
Cisco 642-513 HIPS Certification ExamSecuring Hosts Using Cisco Security Agent Exam 642-513... Continue Below To CCSP Exam Information and Cisco Articles. The real Cisco CCSP 642-513 HIPS Exam has a duration of 75 minutes and 65 -75 questions to complete.
The Securing Hosts Using Cisco Security Agent HIPS 642-513 exam is one of the exams associated with the Cisco Certified Security Professional (CCSP) certification. Candidates can prepare for the Cisco HIPS 642-513 exam by taking the HIPS v2.0 course. The Cisco HIPS 642-513 exam tests a candidate's knowledge and ability to describe, configure, and verify the Cisco Security Agent product. All these objectives are designated from the Cisco.com website. Please note that the HIPS 642-513 exam topics and objectives may change without notice, since technologies are always changing.
CCSP 642-513 Exam Objectives:
Describe and deploy the CSA and CSA MC products
- Explain the concept of network defense in depth
- Describe Cisco Security Agent architecture
- Describe the life cycle of an attack
- Explain how Cisco Security Agent protects against attacks
- Identify the CSA MC and CSA system requirements
- Identify the administration workstation requirements
- Install the CSA MC
- Configure basic settings on the CSA MC
- Install the CSA using a default group
Use CSA MC to configure groups, manage hosts, and build policies
- Describe various components of the menu bar and its function in the CSA MC interface
- Create, save, and delete data on the CSA MC
- Create groups to ease host management and security policy deployment
- Build Agent kits for the newly created groups
- View host status and modify host configuration
- Distribute software updates to hosts
- Discuss components of a policy
- Configure policies and rule modules
Use CSA MC to configure rules
- Describe the basics of rule construction and functionality
- Configure rules common to Windows and UNIX systems
- Configure Windows-Only rules
- Configure UNIX-Only rules
- Describe the individual rules you can add to your policies that allow CSA MC to categorize processes and correlate events across multiple systems
- Describe and configure the system API Control Rule
- Describe and configure the Network Shield Rule
- Describe and configure the Buffer Overflow Control Rule
- Describe and configure the Email Worm Protection Rule module
- Describe and configure the Installation Applications Policy
- Describe and configure Global Event Correlation
Define application classes and work with variables
- Explain the use of application classes in creating security policies
- Discuss the preconfigured application classes included in the CS AMC
- Configure a static application class
- Create a dynamic application class and an application-builder rule
- Discuss how events sets are used to ease administration of security policies
- Configure data, file and network address sets
- Create registry, COM component and network services sets
- Use the COM extraction utility to gather PROGIDs and CLSIDs for the software installed on a system
- Configure Query Settings variables to be used with Query rules
Use CSA Analysis and define and generate reports
- Understand and configure application deployment investigation
- Understand and configure product associations for application deployment investigation
- Configure and run application deployment reports
- Understand and configure application behavior investigation
- Understand and use behavior analysis reports
- Import and use behavior analysis rule modules
- Explain the features of the Event Log and Event Monitor
- Configure filtering of events for logging, reports, and alerts
- Create event-based alerts
- Generate reports on events selected by sorting criteria
Certification Articles
|