Free 350-201 Exam Braindumps (page: 14)

Page 13 of 35

Refer to the exhibit. IDS is producing an increased amount of false positive events about brute force attempts on the organization’s mail server. How should the Snort rule be modified to improve performance?

  1. Block list of internal IPs from the rule
  2. Change the rule content match to case sensitive
  3. Set the rule to track the source IP
  4. Tune the count and seconds threshold of the rule

Answer(s): B



Where do threat intelligence tools search for data to identify potential malicious IP addresses, domain names, and URLs?

  1. customer data
  2. internal database
  3. internal cloud
  4. Internet

Answer(s): D



An engineer wants to review the packet overviews of SNORT alerts. When printing the SNORT alerts, all the packet headers are included, and the file is too large to utilize. Which action is needed to correct this problem?

  1. Modify the alert rule to “output alert_syslog: output log”
  2. Modify the output module rule to “output alert_quick: output filename”
  3. Modify the alert rule to “output alert_syslog: output header”
  4. Modify the output module rule to “output alert_fast: output filename”

Answer(s): A


Reference:

https://snort-org-site.s3.amazonaws.com/production/document_files/files/000/000/249/original/ snort_manual.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAIXACIED2SPMSC7GA%2F20201231%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20201231T141156Z&X-Amz- Expires=172800&X-Amz-SignedHeaders=host&X-Amz-Signature=e122ab6eb1659e13b3bc6bb2451ce693c0298b76c1962c3743924bc5fd83d382



Drag and drop the type of attacks from the left onto the cyber kill chain stages at which the attacks are seen on the right.

Select and Place:

Exhibit A:



Exhibit B:

  1. Please refer to Exhibit B for the answer.

Answer(s): A






Post your Comments and Discuss Cisco® 350-201 exam with other Community members:

350-201 Discussions & Posts