
642-531
B. Logs deny ACL entries
C. Sends SNMP traps to the Sensor
D. Sends Syslog messages to the Sensor
E. Sends SNMP traps to the Director
F. Sends syslog messages to the Director
Answer: B, F
Explanation:
The Sensor can be configured to create an alarm when it detects a policy violation from the syslog generated by
a Cisco router. A policy violation is generated by a Cisco router when a packet fails to pass a designated Access
Control List. Security data from Sensor and Cisco routers, including policy violations, is monitored and
maintained on the Director.
Reference: Cisco Secure Intrusion Detection System Overview
QUESTION 162
The new Certkiller trainee technician wants to know which of the following IDS software components can be
upgraded from IDS MC's Updates page. What would your reply be? (Choose all that apply.)
A. IDS Sensor recovery partitions
B. IDS MC signatures
C. IDS Sensor service packs
D. IEV signatures
E. IDS Sensor version 3.x-4.x upgrades
Answer: B C E
Explanation:
Cisco Systems periodically releases updates of sensor software versions and signature release levels for its IDS
Sensors (both sensor appliances and IDS modules). Two procedures are available:
* Updating IDS Sensor Software from 3.x to 4.x
* Updating IDS Sensor Software Other than from 3.x to 4.x
You should also understand the update files:
1. Cisco releases its periodic updates of sensor software versions and signature release levels for its IDS
Sensors in the form of update files that are compressed (.zip). IDSMC works with these compressed files
2. There are two types of update files:
1. Service pack update files-You can identify service pack update files by their names: the letters "sp" precede
the version number. When these update files are applied, they change the version number of a sensor. Service
contain signature updates.
2. Signature update files-Signature update file names contain the letters "sig" before the version number.
Signature update files contain newly released signatures but not executable code.
Reference:Cisco Courseware 17-5
QUESTION 163
Where should the update file be located when updating a Cisco IDS Sensor with IDS MC?
Comentários a estes Manuais