nerdexam
IBM

C1000-163 · Question #39

A security analyst uses Use Case Manager > Active Rules and detects which TOP rule- generating offenses are triggered due to inbound traffic that is dropped by the firewall. The company decides that…

The correct answer is B. Open Rule Wizard add a test condition > and when an event matches any of the following. See the full explanation below for the reasoning.

Question

A security analyst uses Use Case Manager > Active Rules and detects which TOP rule- generating offenses are triggered due to inbound traffic that is dropped by the firewall. The company decides that the rule should only trigger only when there are firewall permit events. Which of these does the analyst implement to meet the above requirement?

Options

  • AOpen Rule Wizard add a test condition > and when the context is Local to Local, Local to Remote
  • BOpen Rule Wizard add a test condition > and when an event matches any of the following
  • COpen Rule Wizard add a test condition > and NOT when an event matches any of the following
  • DOpen Rule Wizard add a test condition > and when the event category for the event is one of the

How the community answered

(58 responses)
  • A
    14% (8)
  • B
    76% (44)
  • C
    7% (4)
  • D
    3% (2)

Community Discussion

No community discussion yet for this question.

Full C1000-163 Practice