What is HBSS Right Ans - -host based security system on the individual
workstation or the host
-(COTS)
-monitor, detect, and counter against known cyber threats. -address known
traffic exploits
EPO DISA builds also contain Right Ans - -The SQL database (stores logs,
events, policies),
-The Master Repository: stores all installed ePO products on the server as well
as software deployable to client machines
HBSS Components Right Ans - -ePolicy Orchestrator Server,
-the McAfee Agent,
-the distributed repositories,
-registered server,
McAfee ePO server Right Ans - -application server that manages the suit of
product,
-contains the SQL database that stores logs, events, and policies,
-contains the master repository which stores all products as well as software
that is deplorable to the clients
McAfee Agent Right Ans - Client software which allows the ePO server to
enforce policies on client machines. (red shield icon)
Distributed Repositories Right Ans - servers that contain software
packages for remote clients
Registered Servers Right Ans - provide data to the ePO (LDAP, SNMP, other
ePO servers.)
How HBSS works. Right Ans - Through the ePO's web interface create the
policies & tell each product how they will behave, then stored on the local ePO
server, agent on the client machine will pull the latest policy from the ePO
server, enforce the last policy as long as agent is running
, Port 80 Right Ans - -Agent to Server communication (TCP),
-Inbound TCP. The ePO server listens for requests from McAfee Agents
Port 443 Right Ans - -Agent to Server secure communication (TLS),
-Inbound TCP. The ePO server listens for TLS (SSL)-encrypted requests from
McAfee Agents
Port 591 Right Ans - -Agent Wakeup Call,
-Outbound TCP. For when the ePO server or an Agent Handler sends a
Wakeup Call to a managed machine.
Port 8005 Right Ans - -Agent Handler Communication,
-Inbound TCP. ePO Agent Handlers connect to this port during installation and
updates
Port 8007 Right Ans - -Console-to-application (HTTPS),
-Inbound TCP. Port used to connect to the ePO web interface using HTTPS
Port 8443 Default SQL Port Right Ans - -Rogue system detection sensor
(HTTPS),
-Inbound TCP. The ePO server listens for Rogue System Detection events. Also
used by Agent Handlers to get information from the ePO (like LDAP servers).
Port 8082 Default SQL Port Right Ans - -UDP Broadcast communication
port,
-Inbound UDP. Agents listen for UDP broadcasts from SuperAgents
Distributed Repository Right Ans - Optionally configured and placed them
throughout your network strategically.
Ensure managed systems are updated while network traffic is minimized,
especially across slow connections.
As the master repository is updated, ePO replicates contents to the distributed
repositories
Repository Branches Current Right Ans - Acts as main repository branch
for the latest packages and updates.
The benefits of buying summaries with Stuvia:
Guaranteed quality through customer reviews
Stuvia customers have reviewed more than 700,000 summaries. This how you know that you are buying the best documents.
Quick and easy check-out
You can quickly pay through credit card or Stuvia-credit for the summaries. There is no membership needed.
Focus on what matters
Your fellow students write the study notes themselves, which is why the documents are always reliable and up-to-date. This ensures you quickly get to the core!
Frequently asked questions
What do I get when I buy this document?
You get a PDF, available immediately after your purchase. The purchased document is accessible anytime, anywhere and indefinitely through your profile.
Satisfaction guarantee: how does it work?
Our satisfaction guarantee ensures that you always find a study document that suits you well. You fill out a form, and our customer service team takes care of the rest.
Who am I buying these notes from?
Stuvia is a marketplace, so you are not buying this document from us, but from seller Studyhall. Stuvia facilitates payment to the seller.
Will I be stuck with a subscription?
No, you only buy these notes for $9.99. You're not tied to anything after your purchase.