Testinside cisco CCSP 642-513
Securing Hosts Using Cisco Security Agent Exam (HIPS) : 642-513 Exam
642-513 HIPS
Securing Hosts Using Cisco Security Agent Exam
Exam Number: 642-513
Associated Certifications: CCSP
Duration: 75 minutes (65-75 questions)
Available Languages: English
Click Here to Register: Pearson VUE
Exam Policies: Read current policies and requirements
Exam Tutorial: Review type of exam questions
Exam Description Exam Topics Recommended Training Additional Resources
Exam Description
The Securing Hosts Using Cisco Security Agent exam 642-513 HIPS is one of the exams associated with the Cisco Certified Security Professional certification. Candidates can prepare for this exam by taking the HIPS v3.0 course. This exam tests a candidate’s knowledge and ability to describe, configure, and verify the Cisco Security Agent product.
Exam Topics
The following information provides general guidelines for the content likely to be included on the exam. However, other related topics may also appear on any specific delivery of the exam. In order to better reflect the contents of the exam and for clarity purposes the guidelines below may change at any time without notice.
Describe and deploy the CSA and CSA MC products
Explain the concept of network defense in depth
Describe Cisco Security Agent architecture
Describe the life cycle of an attack
Explain how Cisco Security Agent protects against attacks
Identify the CSA MC and CSA system requirements
Identify the administration workstation requirements
Install the CSA MC
Configure basic settings on the CSA MC
Install the CSA using a default group
Use CSA MC to configure groups, manage hosts, and build policies
Describe various components of the menu bar and its function in the CSA MC interface
Create, save, and delete data on the CSA MC
Create groups to ease host management and security policy deployment
Build Agent kits for the newly created groups
View host status and modify host configuration
Distribute software updates to hosts
Discuss components of a policy
Configure policies and rule modules
Use CSA MC to configure rules
Describe the basics of rule construction and functionality
Configure rules common to Windows and UNIX systems
Configure Windows-Only rules
Configure UNIX-Only rules
Describe the individual rules you can add to your policies that allow CSA MC to categorize processes and correlate events across multiple systems
Describe and configure the system API Control Rule
Describe and configure the Network Shield Rule
Describe and configure the Buffer Overflow Control Rule
Describe and configure the Email Worm Protection Rule module
Describe and configure the Installation Applications Policy
Describe and configure Global Event Correlation
Define application classes and work with variables
Explain the use of application classes in creating security policies
Discuss the preconfigured application classes included in the CS AMC
Configure a static application class
Create a dynamic application class and an application-builder rule
Discuss how events sets are used to ease administration of security policies
Configure data, file and network address sets
Create registry, COM component and network services sets
Use the COM extraction utility to gather PROGIDs and CLSIDs for the software installed on a system
Configure Query Settings variables to be used with Query rules
Use CSA Analysis and define and generate reports
Understand and configure application deployment investigation
Understand and configure product associations for application deployment investigation
Configure and run application deployment reports
Understand and configure application behavior investigation
Understand and use behavior analysis reports
Import and use behavior analysis rule modules
Explain the features of the Event Log and Event Monitor
Configure filtering of events for logging, reports, and alerts
Create event-based alerts
Generate reports on events selected by sorting criteria
“Securing Hosts Using Cisco Security Agent Exam (HIPS)”, also known as 642-513 exam, is a Cisco certification.
Preparing for the 642-513 exam? Searching 642-513 Test Questions, 642-513 Practice Exam, 642-513 Dumps?
Free 642-513 Demo Download
TestInside offers free demo for 642-513 exam ( Securing Hosts Using Cisco Security Agent Exam (HIPS)). You can check out the interface, question quality and usability of our practice exams before you decide to buy it. We are the only one site can offer demo for almost all products.
QUESTION 21:
The Certkiller security administrator needs to configure a new policy. Which view
would you use to create a new policy within the CSA MC?
A. Configuration> Rules> Policies
B. Configuration> Policies
C. Systems> Policies
D. Systems> Rules> Policies
E. None of the above
Answer: B
Explanation:
Generally, when you configure a policy, you are combining multiple rule modules under
a common name. That policy name is then attached to a group of hosts and it uses the
rules that comprise the policy to control the actions that are allowed and denied on those
hosts. You can have several different types of rules in a rule module and consequently
within one policy.
The policy level is the common ground by which host groups acquire the rules that make
up their security policy. You can attach rule modules of differing architectures to the
same policy. This way, you can configure task-specific, self-contained, inclusive policies
across all supported architectures (Windows, Solaris, Linux) for software that is
supported on all platforms.
To configure a policy, do the following:
Step1
Move the mouse over Configuration in the menu bar of CSA MC and select Policies from
the drop-down menu that appears. The policy list view appears.
Step2
Click the New button to create a new policy entry. This takes you to the policy
configuration page.
Step3
In the available policy configuration fields, enter the following information:
Name-This is a unique name for this policy grouping of rule modules. Names are case
insensitive, must start with an alphabetic character, can be up to 64 characters long and
can include alphanumeric characters, spaces, and underscores.
Description-This is an optional line of text that is displayed in the list view and helps
you to identify this particular policy.
Step4
Select one or more Target architecture types for the policy. You can have one policy, for
example – an Apache Web Server policy, and have all three architecture checkboxes
selected. This way, each architecture specific rule module for Apache can be attached
and deployed through one single Apache policy.
Step5
Click the Save button.
Reference:
http://www.cisco.com/en/US/products/sw/secursw/ps5057/products_configuration_guide_chapter09186a00804
2
QUESTION 22:
DRAG DROP
You are a student at the Certkiller University. Your instructor asks you to match the
CSA MC view on the left with its purpose on the right below:
Answer:
QUESTION 23:
One of the tools available on the Certkiller Management Center for Cisco Security
Agents is the Compare Tool. What is the purpose of this tool?
A. To save data that has been configured
B. To compare individual rules
C. To compare individual rule modules
D. To compare and merge configurations
E. None of the above
Answer: D
Testinside CCSP 642-513 Questions and Answers : 99 Q&As
Updated: October 3rd , 2008
Price: $129.99 $89.99
Free download:pass4sure CCSP 642-513
Free download:testking CCSP 642-513
password : www.ciscoexams.org
17. October 2008 at 8:59 pm :
[...] Exam(SNPA) Testinside Cisco 642-532 Securing Networks Using Intrusion Prevention Systems Exam (IPS) Testinside Cisco 642-513 Securing Hosts Using Cisco Security Agent Exam (HIPS) Testinside Cisco 642-551 Securing Cisco [...]
18. October 2008 at 2:13 am :
[...] Exam(SNPA) Testinside Cisco 642-532 Securing Networks Using Intrusion Prevention Systems Exam (IPS) Testinside Cisco 642-513 Securing Hosts Using Cisco Security Agent Exam (HIPS) Testinside Cisco 642-551 Securing Cisco [...]
24. November 2008 at 11:55 pm :
[...] Free download: testking 642-513 Free download: pass4sure 642-513 Free download: actualtest 642-513 Free download: testinside 642-513 [...]
27. November 2008 at 1:36 am :
[...] testking 642-513 Free download: pass4sure 642-513 Free download: actualtest 642-513 Free download: testinside 642-513 Pass4sure Tags: ccsp Posted in cisco on November 27, 2008 TestKing Pass4sure cisco CCSP 642-515 [...]