Free RSA NetWitness Logs & Network Administrator Exam Braindumps (page: 4)

Page 3 of 18

Which device index file should you use to create new meta keys?

  1. index-user, xml
  2. index-default xml
  3. index-<device> xml
  4. index-<device>-custom xml

Answer(s): D



In what order are filters evaluated as data flows through the Decoder'?

  1. Feeds. Network Rules. LUA Parsers. Application Rules. BPF
  2. Feeds. Network Rules. BPF. Application Rules, LUA Parsers
  3. Network Rules. Feeds. Application Rules. BPF, LUA Parsers
  4. BPF. Network Rules. LUA Parsers. Feeds. Application Rules

Answer(s): C



Where is the PAM configuration file located on an RSA NetWitness appliance'?

  1. /etc/hosts
  2. /etc/pam.d
  3. /opVbin/pam
  4. /usr/birVconfig

Answer(s): B



What happens when you set the metadata associated with a parser to Transients

  1. Transient means the Decoder is using the parser to parse traffic, and the generated metadata is not stored on disk
  2. Transient means the Decoder is using the parser to parse traffic, and the generated metadata is retained on disk for 24 hours
  3. Transient means the Decoder is using the parser only to filter out data, not to generate metadata
  4. Transient means the Decoder is using the parser only for ESA

Answer(s): C






Post your Comments and Discuss RSA RSA NetWitness Logs & Network Administrator exam with other Community members:

RSA NetWitness Logs & Network Administrator Exam Discussions & Posts