nerdexam
Cisco

300-215 · Question #40

Snort detects traffic that is targeting vulnerabilities in files that belong to software in the Microsoft Office suite. On a SIEM tool, the SOC analyst sees an alert from Cisco FMC. Cisco FMC is…

The correct answer is A. FILE-OFFICE Microsoft Graphics buffer overflow. Snort’s FILE-OFFICE rules flag malformed Office file structures - particularly graphics-parsing overflows - using messages like “FILE-OFFICE Microsoft Graphics buffer overflow” when exploit traffic is seen.

Submitted by miguelv· Mar 6, 2026Incident Response Techniques

Question

Snort detects traffic that is targeting vulnerabilities in files that belong to software in the Microsoft Office suite. On a SIEM tool, the SOC analyst sees an alert from Cisco FMC. Cisco FMC is implemented with Snort IDs. Which alert message is shown?

Options

  • AFILE-OFFICE Microsoft Graphics buffer overflow
  • BFILE-OFFICE Microsoft Graphics cross site scripting (XSS)
  • CFILE-OFFICE Microsoft Graphics SQL INJECTION
  • DFILE-OFFICE Microsoft Graphics remote code execution attempt

How the community answered

(34 responses)
  • A
    91% (31)
  • B
    3% (1)
  • C
    6% (2)

Explanation

Snort’s FILE-OFFICE rules flag malformed Office file structures - particularly graphics-parsing overflows - using messages like “FILE-OFFICE Microsoft Graphics buffer overflow” when exploit traffic is seen.

Topics

#Snort#SIEM#Cisco FMC#vulnerability detection

Community Discussion

No community discussion yet for this question.

Full 300-215 Practice