IBM Security Guardium V10.0 Administration

NO.1 The quard_tap.ini of a UNIX S-TAP is configured with the following parameters:
The administrator must create a policy that will terminate the session on the delete statement in the
below scenario:
A session is started to the monitored database from client IP In the session the user plans to
perform a select statement and then a delete statement.
What actions should the administrator configure?
A. Rule1 - S-TAP Terminate Rule 2 - S-GATE Terminate
B. Rule 1 - S-GATE Detach Rule 2 - S-GATE Terminate
C. Rule 1 - S-GATE Attach Rule 2 - S-GATE Terminate
D. Rule 1 - S-GATE Attach Rule2 - S-GATE Detach
Answer: D

C2150-606 好評   

NO.2 AGuardium administrator must configure a policy to ignore all traffic from an application with a
known client IP. Due to the high amount of traffic from this application, performance of the S-TAP
and sniffer is a concern.
What action should the administrator use in the rule?
A. ignore SQL per Session
B. ignore S-TAP Session
C. ignore Responses per Session
D. Ignore Session
Answer: B

C2150-606 ウェブ   

NO.3 An administrator manages a Guardium environment including 4 Collectors exporting data to an
Aggregator. The Collectors export their data daily at 2, 3, 4 and 5 am Eastern Standard Time (EST)
respectively. The Collectors receive traffic every day. The logs on all the Collectors confirm data is
exported daily without errors, and all the exported files always have data. A Session report is run on
the Aggregator at noon EST for data from the last day.
Which of the following will ensure there is data in the report?
A. Schedule Data Import on the Aggregator to run at any time of the day.
B. Schedule Data Import on the Aggregator to run every day at 6 am EST or later.
C. Schedule Data Purge on the Aggregator to run every day after 5 am EST.
D. Schedule Data Import in the Aggregator to run every day before 2 am EST.
Answer: D

C2150-606 予想   C2150-606 最新な   

NO.4 In a centrally managed environment, while executing the report 'Enterprise Buffer Usage
Monitor', a Guardium administrator gets an empty report. Why is the report empty?
A. Sniffers are not running on the Collectors.
B. The report is not executed with a remote source on the Aggregator.
C. Correct custom table upload is not scheduled on the Central Manager.
D. The report is not executed with a remote source on the Collector.
Answer: B

