HP ArcSight ESM Security Analyst Sample Questions:
1. Which statement is true about join rules and chained rules?
A) Chained rules result in detailed chains; join rules result in simple chains.
B) Chained rules may or may not be join rules that also use Active Lists or rely on Correlation events generated by other rules.
C) Join rules link simple rules together; chained rules link join rules.
D) Join rules use Session Lists; chained rules use Active Lists.
2. Which statements are true about event lifecycle data collection and the event processing phase?
(Select two.)
A) Event severity is determined, based on an Active List of recent severity factors.
B) Model confidence is determined, based on details provided by the event source.
C) Values are normalized and entered into the ArcSight Event Schema.
D) Each line of incoming log data is processed as a separate event.
3. What is a good way for an operator or analyst to quickly determine which events must be addressed first?
A) ask more senior analysts or architects
B) run a report of High Priority Threats
C) view the Event Grid and Correlation categories
D) check the priority rating in a Dashboard or Active Channel
4. Which ESM components collect event data?
A) nodes
B) events
C) SmartConnectors
D) resources
5. Event correlation, event reconciliation, moving average, session reconciliation, and statistics are all examples of which type of Data Monitors?
A) non-event-based
B) correlation
C) event-based
D) system status
Solutions:
Question # 1 Answer: B | Question # 2 Answer: C,D | Question # 3 Answer: D | Question # 4 Answer: C | Question # 5 Answer: B |