
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 80 -
Answer: B
Explanation:
PIX Firewall
You can configure sensors can to use the PIX Firewall to block hosts. A new API command
on the PIX Firewall has been created, shun [ip], which tells the PIX Firewall which hosts to
block. Existing PIX Firewall ACLs are not altered by device management. You cannot use
preshun or postshun ACLs for the PIX Firewall, instead you must create ACLs directly on the
PIX Firewall.
The PIX Firewall does not support the ShunNet command. Therefore, do not send a ShunNet
to sensors that control PIX Firewalls. Instead, you can manually configure the ACLs on the
PIX Firewall to deny the network that is to be blocked. If the sensor controls other devices in
addition to a PIX Firewall, you can send a ShunNet to the sensor, but you must also manually
configure the PIX Firewall to ensure that the network is blocked by all devices controlled by
the sensor. Be aware that any ShunHost that contains a host address that belongs to the
network specified in the ShunNet command does not cause an update to any of the devices
controlled by the sensor. Device Management does not update the device ACLs if the blocked
host is already covered by a ShunNet.
The PIX Firewall in particular does not attempt to block that host even though it does not
support the ShunNet command.
Reference:
Cisco Courseware B-11
Section 4: Configure a Sensor to perform blocking through a
Master Blocking Sensor (6 questions)
QUESTION NO: 1
Which of the following statements regarding the IDS Sensor communications is valid?
A. RDEP makes use of SSL for secured internal communications.
B. RDEP makes use of SSH for secure external communications.
C. PostOffice protocol makes use of IPSec for secured external communications.
D. IDAPI makes use of HTTPS for secured internal communications.
E. cidCU makes use of SSH for secured external communications.
Answer: A
RDEP uses HTTP and TLS/SSL to securely pass XML documents.
Cisco Courseware 4-35
RDEP mismatches the keyword “internal”, but SSH (B) is definitely incorrect.
As REDP is even used to communicate between Sensors (Blocking Forwarding Sensor to
Blocking Master Sensor), perhaps “internal” matches Cisco’s definition?
Komentarze do niniejszej Instrukcji