Signature and Alarm Management Review Questions and Answers
|
1. |
What is a subsignature ID?
-
The signature ID
-
The signature ID combined with the host ID
-
The signature ID combined with the organization ID
-
The ID of the subsignature associated with the CIDS signature |
|
2. |
What is the NSDB?
-
The network security database that contains all CIDS signatures
-
The network security database that contains all 1000, 2000, 3000, 4000, and 5000 series signatures
-
The network security database that contains descriptions of all CIDS signatures and vulnerabilities
-
The network security database located on the sensor and used to define the configured signatures |
|
3. |
Which of the following accurately lists all the possible alarm levels?
-
1, 2, 3, 4, 5
-
Low, Medium, High
-
1, 3, 5
-
Low, Medium, High, Critical |
|
4. |
Which of the following accurately lists all the possible severity levels?
-
1, 2, 3, 4, 5
-
Low, Medium, High
-
1, 3, 5
-
Low, Medium, High, Critical |
|
5. |
Which of the following categories describes the amount of packets a signature must analyze to make a match? (Choose two.)
-
Composite
-
Context
-
Atomic
-
Content |
|
6. |
Which of the following is an example of a signature class?
-
Denial of service class
-
General signature class
-
String signature class
-
Access control lists |
|
7. |
Which of the following signatures have an associated subsignature? (Choose two.)
-
General signatures
-
String signatures
-
Access control lists
-
Reconnaissance class |
|
8. |
Which of the following is an example of a signature implementation?
-
Composite
-
Atomic
-
Context
-
Access class |
|
9. |
Which of the following signature series is responsible for analyzing the IP protocol?
-
2000 series
-
1000 series
-
4000 series
-
9000 series |
|
10. |
Which of the following is not a valid CIDS signature series?
-
2000 series
-
5000 series
-
7000 series
-
10000 series |
Answers
|
1. |
D. The ID of the subsignature associated with the CIDS signature |
|
2. |
C. The network security database that contains descriptions of all CIDS signatures and vulnerabilities |
|
3. |
A. 1, 2, 3, 4, 5 |
|
4. |
B. Low, Medium, High |
|
5. |
A. and C. Composite and Atomic |
|
6. |
A. Denial of service class |
|
7. |
B. and C. String signatures and access control lists |
|
8. |
C. Context |
|
9. |
B. 1000 series |
|
10. |
C. 7000 series cp27
|
1737 times read
|
|
|
Did you enjoy this article?
(total 0 votes)
|