
642-531
QUESTION 114
Select the three phases of sensor tuning (Choose three.)
A. Prep Phase.
B. eployment Phase
C. Setup Phase
D. Tuning Phase
E. Maintenance Phase
F. Config Phase
Answer: A, B, C
Explanation:
The following routers do not support online insertion and removal (OIR) of network modules:
Cisco2600 series
Cisco2811
Cisco2821
Cisco2851
Cisco3620
Cisco3640
CiscoMWR1941-DC
QUESTION 115
Considering the following list of signature engines, which one would you deem is the best choice when creating
a custom signature when you consider a situation where an intruder has created a worm that targets an
application running on a fixed port and attempts to gain administrator access using a well-known default
password.
A. ATOMIC.IPOPTIONS
B. SERVICE.MSSQL
C. SERVICE.IDENT
D. STRING.TCP
Answer: D
TCP.STRING by using these parameters:
1. ToService (=number of the targeted port)
2. RegExString (=string of well known default password)
Reference:Cisco Courseware 13-62
QUESTION 116
Which of the following is used by a blocking Sensor inorder to manage a Cisco IOS router for shunning?
(Choose two.)
A. RDEP
B. Telnet
C. SSL
Comentários a estes Manuais