01. Three teams each need scheduled work against the same production database: one runs assessments, one runs classification, and one runs a reporting task.
Each team has created its own datasource definition for that database, each with its own credential.
What should the administrator do?
a) Consolidate on one definition for that database, and grant the three teams access to it
b) Consolidate the three schedules into one, so that the database is connected to only once
c) Leave the definitions in place but point all three at a single credential held in the vault
d) Leave the definitions in place and rename them by team, so that it is clear who owns each schedule
02. A rollout of monitoring agents reports every installation successful, and every installed agent is showing as connected on the appliance.
The compliance owner asks whether the in-scope estate is now monitored. The rollout list was assembled from change tickets raised by the server teams.
What must be done before that question can be answered?
a) Confirm that each server team has signed off its own change ticket, since those tickets are the record of what the rollout set out to do and of what each team reported back
b) Confirm that each installed agent is at the current version, since an agent can be connected while still running an older one
c) Confirm that the policy is installed on each of the collectors receiving the activity, since what ends up being captured depends on the installed policy as well as on the presence of an agent on the host
d) Reconcile the servers now reporting against the inventory of servers that are in scope, because the rollout list records what was attempted rather than what was required
03. Console roles are mapped to directory groups through the LDAP integration. An administrator has changed teams and should no longer hold the role that permits policy changes, and the service desk has removed them from the corresponding directory group.
Which two checks confirm that the removal is complete?
(Choose two)
a) Confirm that the person's directory group membership no longer includes any group mapped to that role
b) Confirm that the policy this person last changed has been reinstalled, so that their changes are no longer in force
c) Confirm that no locally defined console account grants the same role to that person independently of the directory
d) Confirm that the reports this person previously ran have been reassigned to another owner
04. A new collector has been built and its initial configuration completed. Agents on two database servers are sending activity to it, and reports run on that collector show the traffic arriving.
From the enterprise console, however, the administrator cannot see the new system among the managed environment and cannot push the standard policy to it.
Which step was missed?
a) Restarting the agents on the two database servers so that their status is refreshed
b) Adding the two database servers to the group that the standard policy references
c) Registering the new collector as a managed unit
d) Installing the standard policy locally on the new collector first, before any central distribution is attempted
05. Guardium is integrated with a ticketing platform so that violations raise incidents there. During a planned outage of the ticketing platform, violations continue to occur.
What must the design already have settled?
a) That the ticketing platform is covered by the same maintenance window as the appliances
b) What happens to a finding that cannot be delivered while the far side is down
c) That the integration account has permission to reopen closed incidents
d) That violations are suppressed for the duration so no incident is missed
06. Alerts and events are now forwarded to the enterprise SIEM, where the security operations team correlates them with other sources.
Storage on the appliances is growing steadily, and the platform team proposes shortening on-appliance retention on the grounds that the SIEM already holds the data.
Which position should the administrator take?
a) Leave retention as it is and stop forwarding to the SIEM, since holding the same events in two places is what has driven the growth
b) Shorten retention now and revisit the decision at the next audit, when the auditors can say whether the shorter period was acceptable
c) Keep on-appliance retention set by the obligation that applies to the records, and treat any reduction as a decision taken with the compliance owner and recorded with the trade-off it makes
d) Shorten retention, because the copy forwarded to the SIEM serves the same purpose as the records held on the appliance
07. One alert has fired several hundred times in a week. Almost every occurrence is a scheduled integration account doing exactly what it is meant to do, and the team has stopped reading the notifications. The activity itself must remain on the record.
Which two changes address this?
(Choose two)
a) Raise the alert's threshold until the notifications stop arriving at the volume the team objects to, so that what does arrive is small enough for somebody to read it.
b) Stop recording the integration account's activity, since that account is what generates the volume in the first place.
c) Cover the remaining routine occurrences in a periodic report rather than a notification.
d) Narrow the alert's condition so that it describes the cases somebody is expected to act on, rather than the scheduled account's normal work.
08. A sponsor proposes that, now behavioral analytics are running, the quarterly compliance reporting cycle can be dropped. The argument is that anything worth reporting will surface as an anomaly, and the effort spent producing the quarterly pack can be redirected.
Which two positions should the administrator take?
(Choose two)
a) Keep the quarterly cycle only for systems the analytics do not cover, and drop it for the rest
b) Keep the scheduled audit process running over the retained records, because that is what produces the evidence the obligation asks for
c) Use the analytics output to direct investigation effort towards the users and objects it surfaces
d) Replace the quarterly cycle with an on-demand report produced whenever an anomaly is raised, so that reporting follows the findings
09. Three things are waiting for an administrator at the start of a shift: a self-monitoring alert that a service on a collector restarted twice overnight; a policy violation recording one read of a regulated table by a privileged account overnight; and a storage warning on that same collector.
Which should be handled first, and on what reasoning?
a) The storage warning alone, since storage is the resource that fails hardest, and the service restarts can wait for the next maintenance window.
b) The two appliance findings, because both of them threaten the collector's ability to go on recording.
c) The service restarts alone, because a service that has restarted twice will restart again, whereas a storage warning is only a warning.
d) The policy violation, because unauthorized access to regulated data is the most serious kind of event in the list and the reason the monitoring exists.
10. Assessments and classification are scheduled against a set of production databases. Soon afterwards, the analytics begin surfacing a service account that connects to many of those databases at the same times each week and reads catalog objects.
An analyst proposes an exclusion so that this account's sessions stop being captured.
What should the administrator do?
a) Apply the exclusion, since activity generated by the monitoring platform itself is not the database user activity that the audit is about and adds nothing to the record the auditors read
b) Move the assessment schedule so the runs no longer coincide, which stops the analytics grouping them together
c) Keep the activity captured, recognize it as the platform's own scheduled work, and account for that account when tuning what the analytics treat as unusual
d) Apply the exclusion for the scheduled window only, so that the account is still captured at every other time of the week