nerdexam
GIAC

GSEC · Question #350

Use sudo to launch Snort with the, /etc /snort /snort.conf file In full mode to generate alerts based on incoming traffic to echo. What is the source IP address of the traffic triggering an alert with

Sign in or unlock GSEC to reveal the answer and full explanation for question #350. The question stem and answer options stay visible for context.

Network Security

Question

Use sudo to launch Snort with the, /etc /snort /snort.conf file In full mode to generate alerts based on incoming traffic to echo. What is the source IP address of the traffic triggering an alert with a destination port of 156? Note: Snort Is configured to exit after It evaluates 50 packets.

Exhibit

GSEC question #350 exhibit

Options

  • A192.168.^.30
  • B10.72.101.210
  • C10.10.28.19
  • D10.11.10.11
  • E10.10.10.66
  • F192.168.87.68
  • G10.12.10.112
  • H10.11.12.13
  • I10.10.201.150
  • J10.10.199.146

Unlock GSEC to see the answer

You've previewed enough free GSEC questions. Unlock GSEC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Snort#IDS#intrusion detection#network alerts
Full GSEC Practice