Intel Security Certified Product Specialist McAfee Network Security Platform (NSP)



Similar documents
Intel Security Certified Product Specialist Data Loss Prevention Endpoint (DLPe)

Intel Security Certified Product Specialist Security Information Event Management (SIEM)

Intel Security Certified Product Specialist

McAfee Network Security Platform Administration Course

McAfee Certified Product Specialist McAfee epolicy Orchestrator

McAfee Web Gateway Administration Intel Security Education Services Administration Course Training

McAfee Certified Assessment Specialist Network

McAfee Network Security Platform 8.2

McAfee Security Information Event Management (SIEM) Administration Course 101

Technology Blueprint. Protect Your Servers. Guard the data and availability that enable business-critical communications

Managing Latency in IPS Networks

Modular Network Security. Tyler Carter, McAfee Network Security

McAfee Application Control / Change Control Administration Intel Security Education Services Administration Course

Setup Guide Revision B. McAfee SaaS Archiving for Microsoft Exchange Server 2010

McAfee Next Generation Firewall (NGFW) Administration Course

HP Certified Professional

How To Manage Sourcefire From A Command Console

How McAfee Endpoint Security Intelligently Collaborates to Protect and Perform

McAfee Global Threat Intelligence File Reputation Service. Best Practices Guide for McAfee VirusScan Enterprise Software

Cisco Advanced Services for Network Security

McAfee Endpoint Protection for SMB. You grow your business. We keep it secure.

Network Security Platform 7.5

How To Fix A Fault Notification On A Network Security Platform (Xc) (Xcus) (Network) (Networks) (Manual) (Manager) (Powerpoint) (Cisco) (Permanent

Company Co. Inc. LLC. LAN Domain Network Security Best Practices. An integrated approach to securing Company Co. Inc.

Data Center Connector for vsphere 3.0.0

How To Protect Your Network From Intrusions From A Malicious Computer (Malware) With A Microsoft Network Security Platform)

Decryption. Palo Alto Networks. PAN-OS Administrator s Guide Version 6.0. Copyright Palo Alto Networks

Access FedVTE online at: fedvte.usalearning.gov

McAfee Asset Manager Console

Cisco Certified Security Professional (CCSP)

TSM for Windows Installation Instructions: Download the latest TSM Client Using the following link:

PFSENSE Load Balance with Fail Over From Version Beta3

Configuring Global Protect SSL VPN with a user-defined port

White Paper. Time for Integrated vs. Bolted-on IT Security. Cyphort Platform Architecture: Modular, Open and Flexible

GOOD PRACTICE GUIDE 13 (GPG13)

McAfee Network Security Platform Services solutions for Managed Service Providers (MSPs)

Dell SupportAssist Version 2.0 for Dell OpenManage Essentials Quick Start Guide

HP IMC Firewall Manager

Centrify Cloud Connector Deployment Guide

Total Protection for Compliance: Unified IT Policy Auditing

Exam Preparation Guide HP0-Y29: Installing an HP Networking IP Telephony Solution

McAfee Public Cloud Server Security Suite

Elastix SIP Firewall. Quick Installation Guide


CA Performance Center

RealPresence Platform: Installation, Configuration and Troubleshooting - RPIIT202

Configuration Information

FortiMail Filtering. Course for FortiMail v4.0. Course Overview

Creating a Content Group and assigning the Encrypt action to the Group.

Hosts HARDENING WINDOWS NETWORKS TRAINING

How To Buy Nitro Security

FortiMail Filtering. Course 221 (for FortiMail v4.2) Course Overview

How To Set Up A Firewall Enterprise, Multi Firewall Edition And Virtual Firewall

FortiMail Filtering. Course 221 (for FortiMail v5.0) Course Overview

CNS-301-3I ~ Citrix NetScaler 11 Advanced Implementation

Web Authentication Application Note

ASDI Full Audit Guideline Federal Aviation Administration

COUNTERSNIPE

Comodo Endpoint Security Manager SME Software Version 2.1

HELP DOCUMENTATION E-SSOM INSTALLATION GUIDE

AVG Business Secure Sign On Active Directory Quick Start Guide

CONTINUOUS DIAGNOSTICS BEGINS WITH REDSEAL

Websense Certified Engineer Web Security Professional Examination Specification

Effective IDS/IPS Network Security in a Dynamic World with Next-Generation Intrusion Detection & Prevention

FedVTE Training Catalog SUMMER advance. Free cybersecurity training for government personnel. fedvte.usalearning.gov

Oracle Maps Cloud Service Enterprise Hosting and Delivery Policies Effective Date: October 1, 2015 Version 1.0

RSA SecurID Certified Administrator (RSA Authentication Manager 8.0) Certification Examination Study Guide

Service Overview & Installation Guide

Web Application Firewall

Hackers are here. Where are you?

Media Shuttle s Defense-in- Depth Security Strategy

IBM Security QRadar SIEM Version MR1. Administration Guide

When your users take devices outside the corporate environment, these web security policies and defenses within your network no longer work.

McAfee Enterprise Security Manager 9.3.2

Reverse Shells Enable Attackers To Operate From Your Network. Richard Hammer August 2006

RSA Security Analytics Certified Administrator (CA) Certification Examination Study Guide

How To Set Up A Backupassist For An Raspberry Netbook With A Data Host On A Nsync Server On A Usb 2 (Qnap) On A Netbook (Qnet) On An Usb 2 On A Cdnap (

Managed Security Services for Data

Security FAQs (Frequently Asked Questions) for Xerox Remote Print Services

NEFSIS DEDICATED SERVER

How To Plan A Desktop Workspace Infrastructure

escan SBS 2008 Installation Guide

McAfee Security Architectures for the Public Sector

BUILDING A SECURITY OPERATION CENTER (SOC) ACI-BIT Vancouver, BC. Los Angeles World Airports

Configuration Information

HP Certified Professional

Concierge SIEM Reporting Overview

REQUIREMENTS AND INSTALLATION OF THE NEFSIS DEDICATED SERVER

McAfee Firewall Enterprise System Administration Intel Security Education Services Administration Course

QUICK START GUIDE. Cisco S170 Web Security Appliance. Web Security Appliance

FortiMail Filtering Course 221-v2.0. Course Overview. Course Objectives

Administration Guide Revision E. Account Management. For SaaS and Web Security

Securing the Internet of Things OEM capabilities assure trust, integrity, accountability, and privacy.

McAfee Next Generation Firewall Optimize your defense, resilience, and efficiency.

Managed Intrusion, Detection, & Prevention Services (MIDPS) Why Sorting Solutions? Why ProtectPoint?

GFI Product Manual. Administration and Configuration Manual

Transcription:

Intel Security Certified Product Specialist McAfee Network Security Platform (NSP) Why Get Intel Security Certified? As technology and security threats continue to evolve, organizations are looking for employees with the most up-to-date certifications on the most current techniques and technologies. In a well cited IDC White Paper, over 70% of IT Managers surveyed felt certifications are valuable for their team and were worth the time and money to maintain. Becoming Intel Security Certified distinguishes you from other security professionals and helps validate that you have mastery of the critical skills covered by the certification exams. Earning a certification also shows your commitment to continued learning and professional growth. About Intel Security Certification Program Currently, Intel offers two industry-recognized certifications as part of our Intel Security Certification Program: Intel Security Certified Product Specialist and Intel Security Certified Security Professional. The Intel Security Certified Product Specialist certifications are designed for candidates who administer a specific McAfee product or suite of products, and have one to three years of experience with that product or product suite. This certification level allows candidates to demonstrate knowledge in the following key product areas: Installation Configuration Management Basic architecture and troubleshooting Highlights This guide has been developed as a resource for your preparation to take the Intel Security Certified Product Specialist NSP Exam (MA0-101). The following information is provided: About the Intel Security Certification Program Exam details Suggested resources for exam preparation Knowledge domain topics Sample exam items The Intel Security Certified Security Professional certifications are designed for security practitioners penetration testers, auditors, consultants, administrators with one to three years of experience. This certification level allows candidates to demonstrate knowledge in the following high-level assessment areas: Profiling and inventorying Vulnerability identification Vulnerability exploitation Expanding influence About This Guide This guide is intended to help prepare you for the Intel Security Certified Security Professional Network Security Platform (NSP) exam. For more information about other certification exams or about the Intel Security Certification program go to www.mcafee.com and select For Business, Services, and then Education Services.

Intel Security Certified Product Specialist Network Security Platform (NSP) This exam validates that the successful candidate has the knowledge and skills necessary to successfully install, configure, and manage a McAfee Network Security Platform solution. It is intended for security professionals with one to three years of experience using the McAfee NSP product and associated technologies. Exam Details Associated exam: MA0-101 Associated Training: McAfee Network Security Platform Administration (4 days) Number of Questions: 100 Exam Duration: 120 Minutes Passing Score: 61% Exam Price: $150 USD (Exam prices are subject to change. Please visit the following link for exact pricing: www. prometric.com/mcafee.) Exam Preparation Suggested preparation for this exam is: 4 Days McAfee Network Security Platform Administration training (https://mcafee.netexam.com/catalog.html) Minimum of one year using McAfee NSP McAfee Service Portal (https://support.mcafee.com) Knowledge domains (see later in the guide) Sample questions (see later in the guide) Certificate Registration Intel Security has partnered with Prometric, a leading global provider of comprehensive testing and assessment services, to administer our certification program. Prometric makes the certification process easy from start to finish. With more than 5,000 global locations, you can conveniently test your knowledge and become Intel Security Certified. To register for an exam, go to: www.prometric.com/mcafee. Exam Duration The Intel Security Certification Program has built in time to include the following actions during an exam at each testing facility: Time to answer exam questions Time to review instructions and provide comments after completion Intel Security reserves the right to change the exam content and time requirements at any time. The most accurate means of obtaining this information is to contact the exam delivery provider on the day of your exam challenge. A notification appears on your screen before the exam begins that shows the maximum time allowed for answering the questions in that exam. Certification Transcripts Individuals who have passed an Intel Security certification exam are granted access to the Intel Security Certification Program Candidate site. On the site, you will find: Your official Intel Security Certification Program transcript and access to the transcript sharing tool The ability to download custom certification logos Additional information and offers for Intel-certified individuals Your contact preferences and profile News and promotions 2

McAfee Network Security Platform Administration (4 days) Although formal training is not required prior to the exam, the McAfee Network Security Platform Administration (4 days) course is recommended. This course provides in-depth training on how to use McAfee Network Security Platform (NSP). At the end of this course, you will be able to plan the NSP deployment, install and configure the Manager, manage users and resources, configure and manage policies, analyze and respond to threats, and tune your security policies for maximum effectiveness. To register for this course, go to: https://mcafee.netexam.com/catalog.html. Practical (Hands-on) Experience A minimum of one year of experience using McAfee NSP and associated technologies is required. Recommended hands-on activities include, but are not limited to: Architecture design Installation/upgrade Configuration Management Troubleshooting Technical ServicePortal The Technical ServicePortal provides a single point of access to valuable tools and resources, such as: Documentation Security bulletins Technical articles Product downloads Tools To access the ServicePortal, go to: https://support.mcafee.com. Expert Center Community The Expert Center is a community for McAfee product users. Here you will find valuable information for your McAfee products, such as: Instructional videos and whitepapers Discussion feeds for experts and other users Guidelines to establish baselines, and to harden your IT environment Ways to expedite monitoring, response, and remediation processes To access the Expert Center, go to: https://community.mcafee.com/community/business/expertcenter. 3

Exam Knowledge Domains Setup NSP Installation (e.g. server requirements, planning) NSP Configuration (e.g. domains, user account, authentication, response management and notification) Response Actions (e.g. white list, black list, update policies, create ignore rules) Reporting NSP Navigation Sensor Installation (e.g. sensor sizing, planning, placement, ports, operational modes) Sensor Configuration (e.g. CLI commands) Maintenance and troubleshooting (e.g. backup, database tuning, file pruning) Integration (e.g. EPO, NTBA, GTI) Policy Management Policy Manager (e.g. creation, assignment) IPS Policies (e.g. custom attack editor, attack definitions, import/export, system tuning) Advanced Malware Policies Inspection Options Policies Connection Limiting Policies Firewall Policies Quality of Service (QoS) Policies Exceptions (e.g. ignore rules, filehash exceptions, domain name exceptions) Objects (e.g. policy groups, rule objects, attack set profiles) Event Management Dashboard Monitoring Threat Analysis (e.g. threat explorer, malware detections, attack log, pcap analysis, recognizing patterns) 4

Sample Exam Items The following exam items are provided for review. These items are similar in style and content to those referenced in the Intel Security Certified Product Specialist NSP exam. The answers are provided after the questions. 1. Upon initial configuration, which of the following allows management connection to the Sensor? A RJ45 B RJ11 C Monitoring port D Console Port 2. To archive alerts and packets logs, you must navigate through which of the following paths? A Manage Maintenance Archiving B Manage Alerts Archiving C Maintenance Alerts Archiving D Manage Maintenance Alerts Archiving 3. Why is the DBAdmin tool considered a preferred method of performing system maintenance tasks that could be performed within the NSM? A Saves additional workload on the Manager B Reliability C Speed D Ease of use 4. Which step needs to be completed before a sensor can be configured? A Sensor IP addressing must be set B Sensor must be added to the Manager C Sensor username and password must be set D Sensor Gateway addressing must be set 5. Which command can be issued on a Sensor to check the health of the Sensor? A show sensor health B show health status C show config D check health 6. In the Policy Manager, a policy can be modified at the interface level unless that policy was initially created in a: A Parent Domain. B Child Domain. C Top Domain. D non-adjacent domain 7. A rule set cannot be applied to a policy with: A the same rule set applied to both traffic flows. B one rule set applied to all traffic. C different rule sets applied to each traffic flow. D two rules sets applied to each traffic flow. 8. At the device level, the IPS policy cannot be modified to include/exclude: A Default McAfee Attacks. B Modified McAfee Attacks. C Custom McAfee Format Attacks. D Custom Snort Attacks 9. On the NSP CLI, what is the command that enables the L2 mode feature? A layer2 mode off 5

B C D layer2 mode on layer2 mode assert layer2 mode deassert 10. If domain-level exception object settings are assigned at the Sensor level: A other resources using that object on that Sensor are not affected B other resources using that object on that Sensor are also affected C a Fault level of warning will be sent to the NSM to warn the administrators D the Sensor level settings will be ignored; domain-level settings always take precedence Answer Key 1. D 2. D 3. A 4. B 5. A 6. A 7. D 8. B 9. B 10. B McAfee. Part of Intel Security. 2821 Mission College Boulevard Santa Clara, CA 95054 888 847 8766 www.intelsecurity.com