Cisco IDS-4230-FE - Intrusion Detection Sys Fast Ethernet Sensor Arkusz Danych Strona 84

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 168
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 83
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 84 -
Topic 7, Describe the Cisco IDS signatures
and determine the immediate threat posed
to the network (23 questions)
Section 1: Explain the Cisco IDS signature features (7 questions)
QUESTION NO: 1
The new TestKing trainee technician wants to know which signature description best
describes a string signature engine. What would your reply be?
A. Layer 5, 6, and 7 services that require protocol analysis.
B. Regular expression-based pattern inspection for multiple transport protocols.
C. Network reconnaissance detection.
D. State-based, regular expression-based, pattern inspection and alarm functionality for
TCP streams.
Answer: B
Explanation:
About STRING Engines
The STRING engine provides regular expression-based pattern inspection and alarm
functionality for multiple transport protocols including TCP, UDP and ICMP.
Regular expressions are a powerful and flexible notational language that allow you to describe
text. In the context of pattern matching, regular expressions allow a succinct description of
any arbitrary pattern. Regular expressions are compiled into a data structure called a pattern
matcher, which is then used to match patterns in data.
The STRING engine is a generic string-based pattern matching inspection engine for TCP,
UDP, and ICMP protocols. This STRING engine uses a new Regex engine that can combine
multiple patterns into a single pattern-matching table allowing for a single search through the
data. The new regex has the alternation "|" operator also known as the OR operator. There are
three STRING engines: STRING.TCP, STRING.UDP, and STRING.ICMP.
Reference:
Cisco Courseware 13-61
QUESTION NO: 2
Which of the following statements regarding SERVICE engine signatures on a Cisco
IDS Sensor is valid?
A SERVICE engine signatures on a Cisco IDS Sensor include all general signatures
B SERVICE engine signatures on a Cisco IDS Sensor are operating system independent
C SERVICE engine signatures on a Cisco IDS Sensor include signatures based on network
attacks.
D SERVICE engine signatures on a Cisco IDS Sensor are categorized and tuned by
operating system
Przeglądanie stron 83
1 2 ... 79 80 81 82 83 84 85 86 87 88 89 ... 167 168

Komentarze do niniejszej Instrukcji

Brak uwag