MA0-101 Sample Questions & Answers
Deployment architecture and planning tie with tuning intrusion prevention policies for the top weight, alongside administering the Manager and its backups and licensing, role-based access control, sensor installation and health, alert investigation, and reporting.
Launch the full MA0-101 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Policy Configuration and Management · Policy Optimization
Case Study:
A rapidly growing e-commerce company, 'SwiftCart', is experiencing performance degradation on its M-series NSP Sensor that protects its primary web server farm. The Sensor's CPU utilization frequently spikes to 100% during peak business hours. A review of the applied policy shows that it contains over 5,000 enabled attack signatures, including many for protocols not used in their environment (e.g., SCADA, industrial control systems).
The security team's primary goal is to reduce the CPU load on the Sensor without compromising the security of their web applications. They have a secondary goal of improving the accuracy of alerts to reduce analyst fatigue. The network consists of standard HTTP/HTTPS, SQL, and DNS traffic.
Which strategy should the security team implement to best achieve their goals?
Show answer & explanation
Correct answer: C
This is the most effective strategy. Starting with a specialized template like 'Web Server' provides a relevant and optimized baseline. Disabling entire categories of attacks that are not applicable to the protected assets (like SCADA) drastically reduces the number of signatures the Sensor has to process for each packet, directly lowering CPU load. This also improves alert accuracy by eliminating irrelevant potential alerts, addressing both of the company's goals without requiring a hardware upgrade.
- Question 2Intermediate
Threat Detection and Response · False Positive Management
During a vulnerability scan, an administrator notices a large number of 'TCP Port Scan' alerts in the Threat Explorer originating from their internal vulnerability scanner's IP address. This is expected behavior, but it is cluttering the alert view for the security operations team. What is the BEST PRACTICE to handle these specific alerts without affecting the detection of real port scans from other sources?
Show answer & explanation
Correct answer: D
Creating an Attack Policy Exception is the most precise and recommended method. It allows the administrator to suppress a specific signature (TCP Port Scan) only when the traffic originates from a specific source IP (the vulnerability scanner). This stops the unwanted alerts while keeping the signature active to detect malicious scans from any other source, achieving the goal without creating a security blind spot.
- Question 3Intermediate
User and Access Management · External Authentication
An administrator is configuring a new NSP Manager and needs to integrate it with the company's Active Directory for user authentication. The goal is to allow network administrators, who are members of the 'NSP-Admins' AD group, to log in to the NSP Manager with their domain credentials. Which component must be configured in the NSP Manager to facilitate this?
Show answer & explanation
Correct answer: C
Active Directory uses the Lightweight Directory Access Protocol (LDAP) for querying and authenticating users. To integrate NSP Manager with Active Directory, an administrator must configure an LDAP Server profile with the details of the domain controller, service account credentials, and the directory structure (base DN). This profile allows the Manager to query AD to authenticate users and check group memberships.
- Question 4Advanced
NSP Deployment and Planning · Sensor Placement
A network architect is designing a security solution for a data center using the following topology. The goal is to inspect all traffic between the Web/App tier and the Database tier for potential threats.
Internet | [Firewall] | [Core Switch] / [Web/App Tier] [Database Tier] (10.10.10.0/24) (10.10.20.0/24)Given that the traffic between these two tiers is high-volume and low-latency is critical, what is the most appropriate deployment mode and location for the NSP Sensor?
Show answer & explanation
Correct answer: B
To inspect and block all traffic between the tiers, the Sensor must be placed inline. Placing it in L2 Transparent Bridge mode between the Core Switch and the Database Tier's switch allows it to inspect all traffic destined for the databases without requiring any IP address changes or routing modifications. This inline position is necessary for prevention, and the L2 mode simplifies integration into the existing network fabric, meeting the requirement to inspect all traffic.
- Question 5Intermediate
Threat Detection and Response · Botnet Detection
What is the primary function of the 'Botnet Controller and Infected Host' callback detection feature in McAfee NSP?
Show answer & explanation
Correct answer: A
The core function of callback detection is to identify already-infected hosts within the network that are attempting to 'call back' to their external C2 servers for instructions. NSP maintains a list of known malicious C2 domains and IP addresses and blocks any outbound communication to them, effectively neutralizing the bot and alerting administrators to the compromised host.
- Question 6BeginnerSelect 2
NSP Manager Administration · Backup and Restore
An administrator needs to perform a backup of the NSP Manager configuration. Which TWO of the following items are included in a standard Manager backup? (Select TWO)
Show answer & explanation
Correct answers: C, D
- Question 7Intermediate
Sensor Management · CLI Commands
The 'set sensor-shared-secret' command is used for what purpose on the NSP Sensor CLI?
Show answer & explanation
Correct answer: B
The sensor shared secret is a pre-shared key that is configured on both the Sensor (via CLI) and the Manager (via GUI) during the initial setup. It is used to authenticate the Sensor to the Manager and establish the secure TLS tunnel for all subsequent communication. It is a critical step in adding a new Sensor to be managed.
- Question 8Intermediate
Reporting and Maintenance · Log Integration
A hospital needs to comply with regulations that require long-term storage of all security alerts. The NSP Manager's local database has limited retention capacity. What is the recommended method for forwarding all generated alerts to a centralized, long-term storage solution?
Show answer & explanation
Correct answer: B
The standard and most scalable method for long-term log retention and centralized analysis is to forward alerts to a Syslog or Security Information and Event Management (SIEM) server. The NSP Manager can be configured to send alerts in real-time in standard formats like CEF or LEEF. This offloads the storage burden from the Manager and integrates the NSP data into the broader security monitoring ecosystem.
- Question 9Advanced
User and Access Management · Role-Based Access Control
Case Study:
'Global Logistics Inc.' has deployed NSP Sensors at multiple branch offices, all managed by a central NSP Manager at their headquarters. Each branch office has a local IT administrator responsible for monitoring their own site's security events, but they should not be able to see events from other branches or modify global security policies.
The headquarters security team is responsible for creating and distributing all IPS policies. They have created a hierarchical Administrative Domain structure in the NSP Manager, with 'Global' as the parent domain and individual branches like 'Branch-A' and 'Branch-B' as child domains.
How should the user accounts and permissions be structured to meet these requirements?
Show answer & explanation
Correct answer: A
This solution correctly implements the principle of least privilege using NSP's features. Placing the user in the child domain ('Branch-A') restricts their visibility to only the devices and events within that domain. Assigning a custom 'Branch-Monitor' role with view-only permissions prevents them from making changes. The global policies created in the parent 'Global' domain will be inherited by the child domains but cannot be modified by the local administrators.
- Question 10Beginner
Policy Configuration and Management · Policy Types
True or False: The 'Network Access Policy' in McAfee NSP is primarily used for defining firewall-like access control rules based on IP address, port, and protocol.
Show answer & explanation
Correct answer: A
True. The Network Access Policy (or Access Control Policy) provides stateful firewall capabilities within the NSP Sensor. It allows administrators to create rules to permit or deny traffic based on Layer 3 and Layer 4 information, such as source/destination IP addresses, ports, and protocols, similar to a traditional firewall.
Ready for the real thing?
The full MA0-101 simulator has every exam-style question, timed mode, and instant scoring.