Skip to main content

 
Professional certification

  >  

Certifications

  >  

Test information

Test 937: IBM Tivoli Compliance Insight Manager V8.5 Implementation


Overview Objectives alt="" height="1" width="30" Test Preparation

Section 1: Planning

  1. Given the customer reporting needs, determine which report requirements can be supported by TCIM so that a reporting plan can be established for the implementation.

  2. With emphasis on the following steps:
    1. Identify the customer report needs.
    2. Analyze the reports requested by the customer.
    3. Determine which of these reports can be generated by TCIM.
    4. Categorize the reports per platform.
    5. Deliver a list of reports that can be produced.
    6. Discuss with the customer how the reports should be distributed – per platform, per department, with or without scoping.

  3. Given the customer report needs, review the requirements and assess which event sources will be required so that you can deliver a list of event sources needed for the TCIM environment.

  4. With emphasis on the following steps:
    1. Review the reporting requirements determined during the assessment of the customer reporting needs.
    2. Assess which event sources will be required to support the reporting requirements.
    3. Deliver a list of event sources that need to be deployed.

  5. Given the list of event sources needed to support the customer reporting needs, determine the best collection option for each event source so that you identify the appropriate collection method for each event source.
    1. Review the list of event sources determined during the assessment of the customer reporting needs.
    2. Discuss the collection options for each event source with the customer.
    3. Discuss the advantages and disadvantages of each collection mechanism (per event source).
    4. Assess the number of events per second to determine appropriate collection method for SNMP and syslog event sources.
    5. Determine the best collection option for each event source based on the customer feedback.

  6. Given each target platform and the specific procedures, determine and configure the audit settings so that the desired events can be logged and ready for collection.

  7. With emphasis on the following steps:
    1. Identify the Event Source.
    2. Identify the audit setting configuration procedure for the particular target platform.
    3. Specify audit events desired from target platform based on the customer reporting needs.
    4. Specify audit settings for desired platform.
    5. Assess impact of desired settings.
    6. Configure audit settings for desired platform.
    7. Enable auditing on desired platform.
    8. Verify desired events are being logged.

  8. Given hardware and software prerequisites, verify processors' speed, the RAM and hard disk space amounts, available ports and hard disk space partitions so that it is determined that the system meets prerequisites and server is ready to be configured for IBM Tivoli Compliance Insight Manager.

  9. With emphasis on the following steps:
    1. Verify the required hardware and software is available.
    2. Determine the rate of flow of collected data.
    3. Verify CD-ROM drive is available on all TCIM Servers included in installation.
    4. Verify servers and production network are available.
    5. Verify TCP/IP connectivity between monitored servers and TCIM Standard Server(s) is ensured.
    6. Identify the ports to be used by the installation.

    7. -Determine which port will be used for the database.
      -Determine which port will be used for the Directory Server.
      -Determine which port will be used for server and actuator communications; by default this is port 5992.
      -Verify that TCP port 139 is open to allow communication with Windows event sources.
      -Verify that the TCP port 22 is open to allow communications with UNIX SSH event sources.
      -Verify that the database port and the file share port are open for communication between Standard and Enterprise Server.
    8. Verify that SSH is utilized.
    9. Verify that your server’s hard drives are partitioned in a RAID level 5 configuration.
    10. Determine the appropriate hard disk space for the servers and Point of Presences, depending on the amount of daily log data that you collect for your monitored platforms and applications.
    11. Determine the appropriate hard disk space on the audited machines to support the expected audit volume.

  10. Given the event sources, processors, audited logs, hard drive partitions, memory, GEM databases and delivered reports, determine the number of servers required so that IBM Tivoli Compliance Insight Manager can be implemented.

  11. With emphasis on the following steps:
    1. Define What Platform types will be audited.
    2. Define Number of Machines Per each Platform type will be audited
    3. Determine the size of the audit files to be collected at a given rate for each Target Platform.
    4. Determine the number of event sources the environment will handle.
    5. Determine the number of GEM databases that will support the reporting requirements.
    6. Determine the amount of events that will be generated by syslog.

  12. Given the main components of IBM Tivoli Compliance Insight Manager, describe the purpose of the components so that key components are identified.

  13. With emphasis on the following steps:
    1. Describe the purpose of the standard server.
    2. Describe the purpose of the management console.
    3. Describe the purpose of the Web portal.

    4. -Describe iView.
      -Describe log manager.
      -Describe policy generator.
      -Describe scoping.
      -Describe regulatory compliance.
    5. Describe the purpose of the enterprise server.
    6. Describe the actuator.

  14. Given the collection, load, and restart schedules, plan the scheduled tasks so that continuity and completeness of data is maintained.

  15. With emphasis on the following steps:
    1. Determine when the restart task should take place.
    2. Determine when the collects should take place.
    3. Determine when the loads should take place.
    4. Determine when the report distribution should take place.

  16. Given the GEM database and W7 grammar, explain how event values are mapped to the GEM fields and categorized into W7 groups so that the W7 and GEM models are described.

  17. With emphasis on the following steps:
    1. List the W7 dimensions.
    2. List the GEM fields.
    3. Describe the relationship between the W7 grammar elements and the GEM fields.
    4. Explain how the event values are mapped to the GEM fields.
    5. Explain how event values are categorized into W7 groups.

  18. Given TCIM policies, describe how policy exception and attention event are generated so that security rules are identified.

  19. With emphasis on the following steps:
    1. Describe with the W7 Model what would be an acceptable behavior of an event.
    2. Describe how a policy exception is generated.
    3. Describe how an attention event is generated.

  20. Given an installed TCIM 8.0 or 7.0 environment create an implementation plan so that a TCIM upgrade can be performed.

  21. With emphasis on the following steps:
    1. Ensure that you have a backup of your current installation of TCIM.
    2. Document the current environment.

    3. -Assess current environment for capacity considerations
    4. Define rollback plan.
    5. Choose which server will be designated as the security server.
    6. Determine which TCIM servers and components to upgrade.
    7. Determine the order of components to upgrade.
    8. Ensure there is enough hard disk space for the upgrade.
    9. Ensure media has been acquired or downloaded.
    10. Acquire latest patches.

Section 2: Installation

  1. Given the installation media and a Windows 2003 server, install the database engine, directory server, and standard server, so that a TCIM security server is defined for centralized user management.

  2. With emphasis on the following steps:
    1. Log in to the Windows server as a user with administrative privileges.
    2. Verify system prerequisites have been met.
    3. Install the middleware.
    4. Install the standard server.
    5. Apply current patches and platform updates.
    6. Verify the installation.

  3. Given the installation media and a Windows 2003 server, install a standard server, so that audit trails can be collected.

  4. With emphasis on the following steps:
    1. Log in to the Windows server as a user with administrative privileges.
    2. Verify system prerequisites have been met.
    3. Install the middleware.

    4. -Install the database engine.
      -Install the directory server or connect to an existing security server.
    5. Install the standard server.
    6. Apply current patches and platform updates.
    7. Verify the installation.

  5. Given the installation media and a Windows 2003 server, install an enterprise server, so that a TCIM cluster is defined.

  6. With emphasis on the following steps:
    1. Log in to the Windows server as a user with administrative privileges.
    2. Verify system prerequisites have been met.
    3. Install middleware.

    4. -Install the database engine.
      -Install the directory server or connect to an existing security server.
    5. Install the enterprise server.
    6. Apply current patches and platform updates.
    7. Verify the installation.
    8. Subscribe servers to the cluster.

  7. Given the installation media, upgrade a standard server to an enterprise server so that a TCIM cluster can be defined.

  8. With emphasis on the following steps:
    1. Identify the standard server to be upgraded.
    2. Launch the server installation
    3. Perform a custom setup.
    4. Choose the enterprise components.
    5. Complete the installation.
    6. Subscribe servers to the cluster.

  9. Given the TCIM hotfix code on Windows platform, apply the hotfix so that TCIM is updated to the desired level.

  10. With emphasis on the following steps:
    1. Verify the current hotfix level is installed.
    2. Apply hotfix.
    3. Verify the hotfix has been successfully applied.

  11. Given the TCIM hotfix code on the UNIX platform, apply the hotfix to the current environment so that the TCIM is updated to the desired level.

  12. With emphasis on the following steps:
    1. Apply hotfix.
    2. Verify the hotfix has been successfully applied.

  13. Given a running TCIM installation, verify the ability to log in, and that key processes and services are running so that the successful installation is confirmed.

  14. With emphasis on the following steps:
    1. Verify you are able to log in to the Management Console and TCIM Web applications.
    2. Verify that all TCIM services started after successful installation.
    3. Review the installation log files.
    4. Verify the TCIM directory structure has been created.
    5. Verify the main processes are running.

  15. Given Compliance report media, verify the execution of the compliance setup program so that the compliance module is installed in the iView application.

  16. With emphasis on the following steps:
    1. Verify Compliance Reports Media and size.
    2. Verify the available space.
    3. Copy the compliance reports setup to a temporary directory.
    4. Run set up.
    5. Verify successful installation.
    6. Delete the compliance reports setup from the temporary directory.

  17. Given the actuator code and cfg file, install the actuator code on a supported platform so that an actuator is installed and ready to collect audit trails.

  18. With emphasis on the following steps:
    1. Log in to the server where the Point of Presence is to be installed.
    2. Mount the agent installation media.
    3. Launch the agent setup program.
    4. Install the agent code.
    5. Provide the agent cfg file to establish the Point of Presence to server configuration.
    6. Verify the installation.

  19. Given the management console and properly configured actuator and target machine, use the add machine process so that the actuator code is remotely installed.

  20. With emphasis on the following steps:
    1. Verify what other applications running on the target system that may interfere with the installation.
    2. Launch the management console.
    3. Add a new machine.
    4. Select the system type.
    5. Select the machine or machines to be audited.
    6. Select local for the point of presence.
    7. Define the communication port.
    8. Select automatic for the installation type.
    9. Enter the NetBios name for the machine or machines.
    10. Enter the operating system credentials for the actuator service.
    11. Enter the operating system credentials to be used to complete the installation.
    12. Define the event source or sources to be audited.
    13. Complete the add machine process.

  21. Given an installed TCIM 8.0 or earlier Standard Server perform the upgrade so that TCIM 8.5 and all of its components are functional.

  22. With emphasis on the following steps:
    1. Identify components to be upgraded.
    2. Log in to the windows server using account with administrative privileges.
    3. Verify that prerequisites have been met.
    4. If using a central user information store, install a security server.
    5. Upgrade the Enterprise Server (if present).
    6. Upgrade all Standard Servers
    7. Register Standard Servers with Enterprise Server.
    8. Upgrade the Point of Presences.
    9. Verify the upgrade was successful.

Section 3: Configuration

  1. Given the security compliance reporting requirements for a specific audit platform, configure the audit subsystem so that the collected security audit data can be used to generate the required security compliance reports.

  2. With emphasis on the following steps:
    1. Translate the Security Compliance reporting requirements to the required Audit Setting Configurations on the target platform.
    2. Review the current audit settings on the target platform.
    3. Apply changes to the current audit settings.
    4. Verify that the audit settings changes have been committed.
    5. Verify that the data collected (after committed the audit setting changes) meet the Security Compliance reporting requirements.

  3. Given the management console, use the add machine process so that an audit trail is collected locally.

  4. With emphasis on the following steps:
    1. Launch the management console.
    2. Add a new machine.
    3. Select the system type.
    4. Select the machine or machines to be audited.
    5. Select local for the point of presence.
    6. Define the communication port.
    7. Select automatic or manual for the installation type.

    8. -If automatic installation is selected, enter the NetBios name for the machine or machines.
      -If automatic installation is selected, enter the operating system credentials for the actuator service.
      -If automatic installation is selected, enter the operating system credentials to be used to complete the installation.
    9. Define the event source or sources to be audited.
    10. Complete the add machine process.

  5. Given a Windows target machine, configure the machine so that security audit logs can be successfully collected via remote collection mechanism.

  6. With emphasis on the following steps:
    1. Configure or verify the Windows Domain relationship required for the remote collection of the target machine from TCIM server (or Windows Actuator).
    2. Configure or verify that the Windows Services and network settings on the target machine required for remote collection are properly configured.
    3. Configure or verify that the Windows Services and network settings on the TCIM server (or Windows Actuator) required for remote collection are properly configured.
    4. Configure or verify that the TCP/IP connectivity between TCIM server (or Windows Actuator) and the target windows machine required for remote collection are enabled.
    5. Configure or verify that the TCIM Server (or Windows Actuator) service run account has security privileges to perform a successful remote of the security log data from the target machine.
    6. Add the remote collect windows target machine to the management console.
    7. Add the corresponding event sources to the remote collect windows target machine.
    8. Configure the event source properties of the remote event sources in the management console.
    9. Verify that the security log data from the Windows target can be successfully collected.

    10. +#Given SSH is configured, follow the add machine wizard so that remote SSH collection is installed.
      With emphasis on the following steps:
    11. Determine the SSH daemon is running on the audited system.
    12. Ensure PuTTY is installed on the point of presence.
    13. Determine the authorization key pair to use.
    14. Enable a user account on the audited system.
    15. Create the user.

    16. -Ensure that the partition that contains the user home directory has enough free space to store a copy of the collected log data.
      -Ensure that the user has all the necessary access to the log files and directories used during collect.
      -Ensure that all commands to be run are in the user path and that the user is allowed to execute them.
      Create a special subdirectory in the user home directory to contain its authorized keys.
    17. Test the communication between the point of presence and the audited machine.
    18. Start the Add Machine wizard to add the audited system.
    19. Ensure the collect is successful.

  7. Given the network identity of the appliance, add the network appliance to the TCIM server so that security logs from the network appliance can be successfully collected.

  8. With emphasis on the following steps:
    1. Ensure that the communication path between the TCIM server (or Point of Presence) and the appliance allows unblocked transmission of the security events from the appliance.
    2. Verify that appliance events are directed to TCIM.
    3. Add the appliance as an audited machine to the TCIM server.
    4. Verify that the security events from the appliance can be collected by the TCIM server.

  9. Given a supported syslog ng environment and remote SSH collection is properly configured, configure the TCIM syslog collector so that the syslog events can be collected by TCIM.

  10. With emphasis on the following steps:
    1. Determine appropriate syslog collection method.

    2. If built-in syslog receiver is appropriate;
      Ensure communication path from each audited system to TCIM receiver via UDP port 514 is open and available
      Configure the audited system to forward syslog messages to Windows Point of Presence
      If syslog collector is appropriate;
      Ensure communication path from each audited system to syslog collector via UDP port 514 is open and available
      Ensure SSH communication between syslog collector and the designated Point of Presence is open and available
      Ensure that audited systems are appropriately configured to forward messages to the syslog collector
    3. Configure the syslog collector and the designated Point of Presence for SSH collection
    4. Ensure syslog message format meets requirements.
    5. Add the appropriate event source to TCIM
    6. Verify successful syslog message collection and mapping

  11. Given the scripts, configurations, mapping definition files, collection and load processes, add an event source so that audit trails can be stored, mapped and loaded into GEM databases.

  12. With emphasis on the following steps:
    1. Open the management console
    2. Select the Event Source View
    3. Click Add Event Source
    4. Select Machine from witch to collect from
    5. Select the Event Source Type
    6. Define the Event Source Properties
    7. Define Collect Schedule
    8. Select GEM for data loads
    9. Define Load Schedule

  13. Given the management console, use the add machine process so that a W7 log file is collected.

  14. With emphasis on the following steps:
    1. Define a process that takes the custom log file and converts it to the W7 Log modified format (CSV or XML).
    2. Implement the log file conversion process.
    3. Launch the management console.
    4. Add a new machine.
    5. Select the system type.
    6. Select the machine or machines to be audited.
    7. Select local for the point of presence.
    8. Define the communication port.
    9. Select automatic or manual for the installation type.

    10. -If automatic installation is selected, enter the NetBios name for the machine or machines.
      -If automatic installation is selected, enter the operating system credentials for the actuator service.
      -If automatic installation is selected, enter the operating system credentials to be used to complete the installation.
    11. Define the event source as W7 Log (choosing the appropriate format of CSV or XML).
    12. Define the event source properties.
    13. Complete the add machine process.

  15. Given the location information of a user and grouping store, configure the user information source to collect the user and grouping information from the store so that the user information source collects the user and grouping information.

  16. With emphasis on the following steps:
    1. Configure or verify that the TCIM server (or Windows Actuator) service run account has security privileges to perform a successful collection of the user and grouping information from the store.
    2. Configure or verify that the user account (provided as part of User Information Source property) has security privileges to successfully collect the user and grouping information from the store.
    3. Configure or verify that the Windows Services network settings are properly configured on the store for user and grouping information collection.
    4. Configure or verify that the TCP/IP connectivity between TCIM server (or Windows Actuator) and the user and grouping store are enabled.
    5. Configure or verify that the Windows Services network settings on the TCIM server (or Windows Actuator) required for user and grouping information collection are properly configured.
    6. Add the User Information Source to the management console.
    7. Configure the User Information Source properties in the management console.
    8. Verify successful collection from the User Information Source.

  17. Given the Attention rules, protocol, severity and recipient list, set an alert so that the alert communicates an attention rule to the recipient list.

  18. With emphasis on the following steps:
    1. Identify the Attention Rule ID to use in the alert.
    2. Select the Alert Maintenance Icon in the Management Console.
    3. Create the Alert using the Rule ID, Protocol, Recipient, Severity.
    4. Verify the Alert are received or generated.

  19. Given the management console, use the policy explorer and the company security to define a basic policy so that the customer reporting needs are met.

  20. With emphasis on the following steps:
    1. Determine which policies in the company security policy can be mapped to a TCIM security policy.
    2. Launch the management console.
    3. Open the policy explorer.
    4. Duplicate the latest committed TCIM policy.
    5. Edit the duplicate TCIM policy.
    6. Define the appropriate W7 groups to support the company security policy.
    7. Define the appropriate policy rules to support the company security policy.
    8. Define the appropriate attention rules to support the company security policy.
    9. Save and test the new TCIM policy.
    10. Continue testing until the desired reporting needs are met.
    11. Commit the new TCIM policy.

  21. Given that scoping is required, assign assets so that access can be regulated.

  22. With emphasis on the following steps:
    1. Identify assets which require scoping.
    2. Configure scoping for unassigned assets.

    3. -On the entry page, click Enable Scoping.
      -On the Confirm Status Change page, click Start to enable scoping or Cancel to end your operation.
      -If you clicked Start, the Changing Scoping Status page is displayed. Wait till the change of the scoping status is complete.
      -Define Scoping groups and assign users to these groups.
      -Move a selection of W7 groups to the Scoping groups.
      -Create similar Scoping groups for the Who, Where and OnWhat categories
      -Reload the test data and log on into iView with one of the users that have restricted viewing capabilities as defined through the Scoping module.

  23. Given the list of reports needed to satisfy customer needs, determine which reports will require a custom solution so that the customer reporting needs are met.

  24. With emphasis on the following steps:
    1. Review the list of list of reports needed to satisfy customer needs.
    2. Determine which reports can be satisfied by the standard reports.
    3. Determine which reports will require a custom solution.
    4. For each custom report requirement, determine the following criteria:

    5. -Report layout – report type and column selection
      -Report criteria – event selection and conditions
    6. Use the report wizard or a text editor to create the custom report.

  25. Given a set of GEM load schedules, configure the TCIM Automated Report Distribution manager such that the GEM database reports are successfully sent on-time to a corresponding set of recipients.

  26. With emphasis on the following steps:
    1. Configure the general setting for report distribution.
    2. Determine a time-line at which GEM database load completes and the GEM reports become available for distribution.
    3. Determine the schedule for setting up the report distribution for each GEM database.
    4. Verify with a test report distribution task that the report can be sent successfully to a test recipient.
    5. Add the Report Distribution tasks for each GEM database.
    6. Verify that the reports are distributed to the correct set of recipients on-time.

Section 4: Performance Tuning and Problem Determination

  1. Given TCIM activities, identify log files so that troubleshooting can take place for the TCIM solution.

  2. With emphasis on the following steps:
    1. Identify log file that shows a collection has been successful.
    2. Identify log file that shows the progress of a load into a GEM database, as well as the archiving of them.
    3. Identify log file that shows the progress of a connection to a remote host and to the TCIM server.
    4. Identify log file that shows iView reporting errors.
    5. Identify the log where the actuator run on the point of presence shows its collection activity.
    6. Identify the schedule restart log and sub log of the processes it runs.
    7. Identify the Management Console activities events and the log where they can be found.
    8. Identify the Consolidation log file.
    9. Identify the successful database mount and activity log.
    10. Identify the Log Manager activity log.
    11. Identify the log file where iView activity can be found.
    12. Identify the log file where lost chunks will be shown if they have been transferred to the depot.
    13. Identify the log file showing reports have been delivered by the Distribution scheduled task or error occurred.
    14. Identify log file indicating authentication to the web portal application.
    15. Identify log file where Policy Generator Activity is found.
    16. Identify the application that collects most of the log files for troubleshooting.

  3. Given a GEM database, investigate the set of activities taking place during the GEM load so that the basic stages of load are described.

  4. With emphasis on the following steps:
    1. Identify the type of the GEM database load.
    2. Identify the different phases of the GEM load.
    3. Identify the type of mapping used by the GEM database.
    4. Determine the current stage of the load.
    5. Determine whether any error occurred during the load, and in which phase of the load.
    6. When an error occurs during any phase of the load, determine the set of log files that need to be preserved for further investigation.
    7. Determine the duration of each phase of the load.
    8. Determine whether the load has completed at any point in time, and the total duration of the load.

  5. Given the verification of possible failures, troubleshoot the logon failure so that successful logon is achieved.

  6. With emphasis on the following steps:
    1. Verify TCIM services are running.
    2. Verify database and directory services are running.
    3. Verify correct user name and password are being used.
    4. Verify the restart task.
    5. Verify the recnotify.
    6. Verify the blrec.

  7. Given the log files and error message, apply standard problem determination techniques so that the problem can be resolved.

  8. With emphasis on the following steps:
    1. Identify the component that is failing (such as server, management console, web portal, and so on).
    2. Determine the type of failure (login, connectivity, and so on).
    3. Identify the log file needed to gather additional information on the failure.
    4. Review the appropriate log file.
    5. Correct the problem or call support.

  9. Given a TCIM Server or a Windows Point of Presence, generate and deliver diagnostics such that the diagnostics is complete and is successfully delivered to the Support recipient.

  10. With emphasis on the following steps:
    1. Identify the TCIM Server or Windows Point of Presence where the diagnostics needs to be generated.
    2. Ensure that there is enough disk space to store the diagnostics.
    3. Determine under what situations a diagnostics file may be generated.
    4. Locate the Windows program menu for Diagnostics generation and start up the Diagnostics generation task.
    5. Choose the path where the Diagnostics file has to be generated.
    6. Ensure that the diagnostics file has been generated.
    7. Ensure that the diagnostics file is complete.
    8. Deliver the diagnostics to the intended support recipient.
    9. Verify that the support recipient has successfully received the diagnostics file.

  11. Given the management console, test the connectivity, so that there is a successful connection to point of presence.

  12. With emphasis on the following steps:
    1. Right-click machine name.
    2. Choose the properties option.
    3. Click the Network Tab.
    4. Click the Test IP and Port button.
    5. Verify that message Port is listening appears.
    6. Review log files to determine if there are any connections errors.

  13. Given a set of report distribution schedules, troubleshoot the report generation and distribution process such that the reports are successfully generated and distributed to the designated user.

  14. With emphasis on the following steps:
    1. Identify the status message contained in the email sent by the distribution task.
    2. Ensure that the report was successfully exported by the GEM database load process.
    3. Ensure that the distribution schedule for the exported report was successful.
    4. Ensure that the exported file format can successfully handle the amount of events exported to the report.

Section 5: Administration

  1. Given the management console application, navigate through the different views so that you can perform the basic administration activities for audited machines.

  2. With emphasis on the following steps:
    1. Launch the management console.
    2. Open the audited machine view or event source view.
    3. Determine which machines are being audited.
    4. Determine to which machine group each audited machine is assigned.
    5. Add a new audited machine.
    6. Determine which event sources are being collected for each audited machine.
    7. Determine the audit settings applied to each event source.
    8. Determine where the event sources are being collected (local or remote).
    9. Add a new event source.
    10. Determine the state of each point of presence.
    11. Determine the last collection date and time.
    12. Determine the collection schedule for an event source.
    13. Configure the collection schedule for an event source.
    14. View the basic settings for a point of presence.
    15. Test the connection to a point of presence.
    16. Generate a new password when the secure channel between the server and a point of presence is broken.
    17. Add a user information source.

  3. Given the management console application, navigate through the database view so that you can perform the basic administration activities for databases.

  4. With emphasis on the following steps:
    1. Launch the management console.
    2. Open the database view.
    3. Determine the load schedule for a database.
    4. Determine the load status for a database.
    5. Associate an event source with an existing database.
    6. Add a new database.
    7. Manually load a database.

  5. Given the management console application, navigate to the alert panel so that you can perform the basic administration activities for alerts.

  6. With emphasis on the following steps:
    1. Launch the management console.
    2. Open the alerts panel.
    3. View or modify existing alerts.
    4. Define a new alert.
    5. Create an alert rule that is only triggered by the eventid of an attention rule.
    6. Verify alerts are sent.

  7. Given the management console application, navigate to the user management panel so that you can perform the basic administration activities for users.

  8. With emphasis on the following steps:
    1. Launch the management console.
    2. Create or modify a user.
    3. Assign appropriate roles to a user.
    4. Define database access for a user.
    5. Delete a user.

  9. Given the management console application, navigate to the policy explorer so that you can perform the basic administration activities for policies.

  10. With emphasis on the following steps:
    1. Launch the management console.
    2. Open the policy explorer
    3. List the previously committed policies.
    4. List the policies in draft mode.
    5. Edit a draft policy.

    6. -Add or modify grouping files.
      -Add or modify policy and attention rules.
    7. Commit a draft policy.
    8. Open a committed policy.
    9. Create a new policy based on an existing policy.
    10. View an automatic policy.

  11. Given the TCIM Web portal and TCIM user account with access to iView, navigate iView so that the functionalities are described.

  12. With emphasis on the following steps:
    1. Access TCIM Portal
    2. Access iView
    3. Describe Compliance Dashboard

    4. -Describe Enterprise Overview
      -Describe Trend graphic
      -Configure the trend graphic settings.
      -Describe Database overview
      -Configure the Dashboard settings.
    5. Describe GEM Summary

    6. -Describe Event Information
      -Describe Status of the Database
      -Describe Data in the Database
    7. Describe Event Details

    8. -Describe Detail and Group for the W7 Dimensions
      -Describe Incident Tracking
      -Describe Additional information
      -Describe Investigate
    9. Execute a Standard report for a GEM
    10. Execute a Regulatory Report for a GEM
    11. Verify the groups on the loaded Data
    12. Verify the applied Policy on the loaded Data
    13. Verify the trends on the loaded data
    14. Describe general iView settings.
    15. Schedule reports to be delivered for a GEM

  13. Given the TCIM Web portal and a TCIM user with access to log manager, navigate the log manager so that the log manager functionalities are described.

  14. With emphasis on the following steps:
    1. Access TCIM Portal.
    2. Access Log Manager Application
    3. Describe the Log Manager Dashboard
    4. Describe the Collect History Status, including an explanation of how the collect status is determined.
    5. Describe the Log Continuity Status
    6. Describe History
    7. Describe Continuity including an explanation of the CCRG scheduler and the underlying algorithm.
    8. Describe Activity
    9. Describe Investigate
    10. Describe Retrieval

  15. Given the TCIM Web portal and a TCIM user account with access to the policy generator, navigate the policy generator so that the policy generator functionalities are described.

  16. With emphasis on the following steps:
    1. Access TCIM Portal.
    2. Access the Policy Generator Application
    3. Define the name of the policy to generate.

    4. -Select the Data to use
      -Generate Automatic Policy file
      -Test data in a GEM with policy

  17. Given the depot and collected chunks, perform an export so that collected audit trails are archived.

  18. With emphasis on the following steps:
    1. Verify disk space for export.
    2. Determine export location.
    3. Configure an export schedule based on the customer’s retention policy.
    4. Verify that the export was successful.

  19. Given the depot and archived chunks, perform an import so that archived audit trails are restored.

  20. With emphasis on the following steps:
    1. Determine when the requested data was archived.
    2. Locate the appropriate archived data.
    3. Import the appropriate archived data.
    4. Verify the data was successfully imported.

  21. Given a TCIM installation, verify the status of collects, loads, report generation and distribution, real time alerting so that the overall health of the TCIM installation environment is verified.

  22. With emphasis on the following steps:
    1. Verify that all services related to the TCIM server are running.
    2. Determine the Audited machines involved in the TCIM installation.
    3. Verify that collects are happening on schedule from all audited machines.
    4. Verify that the collected data from the audited machines is complete and consistent.
    5. Verify that the GEM loads are occurring regularly and the GEM loads complete successfully.
    6. Verify that the data loaded in the GEM database is complete and consistent.
    7. Verify that real time alerts (if configured) are sent out and the recipients have received it successfully.
    8. Verify that the reports are generated by the GEM database.
    9. Verify that the GEM database reports are distributed and received successfully by the intended recipients in a timely manner.
    10. Verify that the GEM database reports are complete and consistent.

Test registration

Authorized Prometric test centers (worldwide testing)