RSA RSA NetWitness Logs & Network Administrator Exam
RSA NetWitness Logs & Network Administrator (050-11-CARSANWLN01) (Page 5 )

Updated On: 30-Jan-2026

Parsers can be enabled on which of the following?

  1. Packet Decoder only
  2. Packet Decoder and Log Decoder
  3. Packet Decoder and Log Decoder and Concentrator
  4. Packet Decoder and Log Decoder and Concentrator and Broker

Answer(s): A



Which of the following is the basic building block of a report in RSA NetWitness?

  1. Rule
  2. Broker
  3. Packet
  4. Session

Answer(s): A



To access device information and perform device operations through RSA NetWitness. a user must be

  1. assigned the role of Operator"
  2. a member of a "DeviceUser" group in Active Directory
  3. a member of a role that has privileges for the device
  4. assigned read/write access to the NetWitness appliance

Answer(s): A



Service Groups are used primarily for

  1. grouping metadata from specified hosts
  2. deploying Live resources to specified services
  3. grouping hosts for batch configuration
  4. grouping hosts for monitoring performance in the Health and Wellness view

Answer(s): A



Which of the following rule types relies on two or more events occurring within a specified window of time?

  1. Network Rule
  2. Application Rule
  3. Correlation Rule
  4. BPF Filter Rule

Answer(s): C



Viewing page 5 of 16
Viewing questions 21 - 25 out of 71 questions



Post your Comments and Discuss RSA RSA NetWitness Logs & Network Administrator exam prep with other Community members:

Join the RSA NetWitness Logs & Network Administrator Discussion