Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Ficha Técnica Página 64

  • Descarregar
  • Adicionar aos meus manuais
  • Imprimir
  • Página
    / 123
  • Índice
  • MARCADORES
  • Avaliado. / 5. Com base em avaliações de clientes
Vista de página 63
642-531
QUESTION 148
Which of the following signature descriptions best describes a service signature engine?
A. Inspects multiple transport protocols.
B. Detects network reconnaissance.
C. Protocol analysis for layers 5, 6, and 7 applications.
D. Identifies traffic irregularities.
Answer: C
Explanation:
SERVICE.* EnginesUse the SERVICE engines to create signatures that deal with the Layer 5+ protocol of the
service. The DNS (TCP and UDP) engines support analysis of compressed messages and can fire alarms on
request/reply conditions and overflows. The RPC and PORTMAP engines are fine tuned for RPC and
Portmapper requests. Batch and fragmented messages are decoded and analyzed.
Reference:Cisco Courseware 13-41
QUESTION 149
Which of the following signature engines would be the most appropriate to create a custom signature that
would inspect data at Layer 5 and above?
A. STRING
B. SWEEP
C. ATOMIC
D. SERVICE
Answer: D
Page 437 Cisco Press CCSP CSIDS 2nd edition under Cisco IDS Signature Engines
See: Table 13-6 Signature Engine Categories
Service: Used when services at OSI Layers 5, 6 and 7 require protocol analysis
Cisco Courseware 13-41
QUESTION 150
When creating custom signatures using the TROJAN engines, which parameter values are required?
A. protocol
B. source/destination IP addresses
C. regular expression strings
D. these signatures cannot be created
Answer: D
You cannot create custom signatures with Trojan engies.
Cisco Courseware 13-73
Vista de página 63
1 2 ... 59 60 61 62 63 64 65 66 67 68 69 ... 122 123

Comentários a estes Manuais

Sem comentários