A Guardium administrator must configure real time policy alerts to be sent to a remote SIEM for every SQL statement run on a sensitive object. There is no requirement for the data to be viewed or reported on in the Guardium appliance.
Which policy action would achieve that task and store the least amount of data in the
Guardium internal database?
A. Log Only
B. Alert Per Match
C. Alert Daily
D. Alert Only
正解:C
質問 2:
AGuardium administrator just finished installing the Guardium product to build a Collector. The administrator wants to make sure the Collector has the licenses needed to provide functionality for data activity monitoring, masking and blocking (terminate).
Which of the following lists the minimum licenses the administrator needs to install?
A. Base Collector license plus IBM Security Guardium Advanced Activity Monitor for Databases (DAM Advanced).
B. Base Collector license plus IBM Security Guardium Standard Activity Monitor for Databases (DAM Standard).
C. Base Collector license.
D. None, the licenses required are already installed automatically by the Guardium product installer.
正解:A
質問 3:
The guard_tap.ini of a UNIX S-TAP is configured with the following parameters:

The collector that this S-TAP is sending data to has become unavailable and there is no failover option configured. A Guardium administrator must communicate the impact of this outage to users of the monitored database.
What should the administrator advise is the expected behavior for a database session?
A. in the first 10 seconds of the session no SQL can be executed, then the session will work as normal.
B. The session will not experience any latency or termination.
C. in the first 10 seconds of the session SQL can be executed, then the session is terminated.
D. No SQL can be executed and after 10 seconds the session will be terminated.
正解:C
質問 4:
AGuardium administrator is registering a new Collector to a Central Manager (CM). The registration failed. As part of the investigation, the administrator wants to identify if the firewall ports are open-How can the administrator do this?
A. Login as CLI and execute telnet <ip address> <port number>
B. Login as CLI and execute support show port open <ip address> <port number>
C. Ask the company's network administrators.
D. Ask IBM technical support to login as root and verify.
正解:B
質問 5:
Guardium reports are showing multiple records with client ip as 0.0.0.0. Users are unable to identify which client the connections came from. The Guardium administrator has identified that the databases are using encryption.
Which column can the administrator add that would help users to better identify the client?
A. Analyzed Client IP
B. Client OS
C. Client MAC
D. Access ID
正解:C
質問 6:
A company is installing S-TAPS on new Database Clusters. The Guardium administrator was provided with the PVU load of each node. The clusters are in active/passive mode. The administrator is associating S-TAPs to Collectors using the PVU count.
How should the administrator treat the PVUs of passive nodes?
A. Not include the PVU load of passive nodes.
B. include half of the passive nodes PVU load.
C. include a third of the passive nodes PVU load.
D. include the PVU load of passive nodes.
正解:A
1181 お客様のコメント





北嶋** -
Pass4Testは他の参考書を手にしていないので比較が出来ませんが、とても読みやすく、
イラストで解りやすく解説しています。