Question #1

Importing and exporting definitions is needed in what environment?

A. In all GIM environments to provide consistency with S-TAPs.

B. Customer implementation using SPAN ports that want to share reports and policies.

C. Customer implementation with many standalone collectors that want to share reports and policies.

D. Customer implementation in a centrally managed environment (central manager) with 30 collectors that want to share reports and policies.

Question #2

What is the documented procedure for handling delayed cluster disk mounting?

A. Manually restart the S-TAP process after mounting the database server directory.

B. Configure the wait_for_db_exec parameter in the guard_tap.ini with an appropriate delay.

C. Ensure that the S-TAP process is started only after the database installation directory is available.

D. There is no special procedure, S-TAP can automatically detect when the database directory becomes available.

Question #3

A customer is deploying InfoSphere Guardium for Data Activity Monitoring (DAM) & Data
Level Access Control (DLAC). They are not sure where to locate their collector appliances
with respect to the database server that needs to be monitored & protected. Which
response is correct?

A. The collectors can be located anywhere on the network.

B. The collectors should be located in the same data center the database servers they monitor & protect reside.

C. The S-TAP must reside in the same data center the databases servers are at but the collectors can be anywhere.

D. The collectors and aggregators need to reside in the same location regardless of were the database servers reside.

Question #4

Which is NOT a valid classification rule type?

A. Catalog search

B. Search by permissions

C. Search for vulnerability

D. Search for unstructured data

Question #5

Given the GrdAPI command: grdapi upload_custom_data
tableName=DB2_COLUMN_PRIVS What does this command do?

A. upload database entitlement information into the DB2_COLUMN_PRIVS table for use in the DB2 entitlement reports

B. push Guardium audit information into the DB2 table DB2_COLUMN_PRIVS for use with the DB2 Unload command

C. upload entitlement information into the Guardium central manager for reporting on the DB2_COLUMN_PRIVS entitlement report

D. upload database entitlement information into S-TAP to block privilege users from accessing column level privileges within DB2

Question #6

How can you find the help documents within the Guardium GUI?

A. by selecting the "about" link in the upper right hand of the screen

B. by selecting the "?" to the right of the Portal Map icon

C. by selecting the "tools-> help" from the admin console

D. by selecting the magnifying glass icon in the upper right hand of the screen

Question #7

Guardium supports what databases platforms for entitlement reports?

A. DB2 Informix MS-SQL MySQL Netezza PostgreSQL

B. DB2 Informix MS-SQL Oracle PostgreSQL Sybase

C. DB2 Informix MS-SQL MySQL Netezza Oracle PostgreSQL Sybase Teradata

D. Netezza Oracle PostgreSQL Sybase Teradata

Question #8

Which consideration is true for a Vulnerability Assessment (VA) deployment?

A. Collectors running VA cannot also perform database monitoring.

B. Each collector can run up to 20 Vulnerability Assessments simultaneously.

C. S-TAP must be running on the database server before VA is run for a database on that server.

D. There is a need to create an account with appropriate privileges on the database for VA to work.

Question #9

Which action should be used to ignore activity from users or applications that are producing
a high volume of network traffic?

A. Audit Only

B. Skip logging

C. Ignore S-TAP session

D. Ignore SQL per session

Question #10

In a centrally managed environment, if the dedicated Central Manager is down, which
statement is true?

A. Interactive reports would not run.

B. Collector stop logging data from its S-TAPs.

C. Users would not be able to login to the Managed Units.

D. All Managed Units will revert to pre-registered configuration.

Question #11

Which Operating System requires a restart of the database instance (and listener, if
appropriate) in order to properly log traffic following a new S-TAP installation?


B. Linux

C. Solaris


Question #12

What is the default time of the command "store uid_chain_polling_interval <N>" where N is
time in minutes?

A. 2 minutes

B. 30 minutes

C. 60 minutes

D. 720 minutes

Question #13

After a role is removed, if the user attempts to access reports or applications that are no
longer authorized to this user, what will happen?

A. The user session will be terminated.

B. The user account will be temporarily locked.

C. A "not authorized" message will be produced.

D. Nothing, once you are given access removing roles will not affect your access to that application or report.

Question #14

What is the recommended procedure for unregistering a managed unit from a Central

A. It does not matter where a managed unit is unregistered.

B. Once registered, a managed unit should never be unregistered.

C. Unregistering a managed unit should be done from the Central Manager.

D. Unregistering a managed unit should be done from the managed unit itself.

Question #15

Which guard_tap.ini parameter is configured to set User ID (UID) chain logging?

A. hunt

B. uid_chain

C. hunter_trace

D. Specify "user" in Intercept Types