A NIPS administrator needs to install a new signature to observe the behavior of a worm that may be spreading over SMB. Which of the following signatures should be installed on the NIPS?
I believe C is correct.
The signature is for a Network Intrusion PREVENTION System (NIPS), not a Network Intrusion Detection System (NIDS), therefore, the action that needs to be taken here should be prevention (i.e. DENY/DROP). Since the DROP signature (B) gives the wrong source port (from ANY:445), that makes C be the only reasonable answer.
By the way, I have written some Snort signatures to detect malicious traffic. If we just want to observe/detect the malicious traffic, the signature could be written as something like ALERT from ANY:ANY to ANY:445 ... Not PERMIT...
that may be spreading over SMB. — Suspect is worm dealing some action to the SMB. Confirm or deny this with a command. And then record results????? Sounds like word f--kery from TIA as ususal............
This section is not available anymore. Please use the main Exam Page.SY0-501 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
monkeyyyyy
3 years, 11 months agomonkeyyyyy
3 years, 11 months agosuccessforsure
3 years, 11 months agoTexrax
4 years agosuje
3 years, 11 months agoJacked69
4 years agomadaraamaterasu
4 years agoHeymannicerouter
4 years ago