WorksheetsAlert Logic
Total questions: 16
Worksheet time: 12mins
What are the key components of Cloud Defender
IDS, Log Management, Scanning,and WAF
Log Management, Web App IDS, WAF, Scanning, and IDS
Scanning, IDS, Log Management, Web App IDS, and Log Review
Active Watch, IDS, Log Management, scanning, and Web App IDS
Is Cloud Defender meant to replace RMS?
Maybe?
I've heard Cloud Defender is complimentary to RMS.
With Cloud Defender, responding to threats and vulnerabilities is left to the customer. RMS adds the layer of service on top of Alert Logic, acting on the behalf of my customer.
I thought RMS was Cloud Defender.
My customer has a cloud based (DNS) WAF today. Will they benefit from Cloud Defender?
Cloud Defender is meant to replace all cloud based WAFs, because of the Web App IDS.
My cloud based WAF is scrubbing ALL my traffic before entering my environment, I don't need any protection in my datacenter.
The two services are complimentary. My cloud based WAF will protect/scrub all my traffic, while Cloud Defender will protect me from threats and vulnerabilities that come into my environment.
I'm not comfortable talking about these services and how they help each other.
The two services are complimentary. My cloud based WAF will protect/scrub my 80/443 traffic, while Cloud Defender will protect me from threats and vulnerabilities that come into my environment.
Does Rackspace have an auto shun policy that gets applied to customers in dedicated environments who have a Cisco ASA?
No
Yes
I don't know
My customer has a physical WAF, can I sell them CD to replace the WAF?
No
It depends on the customers expectations of the WAF solution. If active blocking is a concern they should stay with their current solution.
Yes
I'm not sure, I don't know enough about WAF's and Cloud Defender.
As an SE during the presales process should I be asking my customer about Diffie Hellman certificates? I want to make sure my customer has a smooth on-boarding experience.
I only bring it up if I remember.
It never comes up until the implementation.
Yes I should be covering this topic during presales.
DH certificates don't affect anything in regards to architecture.
When deploying Cloud Defender in AWS what should I take into consideration from an infrastructure spend perspective, for a multi AZ environment (2 availability zones)?
Nothing. Cloud Defender pricing includes the necessary instances to deploy the appliances. for a given customer.
Two EC2 instances for a multi AZ environment. One EC2 instance for IDS and one EC2 instance for Log Manager.
At least one EC2 instance per AZ to deploy the IDS. Log Manager runs on top of these EC2 instances.
At least one EC2 instance per AZ to deploy the IDS. There is no Log Manager in AWS deployments.
Our goal at Alert Logic is to provide our customers with positive security outcomes.
True
False
Active Watch is included with Clouded Defender. What is the incident escalation time we have in our SLA to our customers?
5 minutes
30 minutes
15 minutes
25 minutes
In order to pull logs from servers an agent must be installed. Once the agent gets installed there is no other work needed to be done to pull relevant logs from the servers.
True
False
Where is my customers logs and user interface being served from?
The Alert Logic environment built in AWS.
The Alert Logic environment built in Azure.
The Alert Logic environment in the Denver Data center
The Alert Logic environment in the Houston Data center
Alert Logic can only protect Docker containers. No other container platforms are supported.
True
False
Alert Logic just had a security awareness call with my rep. I can assume that:
The customer now wants to buy Alert Logic.
The customer has had a high level overview of Rackspace security offerings and the threat landscape.
On the next call I should be able to now dive deeper into the individual solutions at Rackspace.
There is at least a potential opportunity to drive a sale at Rackspace.
This is the first I'm hearing about security awareness calls.
The Rackspace default auto-shun policy blocks all:
Critical level incidents
High level incidednts
Medium level incidents
Critical, high, medium level incidents
Critical and high level incidents
Medium and low level incidents receive a phone call from the Alert Logic SOC to the customer/Rackspace.
True
False
Alert Logic relies only on its honey pot network, threat researchers, and security content creators to create signatures and stay on top of the the latest vulnerabilities and threat landscape.
True
False
