nerdexam
GIAC

GSLC · Question #326

Which field is NOT defined while creating rules for the Network Honeypot rulebase?

The correct answer is B. Process mode. When configuring Network Honeypot rulebase rules, Process mode is not an available field - the configurable fields are limited to operation mode, response options, and notification options.

Security Operations & Incident Response Leadership

Question

Which field is NOT defined while creating rules for the Network Honeypot rulebase?

Options

  • AResponse options
  • BProcess mode
  • COperation mode
  • DNotification options

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    88% (22)
  • C
    8% (2)

Why each option

When configuring Network Honeypot rulebase rules, Process mode is not an available field - the configurable fields are limited to operation mode, response options, and notification options.

AResponse options

Response options is a valid Network Honeypot rulebase field used to define how the honeypot reacts when it detects interaction.

BProcess modeCorrect

Process mode is not a field defined at the rule level within the Network Honeypot rulebase. The rulebase rule configuration exposes fields such as operation mode, response options, and notification options, while process mode is not among the parameters that administrators configure per rule.

COperation mode

Operation mode is a valid configurable field in the Network Honeypot rulebase that controls the honeypot's behavioral mode.

DNotification options

Notification options is a valid field in the Network Honeypot rulebase that governs alerting and logging behavior when activity is detected.

Concept tested: Network Honeypot rulebase configuration fields

Topics

#honeypot#network security#rulebase configuration#intrusion detection

Community Discussion

No community discussion yet for this question.

Full GSLC Practice