300-710 · Question #328
An engineer is configuring a Cisco Secure Firewall Threat Defense device and wants to create a new intrusion rule based on the detection of a specific pattern in the data payload for a new zero- day e
The correct answer is B. metadata. In Snort-based intrusion rules (used by Cisco Secure Firewall), the 'metadata' keyword is used to embed informational fields about the rule itself, such as the author name, creation date, last modified date, and affected services. This is purely descriptive and does not affect de
Question
An engineer is configuring a Cisco Secure Firewall Threat Defense device and wants to create a new intrusion rule based on the detection of a specific pattern in the data payload for a new zero- day exploit. Which keyword type must be used to add a line that identifies the author of the rule and the date it was created?
Options
- Agtp_info
- Bmetadata
- Creference
- Dcontent
How the community answered
(55 responses)- A7% (4)
- B87% (48)
- C4% (2)
- D2% (1)
Explanation
In Snort-based intrusion rules (used by Cisco Secure Firewall), the 'metadata' keyword is used to embed informational fields about the rule itself, such as the author name, creation date, last modified date, and affected services. This is purely descriptive and does not affect detection logic. The 'content' keyword (D) defines byte patterns to match in the payload. The 'reference' keyword (C) links to external vulnerability databases like CVE or Bugtraq. The 'gtp_info' keyword (A) is used for matching specific fields within GTP (GPRS Tunneling Protocol) packets and is unrelated to rule authorship metadata.
Topics
Community Discussion
No community discussion yet for this question.