nerdexam
EC-Council

EC0-350 · Question #110

Study the snort rule given below and interpret the rule. alert tcp any any --> 192.168.1.0/24 111 (content:"|00 01 86 a5|"; msG. "mountd access";)

The correct answer is D. An alert is generated when a TCP packet originating from any IP address is seen on the network and. See the full explanation below for the reasoning.

Question

Study the snort rule given below and interpret the rule. alert tcp any any --> 192.168.1.0/24 111 (content:"|00 01 86 a5|"; msG. "mountd access";)

Options

  • AAn alert is generated when a TCP packet is generated from any IP on the 192.168.1.0 subnet and
  • BAn alert is generated when any packet other than a TCP packet is seen on the network and destined
  • CAn alert is generated when a TCP packet is originated from port 111 of any IP address to the
  • DAn alert is generated when a TCP packet originating from any IP address is seen on the network and

How the community answered

(63 responses)
  • A
    13% (8)
  • B
    3% (2)
  • C
    6% (4)
  • D
    78% (49)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice