200-201 · Question #509
Refer to the exhibit. An engineer must map these events to the source technology that generated the event logs. To which technology do the generated logs belong?
The correct answer is C. IPS. The logs indicate intrusion detection and prevention events, such as: - "Intrusion TCP.Split.Handshake blocked" - "Intrusion Snort.TCP.SACK.Option.DoS blocked" - "Default-Malicious-Code-Detection-By-Endpoint" These are signatures typically seen in Intrusion Prevention Systems…
Question
Refer to the exhibit. An engineer must map these events to the source technology that generated the event logs. To which technology do the generated logs belong?
Exhibit
Options
- Aproxy
- Bantivirus
- CIPS
- Dfirewall
How the community answered
(61 responses)- A3% (2)
- B5% (3)
- C82% (50)
- D10% (6)
Explanation
The logs indicate intrusion detection and prevention events, such as: - "Intrusion TCP.Split.Handshake blocked" - "Intrusion Snort.TCP.SACK.Option.DoS blocked" - "Default-Malicious-Code-Detection-By-Endpoint" These are signatures typically seen in Intrusion Prevention Systems (IPS), which are designed to detect and mitigate attacks like TCP handshake manipulation and DoS attacks. The mention of Snort, a well-known open-source IPS, further confirms that these logs originate from an IPS system rather than a firewall, antivirus, or proxy.
Topics
Community Discussion
No community discussion yet for this question.
