How is the basic construct of a port variable formatted in the Snort.conf file?
Answer : C
Which action should you perform to enable or disable entire classes of rules through the snort.conf file?
Answer : B
Which statement about the detection engine configuration settings in snort.conf is true?
Answer : B
What is the minimum action that you should take when configuring a new Snort installation?
Answer : D
Which syntax correctly expresses a port variable?
Answer : A
Which statement about the FTPTelnet preprocessor is true?
Answer : B
Which preprocessor can normalize the IIS %u encoding scheme?
Answer : C
When Snort receives packets, in which order are they placed into the preprocessors?
Answer : C
Which configuration is optimal for the frag3 engine?
Answer : A
Which preprocessor maintains connection state so that attacks that manifest over multiple packets in a session can be detected?
Answer : A
Which preprocessor uses a global directive and an engine instance directive in the snort.conf file for configuration to provide target context during packet reassembly?
Answer : B
What is a GID?
Answer : B
Which preprocessor provides a means to measure Snort performance?
Answer : C
Which preprocessor plays a role in detecting the reconnaissance phase of an attack?
Answer : A
A Snort sensor is generating many false-positive sfPortscan alerts, in which busy, trusted hosts are flagged as the source of port sweep events. Which tuning strategy can mitigate this problem?
Answer : A
Have any questions or issues ? Please dont hesitate to contact us