Which type of ESM resources is able to create correlation events?
A. Rules and correlation data monitors
B. Reports
C. Trend tables
D. Active and session lists
What is ArcSight Express?
A. An appliance that builds and maintains a detailed understanding of your network's topology, enabling you to centrally manage your infrastructure
B. An appliance used for long term log data retention and forensics, with very high through put
C. An appliance to host and "linage multiple Smart Connectors in a single device
D. An appliance combining ESM functionality with an easy-to-deploy security monitoring and response system
What are three resources used in the Correlation phase of the event lifecycle?
A. Rules, active channels, trends
B. Dashboards, queries, filters
C. Query viewers, active channels, data monitors
D. Filters, rules, data monitors
Which event schema group describes the Smart Connector that reported the event to the manager?
A. Root
B. Agent
C. Source
D. Device
What is a purpose of Smart Connectors?
A. To parse raw data
B. To calculate priority value
C. To generate reports
D. To perform correlation
What is the major benefit of using ArcSight Connector Appliance?
A. Ability to detect common patterns on your network
B. Ability to configure, monitors, tune, and update Smart Connectors
C. Ability to perform correlation on raw data
D. Long-term storage of data
Which statement is correct?
A. ArcSight Logger event schema is different from the ESM event schema
B. ArcSight Logger receives events from Connectors rather than from raw events
C. ArcSight Logger cannot compress data.
D. ArcSight Logger must be used together with an ArcSight ESM
Which component performs event aggregation?
A. ESM Database
B. ESM Manager
C. CORR-Engine
D. Smart Connectors
Which schema group contains the timestamp of the event and name of the event?
A. Source Event Schema
B. Category Event Schema
C. Agent Event Schema
D. Root Event Schema
The ArcSight ESM uses which component to gather events?
A. Nodes
B. Smart Connectors
C. Collectors
D. Adapters