HP ArcSight ESM Security Analyst Sample Questions:
1. Which string function is used to join two data fields?
A) Find
B) Concatenate
C) Substring
D) Correlate
2. When using the Query Editor, three sub-tabs provide the options you need to properly set up the query. What information do these sub-tabs require?
A) when the query should be run; what the query should be called; how long the data should be archived
B) which data fields to select; how the data should be ordered; how the data should be grouped
C) which data fields to select; how the data should be displayed; how long the data should be archived
D) when the query should be run; which format the query output should take; how many data elements should be included
3. What are functions of Query Viewers? (Select two.)
A) determine which devices are off-line at any given point in time by querying their status
B) provide a baseline analysis of events against which future queries can be compared
C) present detailed comparisons of report elements, not possible with the reporting tool
D) display the Boolean logic behind filters and rules
E) provide a quick way to run SQL queries and identify trends without running reports
4. How do asset categorization and event categorization relate to each other?
A) Asset categorization requires custom FlexConnectors; event categorization uses standard SmartConnectors.
B) Asset categorization and event categorization use the same field set to apply categories to assets and events.
C) Asset categorization and event categorization are the same.
D) Asset categorization is the fingerprint of an asset; event categorization is a set of criteria that describes an event.
5. What do you use to establish identity, ownership, and criticality of the assets you have installed on your network?
A) asset types
B) asset ranges
C) asset categories
D) asset groups
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: B | Question # 3 Answer: B,E | Question # 4 Answer: D | Question # 5 Answer: C |
We're so confident of our products that we provide no hassle product exchange.


By Philipppa

