RSA RSA NetWitness Logs & Network Administrator Exam
RSA NetWitness Logs & Network Administrator (050-11-CARSANWLN01) (Page 3 )

Updated On: 9-Feb-2026

What are the two types of device index files available in RSA NetWitness?

  1. index xml and index.orig.xml
  2. index-rsa.txt and index-custom txt
  3. index-rsa.xml and index-custom xml
  4. index-<device> xml and index-<device>-custom xml

Answer(s): C,D



What is the definition of an RSA NetWitness ad hoc feed?

  1. A feed that is deployed one time on one or more Decoders
  2. A feed that is deployed once on three or more Decoders
  3. A feed that is deployed on no more than three Decoders once
  4. A feed that is deployed on one or more Decoders at least three times

Answer(s): A



Logging in to NetWitness via RAM requires which of the following to succeed'?

  1. PAM User Authentication
  2. NSS Group Authentication
  3. PAM User Authentication and Group Mapping
  4. Kerberos Authentication

Answer(s): A



Which device index file should you use to create new meta keys?

  1. index-user, xml
  2. index-default xml
  3. index-<device> xml
  4. index-<device>-custom xml

Answer(s): D



In what order are filters evaluated as data flows through the Decoder'?

  1. Feeds. Network Rules. LUA Parsers. Application Rules. BPF
  2. Feeds. Network Rules. BPF. Application Rules, LUA Parsers
  3. Network Rules. Feeds. Application Rules. BPF, LUA Parsers
  4. BPF. Network Rules. LUA Parsers. Feeds. Application Rules

Answer(s): C






Post your Comments and Discuss RSA RSA NetWitness Logs & Network Administrator exam prep with other Community members:

Join the RSA NetWitness Logs & Network Administrator Discussion