Free 500-285 sample questions
Real questions from the Securing Cisco Networks with Sourcefire Intrusion Prevention System practice bank, with the correct answer and an explanation for each one. No junk, no filler.
Try them in the simulator Same questions, with study, timed and flashcard modes.
Showing 8 of 17 free sample questions.
Which option is true regarding the $HOME_NET variable? A.is a policy-level variableB.has a default value of "all"C.defines the network the active policy protectsD.is used by all rules to define the internal network
Which option is one of the three methods of updating the IP addresses in Sourcefire Security Intelligence? A.subscribe to a URL intelligence feedB.subscribe to a VRTC.upload a list that you createD.automatically upload lists from a network share
Which statement is true in regard to the Sourcefire Security Intelligence lists? A.The global blacklist universally allows all traffic through the managed device.B.The global whitelist cannot be edited.C.IP addresses can be added to the global blacklist by clicking on interactive graphs in Context Explorer.D.The Security Intelligence lists cannot be updated.
A security architect is designing a variable set for a multi-tenant environment using FireSIGHT Management Center. Tenant A uses the 10.1.0.0/16 subnet, and Tenant B uses 10.2.0.0/16. Both tenants share the same Intrusion Policy but require distinct protection scopes. How should the architect configure the $HOME_NET variable to ensure the Intrusion Policy correctly identifies the protected network for each tenant's specific traffic flow when applied via Access Control Rules?
An administrator observes that a critical business application using a proprietary TCP protocol on port 8888 is being dropped by the default 'Balanced Security and Connectivity' intrusion policy. The drops are triggered by a preprocessor anomaly. What is the most efficient method to allow this traffic without disabling the preprocessor globally?
While analyzing the Context Explorer, an analyst notices that the operating system information for several critical servers is listed as 'Unknown' or incorrect. This inaccuracy is affecting the FireSIGHT recommended rules generation. Which feature must be tuned to improve the accuracy of this passive discovery?
Which of the following Snort 2.9 rule headers is valid for alerting on traffic originating from the external network destined for the HTTP servers defined in the variable set? (Select TWO)
9 more free samples are waiting
Create a free account to unlock the whole 500-285 sample bank, or get full access to all 257 practice questions in the simulator.