
642-531
Page 14-7 CSIDS Courseware under Signature Actions
You can configure signatures to cause the Sensor to take action when the signature is triggered by the
following:
1) IP Log
2) TCP Reset
3) Block - Block Host
- Block Connection
Cisco Courseware 13-10
Cisco Courseware 14-7
Cisco Courseware 14-12 (Screenshot)
QUESTION 110
What information can a network security administrator specify in a Cisco IDS exclude signature filter? (Choose
two)
A. Signature name
B. Signature ID
C. Signature action
D. Signature severity level
E. Sub-signature ID
F. Source port
Answer: B, E
Explanation:
When defining a simple filter, you need to configure the following fields:
* Signature
* Subsignature
* IP address
* Network Mask
* Address Role
Reference:Cisco Secure Intrusion Detection System (Ciscopress) page 446
QUESTION 111
What information can a network security administrator specify in a Cisco IDS signature filter? (Choose three)
A. Source port
B. Source address
C. Destination address
D. Destination port
E. Signature ID
Answer: B, C, E
Explanation: A filter is defined by specifying the signature, the source address, and the destination address and
Commenti su questo manuale