Cisco
350-201 · Question #84
Refer to the exhibit. IDS is producing an increased amount of false positive events about brute force attempts on the organization's mail server. How should the Snort rule be modified to improve…
The correct answer is C. Set the rule to track the source IP. Step 1 Identify Potential Locations for Sensors - To properly tune IDS sensors, the first step is to identify network locations where the sensors can be placed for maximum efficiency.
Network Intrusion Analysis
Question
Refer to the exhibit. IDS is producing an increased amount of false positive events about brute force attempts on the organization's mail server. How should the Snort rule be modified to improve performance?
Exhibit
Options
- ABlock list of internal IPs from the rule
- BChange the rule content match to case sensitive
- CSet the rule to track the source IP
- DTune the count and seconds threshold of the rule
How the community answered
(32 responses)- A6% (2)
- B3% (1)
- C81% (26)
- D9% (3)
Explanation
Step 1 Identify Potential Locations for Sensors - To properly tune IDS sensors, the first step is to identify network locations where the sensors can be placed for maximum efficiency.
Topics
#Snort rules#IDS tuning#false positives#threshold configuration
Community Discussion
No community discussion yet for this question.
