* Identify the components, features and functions of the Cisco Security MARS product * Describe the process of installing the Cisco Security MARS appliance * Add Cisco reporting devices into the Cisco Security MARS appliance * Add non-Cisco reporting devices into the Cisco Security MARS appliance * Investigate events that the Cisco Security MARS appliance collects from configured security devices * Configure the Cisco Security MARS appliance to send alerts * Create and view a long-duration query on the Cisco Security MARS appliance * Configure rules to detect interesting patterns of network activity and other anomalous network behavior * Use the management features in the Cisco Security MARS appliance to assign event, addressing, service, and user information * Configure the Cisco Security MARS appliance hardware maintenance activities * Utilize the Global Controller to manage multiple Cisco Security MARS appliances
You agree that the contents of the exam are confidential and that the disclosure of that information could compromise the integrity of the Program and of Certifications. Cisco makes exams available to you solely to test your knowledge of the exam subject matter for which you seek Certification. You are expressly prohibited from disclosing, publishing, reproducing, or transmitting any exam and any related information including, without limitation, questions, answers, worksheets, computations, drawings, diagrams, length or number of exam segments or questions, or any communication, including oral communication regarding or related to the exam (known collectively as “Proprietary Information”), in whole or in part, in any form or by any means, oral or written, electronic or mechanical, for any purpose, without the prior express written permission of Cisco.
No candidate will take any action that will compromise the integrity or confidentiality of a Cisco Certification examination or otherwise compromise the integrity of the Cisco Certification program. Such actions include but are not limited to: • Disseminating actual exam content via web postings, discussion groups, chat rooms, study guides, etc.