300-215 · Question #40
Snort detects traffic that is targeting vulnerabilities in files that belong to software in the Microsoft Office suite. On a SIEM tool, the SOC analyst sees an alert from Cisco FMC. Cisco FMC is…
The correct answer is A. FILE-OFFICE Microsoft Graphics buffer overflow. Snort’s FILE-OFFICE rules flag malformed Office file structures - particularly graphics-parsing overflows - using messages like “FILE-OFFICE Microsoft Graphics buffer overflow” when exploit traffic is seen.
Question
Snort detects traffic that is targeting vulnerabilities in files that belong to software in the Microsoft Office suite. On a SIEM tool, the SOC analyst sees an alert from Cisco FMC. Cisco FMC is implemented with Snort IDs. Which alert message is shown?
Options
- AFILE-OFFICE Microsoft Graphics buffer overflow
- BFILE-OFFICE Microsoft Graphics cross site scripting (XSS)
- CFILE-OFFICE Microsoft Graphics SQL INJECTION
- DFILE-OFFICE Microsoft Graphics remote code execution attempt
How the community answered
(34 responses)- A91% (31)
- B3% (1)
- C6% (2)
Explanation
Snort’s FILE-OFFICE rules flag malformed Office file structures - particularly graphics-parsing overflows - using messages like “FILE-OFFICE Microsoft Graphics buffer overflow” when exploit traffic is seen.
Topics
Community Discussion
No community discussion yet for this question.