IBM P2150-739 Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Thema 1: Bereitstellung und Konfiguration | - Definieren von Datenquellen und Überwachungsrichtlinien - Installation und Konfiguration von Guardium S-TAP und Collectoren - Integration in Unternehmensumgebungen |
| Thema 2: Sicherheit und Richtlinienverwaltung | - Konfigurieren von Richtlinien und Regeln - Lebenszyklusverwaltung von Richtlinien |
| Thema 3: Fehlerbehebung und bewährte Verfahren | - Leistungs- und Fehlerbehebungsstrategien - Diagnosetechniken für Guardium-Umgebungen |
| Thema 4: Warnmeldungen und Berichterstellung | - Erstellen und Auswerten von Konformitätsberichten - Verstehen der Warnmechanismen von Guardium - Verwalten von Ausnahmeworkflows |
| Thema 5: Grundlagen der Guardium-Architektur | - Grundlagen der Datenbankaktivitätsüberwachung - Systemkomponenten und Rollen von Guardium - Datenfluss und Erfassung in Guardium |
IBM InfoSphere Guardium Technical Mastery Test v2 P2150-739 Prüfungsfragen mit Lösungen
Frage #1
In a Guardium environment where data servers can talk to the collector, what is the relationshipbetween the S-TAP and the collector appliance?
A. There is no relationship since the S-TAP and the collector are incompatible Guardium entities.
B. The S-TAP reports database activity to the collector for policy management and auditing.
C. A collector can only interact with one S-TAP for policy management and auditing.
D. The collector sends the S-TAP information about its policies so it knows what traffic to intercept.
Frage #2
Which of the following actions is NOT a known benefit of using correlation alerts?
A. Saving time in alerting and analyzingversusmanually doing so.
B. Automatically alerting users when established behavioral baselines are exceeded.
C. Real time database traffic analysis and security policy inspection.
D. Monitoring database usage and pinpointing suspicious activity.
Frage #3
What is the simplest definition of a Guardium domain?
A. A simple identification label to indicate ownership or control of a Guardium resource.
B. A Guardium entity containing a series of attributes.
C. Grouping of a set of tables and relationships between those tables providing a view of the data that Guardium stores.
D. A model of a Guardium system describing the different entities involved in the environment and their relationships.
Frage #4
A database known to contain the medical records of a foreign head of state is accessed at 1:30 AM.
No security mechanism is installed and so this highly sensitive information is leaked to the media.
Could this breach have been detected by running a Guardium vulnerability assessment without creating any custom assessment tests?
A. No, this type of test is not included with Guardium.
B. Yes, but only if the appliance includes Guardium's Database Protection Subscription service.
C. Yes, however this particular test is only available for IBM DB2 and Informix servers.
D. Yes,after hours login detection is one of the standard behavioral vulnerability tests included with Guardium.
Frage #5
What is the purpose of Guardium's Application Events API?
A. The Application Events API is used to increase the speed at which Guardium processes statements.
B. Enabling non-supported database engines to be used with Guardium.
C. Adding application event data, such as user ID, event type and number, to the SQL statements executed between an API no-op call and its release signal.
D. Being part of the pattern matching engine that evaluates statements for membership in a specific security policy.
Fragen und Antworten:
| Frage #1 Antwort: B | Frage #2 Antwort: C | Frage #3 Antwort: C | Frage #4 Antwort: D | Frage #5 Antwort: C |






720 Kundenbewertungen

