
E. network shim<br />
Answer: A, E<br />
QUESTION NO: 7<br />
For which layers of the OSI reference model does CSA enforce security?<br />
A. Layer 1 through Layer 4<br />
B. Layer 1 through Layer 7<br />
C. Layer 2 through Layer 4<br />
D. Layer 3 through Layer 7<br />
Answer: D<br />
QUESTION NO: 8<br />
What is a benefit of putting hosts into groups?<br />
A. There is no need to configure rules<br />
B. There is no need to configure rule modules<br />
C. The administrator can deploy rules in test mode<br />
D. The administrator does not have to deploy rules in test mode<br />
Answer: C<br />
QUESTION NO: 9<br />
What is the purpose of network access control rules?<br />
A. to control access to network services<br />
B. to control access to network addresses<br />
C. to control access to both network services and network addresses<br />
D. to control access to networks<br />
Answer: C<br />
QUESTION NO: 10<br />
What action must happen before a system that has CSA can download policies<br />
configured for it?<br />
A. The system must be rebooted<br />
B. The system must install Agent kits<br />
C. The system must be polled by the CSA MC<br />
D. The system must register with the CSA MC<br />
Answer: D<br />
QUESTION NO: 11<br />
Which action do you take when you are ready to deploy your CSA configuration to<br />
systems?<br />
A. select<br />
B. clone<br />
C. deploy<br />
D. generate rules<br />
Answer: D</p>
<p><a href="http://www.testking.name/category/cisco/">Testking cisco </a>Interactive Testing Engine Included!<br />
69 Questions<br />
Updated : 03/14/2008<br />
Price : $87.99 $79.99</p>
<p>Free Down:<a href="http://testking.name/adhit.php?i=0&#038;c=MjEyMnxFNzAy&#038;ad_channel=603">Testking Cisco CCSP 642-513</a><br />
<a href="http://www.pass4sure.com/s.php?userid=100042&#038;dest=http://www.pass4sure.com/642-513.html&#038;type=1">Pass4sure ccsp 642-513 V2.93</a></p>
<p>password:www.certbible.net</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/testking-cisco-ccsp-642-513-exam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pass4sure  Cisco  CCSP  642-513   Exam</title>
		<link>http://www.ccsp.name/pass4sure-cisco-ccsp-642-513-exam</link>
		<comments>http://www.ccsp.name/pass4sure-cisco-ccsp-642-513-exam#comments</comments>
		<pubDate>Tue, 26 Aug 2008 15:10:52 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Practice Tests]]></category>
		<category><![CDATA[642-513]]></category>
		<category><![CDATA[hips]]></category>
		<category><![CDATA[pass4sure]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/pass4sure-cisco-ccsp-642-513-exam/</guid>
		<description><![CDATA[Securing Hosts Using Cisco Security Agent Exam (HIPS) : 642-513 Exam
Exam Number/Code: 642-513
Exam Name: Securing Hosts Using Cisco Security Agent Exam (HIPS)
VUE Code: 642-513
Questions Type: Single choice, Multiple choice, Simulate,
Question Numbers of Real-exam: 65-75 questions
&#8220;Securing Hosts Using Cisco Security Agent Exam (HIPS)&#8221;, also known as 642-513 exam, is a Cisco certification.
Preparing for the 642-513 exam? [...]]]></description>
			<content:encoded><![CDATA[<p>Securing Hosts Using Cisco Security Agent Exam (HIPS) : 642-513 Exam<span id="more-28"></span></p>
<p>Exam Number/Code: <a href="http://www.ccsp.name/tag/642-513">642-513</a><br />
Exam Name: Securing Hosts Using Cisco Security Agent Exam (<a href="http://www.ccsp.name/tag/hips">HIPS</a>)<br />
VUE Code: 642-513<br />
Questions Type: Single choice, Multiple choice, Simulate,<br />
Question Numbers of Real-exam: 65-75 questions</p>
<p>&#8220;Securing Hosts Using Cisco Security Agent Exam (HIPS)&#8221;, also known as 642-513 exam, is a Cisco certification.<br />
Preparing for the 642-513 exam? Searching 642-513 Test Questions, 642-513 Practice Exam, 642-513 Dumps?<br />
The Securing Hosts Using Cisco Security Agent exam 642-513 HIPS is one of the exams associated with the Cisco Certified Security Professional certification. Candidates can prepare for this exam by taking the HIPS v2.0 course. This exam tests a candidate&#8217;s knowledge and ability to describe, configure, and verify the Cisco Security Agent product.<br />
QUESTION: 1<br />
Which of these is a reason for using groups to administer Agents? </p>
<p>A.   to link similar devices together<br />
B.   to complete configuration changes on groups instead of hosts<br />
C.   to complete the same configuration on like items<br />
D.   to apply the same policy to hosts with similar security requirements </p>
<p>Answer: D </p>
<p>QUESTION: 2<br />
Which three items make up rules? (Choose three.) </p>
<p>A.   variables<br />
B.   applications<br />
C.   application classes<br />
D.   rule modules<br />
E.   policies<br />
F.   actions<br />
Answer: A, C, F </p>
<p>QUESTION: 3<br />
Which action do you take when you are ready to deploy your CSA configuration to<br />
systems? </p>
<p>A.   select<br />
B.   clone<br />
C.   deploy<br />
D.   generate rules </p>
<p>Answer: D </p>
<p>QUESTION: 4<br />
Which one of the five phases of an attack attempts to become resident on a target? </p>
<p>A.   probe phase<br />
B.   penetrate phase<br />
C.   persist phase<br />
D.   propagate phase<br />
E.   paralyze phase </p>
<p>Answer: C </p>
<p>QUESTION: 5<br />
What is the purpose of the Audit Trail function? </p>
<p>A.  to generate a report listing events matching certain criteria, sorted by event<br />
severity<br />
B.   to generate a report listing events matching certain criteria, sorted by group<br />
C.   to generate a report showing detailed information for selected groups<br />
D.   to display a detailed history of configuration changes </p>
<p>Answer: D </p>
<p>QUESTION: 6<br />
In which type of rules are network address sets used? </p>
<p>A.   COM component access control rules<br />
B.   connection rate limit rules<br />
C.   network access control rules<br />
D.   file control rules<br />
E.   file access control rules </p>
<p>Answer: C </p>
<p>QUESTION: 7<br />
Which three of these does the buffer overflow rule detect on a UNIX operating<br />
system, based on the type of memory space involved? (Choose three.) </p>
<p>A.   location space<br />
B.   stack space<br />
C.   slot space<br />
D.   data space<br />
E.   heap space<br />
F.   file space </p>
<p>Answer: B, D, E </p>
<p>QUESTION: 8<br />
When should you use preconfigured application classes for application deployment<br />
investigation? </p>
<p>A.   never<br />
B.   always<br />
C.   only for specific applications<br />
D.   only when applications require detailed analysis </p>
<p>Answer: A </p>
<p>Which systems with specific operating systems are automatically placed into<br />
mandatory groups containing rules for that operating system? (Choose three.) </p>
<p>A.   OS2<br />
B.   HPUX<br />
C.   Solaris<br />
D.   Mac OS<br />
E.   Linux<br />
F.   Windows </p>
<p>Answer: C, E, F </p>
<p>QUESTION: 11<br />
What is the purpose of network access control rules? </p>
<p>A.   to control access to network services<br />
B.   to control access to network addresses<br />
C.   to control access to both network services and network addresses<br />
D.   to control access to networks </p>
<p>Answer: C </p>
<p>QUESTION: 12<br />
What is the purpose of the Compare tool? </p>
<p>A.   to save data that has been configured<br />
B.   to compare individual rules<br />
C.   to compare individual rule modules<br />
D.   to compare and merge configurations </p>
<p>Answer: D </p>
<p>QUESTION: 13<br />
If a Solaris or Windows system is not rebooted after CSA installation, which three<br />
rules are only enforced when new files are opened, new processes are invoked, or<br />
new socket connections are made? (Choose three.) </p>
<p>A.   COM component access rules<br />
B.   network shield rules<br />
C.   buffer overflow rules<br />
D.   network access control rules<br />
E.   file access control rules<br />
F.   demand memory access rules </p>
<p>Answer: C, D, E </p>
<p>QUESTION: 14<br />
For which operating system is the network shield rule available? </p>
<p>A.   OS2<br />
B.   Windows<br />
C.   Linux<br />
D.   Solaris </p>
<p>Answer: D </p>
<p>QUESTION: 15<br />
What is the maximum number of characters that a policy name can contain? </p>
<p>A.   24<br />
B.   32<br />
C.   48<br />
D.   64 </p>
<p>Answer: D </p>
<p>QUESTION: 16<br />
What information is logged for registry access control? </p>
<p>A.   port and direction<br />
B.   registry key<br />
C.   registry access events<br />
D.   PROGID/CLSID </p>
<p>Answer: B </p>
<p>QUESTION: 17<br />
Which protocol should never be disabled on the CSA MC? </p>
<p>A.   SSH<br />
B.   Telnet<br />
C.   IPSec<br />
D.   SSL </p>
<p>Answer: D </p>
<p>QUESTION: 18<br />
Which information is logged for file access control? </p>
<p>A.   port and direction<br />
B.   registry key<br />
C.   process path<br />
D.   PROGID/CLSID </p>
<p>Answer: C </p>
<p>QUESTION: 19<br />
Which action must be taken before a host can enforce rules when it has been moved<br />
to a new group? </p>
<p>A.   save<br />
B.   generate rules<br />
C.   deploy<br />
D.   clone </p>
<p>Answer: B </p>
<p>QUESTION: 20<br />
What is a benefit of putting hosts into groups? </p>
<p>A.   There is no need to configure rules.<br />
B.   There is no need to configure rule modules.<br />
C.   The administrator can deploy rules in test mode.<br />
D.   The administrator does not have to deploy rules in test mode. </p>
<p>Answer: C </p>
<p>With the complete collection of questions and answers, Pass4sure has assembled to take you through 69 Q&#038;As to your 642-513 Exam preparation. In the 642-513 exam resources, you will cover every field and category in CCSP helping to ready you for your successful Cisco Certification.<br />
Questions and Answers : 69 Q&#038;As<br />
Updated: March 27th , 2008<br />
Market Price: $129.99<br />
Member Price: $89.99</p>
<p>Free Down:<a href="http://www.pass4sure.com/s.php?userid=100042&#038;dest=http://www.pass4sure.com/642-513.html&#038;type=1">Pass4sure  Cisco  CCSP  642-513   v2.93<br />
</a><br />
<a href="http://testking.name/adhit.php?i=0&#038;c=MjEyMnxFNzAy&#038;ad_channel=603">Testking 642-513</a></p>
<p>password:www.certbible.net</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/pass4sure-cisco-ccsp-642-513-exam/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco Security Agent</title>
		<link>http://www.ccsp.name/cisco-security-agent</link>
		<comments>http://www.ccsp.name/cisco-security-agent#comments</comments>
		<pubDate>Tue, 26 Aug 2008 12:25:09 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Study Books]]></category>
		<category><![CDATA[642-513]]></category>
		<category><![CDATA[hips]]></category>

		<guid isPermaLink="false">http://www.ccsp.name/cisco-security-agent/</guid>
		<description><![CDATA[Prevent security breaches by protecting endpoint systems with Cisco Security Agent, the Cisco host Intrusion Prevention System
* Secure your endpoint systems with host IPS
* Build and manipulate policies for the systems you wish to protect
* Learn how to use groups and hosts in the Cisco Security Agent architecture and how the components are related
* Install [...]]]></description>
			<content:encoded><![CDATA[<p>Prevent security breaches by protecting endpoint systems with Cisco Security Agent, the Cisco host Intrusion Prevention System</p>
<p>* Secure your endpoint systems with host IPS<br />
* Build and manipulate policies for the systems you wish to protect<br />
* Learn how to use groups and hosts in the Cisco Security Agent architecture and how the components are related<br />
* Install local agent components on various operating systems<br />
* Explore the event database on the management system to view and filter information<br />
* Examine Cisco Security Agent reporting mechanisms for monitoring system activity<br />
* Apply Application Deployment Investigation to report on installed applications, hotfixes, and service packs<br />
* Collect detailed information on processes and see how they use and are used by system resources<br />
* Create and tune policies to control your environment without impacting usability<br />
* Learn how to maintain the Cisco Security Agent architecture, including administrative access roles and backups<span id="more-17"></span></p>
<p><img src="http://www.ciscopress.com/ShowCover.asp?isbn=1587052059&amp;type=a" /></p>
<p><a href="http://www.ccsp.name">Cisco Security </a>Agent presents a detailed explanation of Cisco Security Agent, illustrating the use of host Intrusion Prevention Systems (IPS) in modern self-defending network protection schemes. At the endpoint, the deployment of a host IPS provides protection against both worms and viruses. Rather than focusing exclusively on reconnaissance phases of network attacks a host IPS approaches the problem from the other direction, preventing malicious activity on the host by focusing on behavior. By changing the focus to behavior, damaging activity can be detected and blocked–regardless of the attack.</p>
<p>Cisco Security Agent is an innovative product in that it secures the portion of corporate networks that are in the greatest need of protection–the end systems. It also has the ability to prevent a day-zero attack, which is a worm that spreads from system to system, taking advantage of vulnerabilities in networks where either the latest patches have not been installed or for which patches are not yet available. Cisco Security Agent utilizes a unique architecture that correlates behavior occurring on the end systems by monitoring clues such as file and memory access, process behavior, COM object access, and access to shared libraries as well as other important indicators.</p>
<p>Cisco Security Agent is the first book to explore the features and benefits of this powerful host IPS product. Divided into seven parts, the book provides a detailed overview of Cisco Security Agent features and deployment scenarios. Part I covers the importance of endpoint security. Part II examines the basic components of the Cisco Security Agent architecture. Part III addresses agent installation and local use. Part IV discusses the Cisco Security Agent management console’s reporting and monitoring capabilities. Part V covers advanced Cisco Security Agent analysis features. Part VI covers Cisco Security Agent policy, implementation, and management. Part VII presents additional installation and management information.</p>
<p>Whether you are evaluating host IPS in general or looking for a detailed deployment guide for Cisco Security Agent, this book will help you lock down your endpoint systems and prevent future attacks.</p>
<p>“While there are still a lot of ways that security can go wrong, Cisco Security Agent provides a defense even when something is wrong. I remember the email that came around from our system administrator that said, ‘There’s something attacking our web server. We’re not sure what it is, but Stormwatch is blocking it.’ That was the Nimda worm–the first of a long line of attacks stopped by Cisco Security Agent.”</p>
<p>–Ted Doty, Product Manager, Security Technology Group, Cisco Systems®</p>
<p>This security book is part of the Cisco Press® Networking Technology Series. Security titles from Cisco Press help networking professionals secure critical data and resources, prevent and mitigate network attacks, and build end-to-end self-defending networks.</p>
<p>More info:<a href="http://www.amazon.com/gp/product/B00008MOPR?ie=UTF8&amp;tag=freeitcertexa-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B00008MOPR">CISCO SECURITY DESKTOP AGENT ( CSA-B25-DTOP-K9 )</a><img src="http://www.assoc-amazon.com/e/ir?t=freeitcertexa-20&amp;l=as2&amp;o=1&amp;a=B00008MOPR" style="border: medium none  ! important; margin: 0px ! important" border="0" width="1" height="1" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/cisco-security-agent/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>642-513 HIPS Securing Hosts Using Cisco Security Agent Exam</title>
		<link>http://www.ccsp.name/642-513-hips-securing-hosts-using-cisco-security-agent-exam</link>
		<comments>http://www.ccsp.name/642-513-hips-securing-hosts-using-cisco-security-agent-exam#comments</comments>
		<pubDate>Mon, 25 Aug 2008 11:38:32 +0000</pubDate>
		<dc:creator>Cisco</dc:creator>
				<category><![CDATA[Exam Topics]]></category>
		<category><![CDATA[642-513]]></category>
		<category><![CDATA[hips]]></category>

		<guid isPermaLink="false">http://ccsp.name/?p=10</guid>
		<description><![CDATA[Exam Number:	 642-513
Associated Certifications:	CCSP
Duration:	75 minutes (65-75 questions)
Available Languages:	English
Click Here to Register:	Pearson VUE
Exam Policies:	Read current policies and requirements
Exam Tutorial:	Review type of exam questions
Exam Description
The Securing Hosts Using Cisco Security Agent exam 642-513 HIPS is one of the exams associated with the Cisco Certified Security Professional certification. Candidates can prepare for this exam by taking the HIPS [...]]]></description>
			<content:encoded><![CDATA[<p>Exam Number:	 642-513<br />
Associated Certifications:	CCSP<br />
Duration:	75 minutes (65-75 questions)<br />
Available Languages:	English<br />
Click Here to Register:	Pearson VUE<br />
Exam Policies:	Read current policies and requirements<br />
Exam Tutorial:	Review type of exam questions<span id="more-10"></span></p>
<p>Exam Description<br />
The Securing Hosts Using Cisco Security Agent exam 642-513 HIPS is one of the exams associated with the Cisco Certified Security Professional certification. Candidates can prepare for this exam by taking the HIPS v3.0 course. This exam tests a candidate&#8217;s knowledge and ability to describe, configure, and verify the Cisco Security Agent product.</p>
<p>Exam Topics<br />
The following information provides general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes the guidelines below may change at any time without notice.</p>
<p>Describe and deploy the CSA and CSA MC products</p>
<p>    * Explain the concept of network defense in depth<br />
    * Describe Cisco Security Agent architecture<br />
    * Describe the life cycle of an attack<br />
    * Explain how Cisco Security Agent protects against attacks<br />
    * Identify the CSA MC and CSA system requirements<br />
    * Identify the administration workstation requirements<br />
    * Install the CSA MC<br />
    * Configure basic settings on the CSA MC<br />
    * Install the CSA using a default group</p>
<p>Use CSA MC to configure groups, manage hosts, and build policies</p>
<p>    * Describe various components of the menu bar and its function in the CSA MC interface<br />
    * Create, save, and delete data on the CSA MC<br />
    * Create groups to ease host management and security policy deployment<br />
    * Build Agent kits for the newly created groups<br />
    * View host status and modify host configuration<br />
    * Distribute software updates to hosts<br />
    * Discuss components of a policy<br />
    * Configure policies and rule modules</p>
<p>Use CSA MC to configure rules</p>
<p>    * Describe the basics of rule construction and functionality<br />
    * Configure rules common to Windows and UNIX systems<br />
    * Configure Windows-Only rules<br />
    * Configure UNIX-Only rules<br />
    * Describe the individual rules you can add to your policies that allow CSA MC to categorize processes and correlate events across multiple systems<br />
    * Describe and configure the system API Control Rule<br />
    * Describe and configure the Network Shield Rule<br />
    * Describe and configure the Buffer Overflow Control Rule<br />
    * Describe and configure the Email Worm Protection Rule module<br />
    * Describe and configure the Installation Applications Policy<br />
    * Describe and configure Global Event Correlation</p>
<p>Define application classes and work with variables</p>
<p>    * Explain the use of application classes in creating security policies<br />
    * Discuss the preconfigured application classes included in the CS AMC<br />
    * Configure a static application class<br />
    * Create a dynamic application class and an application-builder rule<br />
    * Discuss how events sets are used to ease administration of security policies<br />
    * Configure data, file and network address sets<br />
    * Create registry, COM component and network services sets<br />
    * Use the COM extraction utility to gather PROGIDs and CLSIDs for the software installed on a system<br />
    * Configure Query Settings variables to be used with Query rules</p>
<p>Use CSA Analysis and define and generate reports</p>
<p>    * Understand and configure application deployment investigation<br />
    * Understand and configure product associations for application deployment investigation<br />
    * Configure and run application deployment reports<br />
    * Understand and configure application behavior investigation<br />
    * Understand and use behavior analysis reports<br />
    * Import and use behavior analysis rule modules<br />
    * Explain the features of the Event Log and Event Monitor<br />
    * Configure filtering of events for logging, reports, and alerts<br />
    * Create event-based alerts<br />
    * Generate reports on events selected by sorting criteria</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ccsp.name/642-513-hips-securing-hosts-using-cisco-security-agent-exam/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
