C2150-606 · Question #41
The quard_tap.ini of a UNIX S-TAP is configured with the following parameters: firewall_installed=1 firewall_fail_close=0 firewall_default_state=0 firewall_timeout=10 A Guardium administrator…
The correct answer is A. Rule 1 - S-GATE Attach. S-GATE ATTACH: sets S-GATE mode to "Attached" for a specific session. Intended for use when a certain criteria is met that raises the need to closely watch (and if needed block) the traffic on that session. S-GATE DETACH: sets S-GATE mode to "Detached" for a specific session…
Question
The quard_tap.ini of a UNIX S-TAP is configured with the following parameters:
firewall_installed=1 firewall_fail_close=0 firewall_default_state=0 firewall_timeout=10 A Guardium administrator applies a policy to the Collector with two rules as below. The actions of the rules have been hidden. The administrator must create a policy that will terminate the session on the delete statement in the below scenario:
A session is started to the monitored database from client IP 9.9.8.7. In the session the user plans to perform a select statement and then a delete statement. What actions should the administrator configure?
Exhibits
Options
- ARule 1 - S-GATE Attach
- BRule 1 - S-GATE Detach
- CRule 1 - S-GATE Attach
- DRule 1 - S-TAP Terminate
How the community answered
(62 responses)- A77% (48)
- B6% (4)
- C13% (8)
- D3% (2)
Explanation
- S-GATE ATTACH: sets S-GATE mode to "Attached" for a specific session. Intended for use when a certain criteria is met that raises the need to closely watch (and if needed block) the traffic on that session. * S-GATE DETACH: sets S-GATE mode to "Detached" for a specific session. Intended for use on sessions that are considered as "safe" or sessions that cannot tolerate any * S-GATE TERMINATE: Has effect only when the session is attached. It drops the reply of the firewalled request, which will terminate the session on some databases. The S-GATE TERMINATE policy rule will cause a previously watched session to terminate. 01.ibm.com/support/knowledgecenter/SSMPHH_9.5.0/com.ibm.guardium95.doc/protect/topics/rul
Topics
Community Discussion
No community discussion yet for this question.

