
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 109 -
QUESTION NO: 5
The new TestKing trainee technician wants to know what types of requests can be made
with a client initiated RDEP event request. What would your reply be? (Choose all that
apply.)
A. IP log
B. subscriptions
C. transaction log
D. queries
E. configuration
Answer: B, D
Page 123 Cisco Press CCSP CSIDS 2nd edition under Remote Data Exchange Protocol
The client can issue one of the following two types of event requests:
- Queries (used to retrieve events from the sensor based on a specified query)
- Subscriptions (enable a client to establish a live event feed with the sensor based on specific
query criteria)
QUESTION NO: 6
Which two classes of request and response messages are defined by RDEP? (Choose
two.)
A. Event messages
B. Syslog messages
C. IP Log messages
D. PostOffice messages
E. CnC messages
ANSWER: A, C
Explanation:
RDEP defines the following classes of request and response messages:
1) Event messages – Include IDS alarm, status, and error messages. Monitoring
applications such as IEV and the Security Monitor use RDEP’s event pull model to
retrieve events from the Sensor. The pull model allows the application to pull alarms
at its own pace. As soon as the monitoring application connects to the Sensor and
requests alarms, the alarms are returned to the monitoring application console without
delay. Alarms remain on the Sensor until a 4-GB limit is reached and they are
overwritten by new alarms. Since a large number of alarms can be stored on the
Sensor itself, the management application can pull alarms after being disconnected for
a long period of time without losing alarms.
2) IP log messages – Used by clients to retrieve IP log data from Sensors.
Cisco Courseware 6-7
Komentarze do niniejszej Instrukcji