Ujian Forescout Auto Lulus
Ujian Forescout Auto Lulus
Ujian Forescout Auto Lulus
Select one:
Disabling external devices via the “disable external devices” action, requires which
component?
Select one:
Host Manageability
Mirrored Traffic
SecureConnector
Disabling HPS
HeartBeat Timer
Switch
DNS Client
User Directory
Which of the following is NOT a service that needs to be running for the HPS Plugin to
manage Windows endpoints?
Select one:
Remote Registry
Server
Which of the following is NOT an action you can take with a policy?
Select one:
Which of the following is a benefit of Appliance management tools? (Options > CounterAct
Devices for EM deployments or Options > Appliance for standalone deployments)
Select one:
The search feature will only search through information in the displayed columns
You must search using more specific criteria to reduce the number
You may export all 3,968 matching endpoints for external analysis
It is a manual action that causes a network asset to match a specific device type.
Which policy family is intended for sharing of information between Forescout and other
systems?
Select one:
Discover
Control
Orchestrate
Assess
Classify
Which of the following is NOT displayed by the Setup Summary section of the initial
command line installation?
Select one:
DNS server
NTP server
Forescout Virtual Firewall actions are normally performed within what policy family?
Select one:
Assess
Control
Classify
Orchestrate
Discover
Response interface
Management interface
SPAN interface
Monitor interface
Finish the statement: The Passive learning default group is used when
Select one:
An endpoint is managed
Discover Policy
Assessment Policies
Control Policies
Informational Security
ActiveResponse
Once all the required template policies have been created, which of the following Dashboards
are NOT available by default? (Choose two)
Select one or more:
Device Compliance
Device Visibility
Health Compliance
Health Monitoring
Servers
Which of the following is NOT a configuration option of the Options > CounterAct Devices
management tools for an Enterprise Manager?
Select one:
Add/Remove Appliances
Upgrade Software
Reinstall software
Start/Stop Appliances
When pushing SecureConnector out via management systems, the name of the.exe file is
unimportant.
When deployed as a dissolvable agent, SecureConnector uninstalls itself when it’s no longer
needed.
They can add actions which can then be applied via policies.
They can add properties which can then be used in policies to evaluate endpoints.
What action types are typically included within assessment policies?
Select one:
Remediation actions
Which of the following does Forescout identify in the Enterprise Discover policy?
Select one:
Authentication method
User identity
AntiVirus version
VOIP devices
How can you manually download SecureConnector if you have a stand alone appliance?
Select one:
Navigate to https://ip_of_enterprise_manager/sc
Navigate to https://ip_of_forescout_appliance/sc
Navigate to https://ip_of_forescout_appliance/install
Navigate to http://ip_of_forescout_appliance/install
Navigate to http://ip_of_forescout_appliance/sc
Which Forescout interface connects to a switch SPAN destination port?
Select one:
Monitor interface
Response interface
Management interface
NetFlow interface
HTTP Redirect
Start SecureConnector
Switch block
Sub-rules inform Forescout when to follow-up with hosts not detected via the Main rule.
All Sub-rules in a policy are evaluated for every host detected via the Main rule.
Sub-rules instruct Forescout how to follow-up with hosts before initial detection via the Main
rule.
Sub-rules are if – then statements which must have a condition and an action.
Discover
Classify
Control
Assess
Orchestrate
Which of the following can be used to send notification messages to unregistered guest users?
Select one:
VLAN reassignment
SecureConnector balloon
http redirection
IP ACL
SMTP
Which of the following is true regarding the range of IP addresses configured in Options >
Access > Web?
Select one:
Addresses NOT defined here will be able to receive configured Web feature (HTTP, various
portals, User Portal Builder etc).
Span traffic is not necessary for HTTP redirection pages for Addresses configured here.
Addresses defined here will be able to receive the configured Web feature (HTTP, various
portals, User Portal Builder etc).
By default, this is the Internal Network range.
Enabling Anti-virus
Restricting Peer-to-Peer
NIC
Function
Hostname
Serial Number
User
Forescout has command line tools to help configure custom options and troubleshoot. Which
of the following is an example of a utility that displays a configuration summary for
Forescout?
Select one:
config_sum
fstool network_sum
sum_config
fstool config_sum
fstool version
Over what transport protocol and port does an Enterprise Manager communicate with the
deployed appliances?
Select one:
UDP port 53
Dashboards
Reports Portal
Switch module
Go to File>Exit
Control + P
Which feature can generate Donut, Trend or Counter displays for policies?
Select one:
Reports Portal
When creating a control policy to block hosts, what is the appropriate Restrict action when it
is attached to an unmanaged switch?
Select one:
Which of the following is not a valid SecureConnector deployment mode for Windows?
(Choose two)
Select one or more:
Permanent as a service
Dissolvable
Temporary as a service
Permanent as an application
Run as a web app
Select a property that Forescout uses during discovery to identify the device type.
Select one:
Device manageability
AV up to date
Open sessions
Applications Installed
Operating System
Make segments of classified systems, devices, and break them down into organizational
units.
Which of the following are NOT valid deployment architectures? (Choose two)
Select one or more:
Which of the following statements are true about the Options > NAC > HTTP Login
Attempts. (Choose two)
Select one or more:
Users that exceed this limit cannot be tracked using the Event > HTTP Login Failure property
Users that exceed this limit can be tracked using the Event > HTTP Login Failure property
Define the failed login limit for endpoint users attempting to authenticate via the HTTP Login
page.
What Virtual Firewall parameters are configured when provisioning a policy? (Choose two)
Select one or more:
Blocking rules
Quality of service
Malware blocking
Which of the properties listed might be used by the Enterprise Discover policy to identify
Printers?
Select one:
Network Adapter
Function
WLAN AP Name
IPv4 address
DHCP Device OS
Login events
Compliance events
Admission events
Open ports
Endpoint visibility
Virtual Firewall
Assign to a VLAN
Switch Block
Which of the following action categories modifies network infrastructure devices to manage
the network access of detected endpoints?
Select one:
Restrict
Manage
Notify
Enable
Remediate
Select the option that best describes the GUI location to access the Segment Manager
Select one:
Details Pane
Inventory Pane
Detections Pane
Views Pane
Filters Pane
How can you show only active endpoints in the information pane?
Select one:
Send Email to user, Run Windows Script, Kill Peer to Peer, HTTP redirection to URL
Which of the following is NOT a way that Windows SecureConnector may be installed on
managed systems?
Select one:
By the end user, via link in an HTTP message on any system as a result of a policy HTTP
redirect action.
How do you access the Segment Manager to add a new subnet? (Choose two)
Select one or more:
Which of the following is required for the Virtual Firewall action to function properly?
Select one:
Switch SNMP Integration
Router Integration
Host Manageability
Mirrored/SPAN Traffic
Notification
Classify
Manage
Restrict
Remediate
A layer-three deployment
Unique Name
Scope
Sub-rules
Which of the following does NOT represent one of the elements of a policy structure?
Select one:
History
Policy conditions
A policy scope
Policy actions
Which of the following shows how to correctly reset the Admin GUI password from the
Forescout command line?
Select one:
[root@vct1 ~]# fstool passwd -admin (then type new password and confirm)
[root@vct1 ~]# fstool passwd -gui (then type new password and confirm)
[root@vct1 ~]# passwd –u admin (then type new password and confirm)
[root@vct1 ~]# fstool passwd ( then type new password and confirm)
Which of the following is NOT a Remediate action?
Select one:
Run Script
Start/Update Antivirus
Virtual Firewall
Kill Process
When creating a control policy to block hosts, what actions require a vendor compatible
managed switch? (Choose two)
Select one or more:
What is the default port used to manage a member appliance from an Enterprise Manager?
Select one:
TCP 52311
UDP 69
TCP 13000
UDP 61
TCP 443
Which Forescout interfaces are needed for a layer 3 channel? (Choose two)
Select one or more:
Monitor interface
Trunk interface
Response interface
NetFlow interface
Management interface
Which of the following does NOT help to enhance discovery?
Select one:
Virtual firewall
DHCP traffic
An Admission Event
Which of the following is NOT required for initial command line installation?
Select one:
DNS server
DHCP reservation
Management interface
Administrator password
IP address
What authentication methods are available for console users? (Choose two)
Select one or more:
OAuth
TACACS+
MS-Direcotry Services
CLI
Local
Which feature can be populated through Options > Discovery Rules and through targeted
policies?
Select one:
Group Manager
Advanced Tools