nerdexam
Huawei

H12-725_V4.0 · Question #85

Which of the following does the filter condition of the IPS device signature filter not include?

The correct answer is A. Source of attack. Source of attack is not a filter condition in an IPS device signature filter because IPS signatures are designed to classify and match traffic patterns - they filter based on characteristics inherent to the signature itself, such as what is targeted, what type of threat it…

Intrusion Prevention System (IPS) and Anti-DDoS

Question

Which of the following does the filter condition of the IPS device signature filter not include?

Options

  • ASource of attack
  • BObject
  • CThreat categories
  • DAgreement

How the community answered

(44 responses)
  • A
    77% (34)
  • B
    5% (2)
  • C
    2% (1)
  • D
    16% (7)

Explanation

Source of attack is not a filter condition in an IPS device signature filter because IPS signatures are designed to classify and match traffic patterns - they filter based on characteristics inherent to the signature itself, such as what is targeted, what type of threat it represents, and which protocol is involved. The origin or source of an attack is an event/log attribute captured after detection, not a pre-classification filter criterion used to organize signatures.

Why the distractors are wrong:

  • B (Object) is a valid filter condition - it specifies what the signature targets (e.g., server, client, operating system, or application).
  • C (Threat categories) is a valid filter condition - it classifies signatures by attack type (e.g., exploit, malware, DoS), allowing you to apply policies by category.
  • D (Agreement/Protocol) is a valid filter condition - it filters signatures by the network protocol involved (e.g., HTTP, FTP, DNS), helping scope policies to relevant traffic.

Memory tip: Think of the IPS signature filter as describing the nature of a threat, not its origin. You can filter by what is attacked (Object), how it's classified (Threat category), and which protocol carries it (Agreement) - but the attacker's source IP is dynamic event data, not a static signature property.

Topics

#IPS signature filtering#filter conditions#signature-based detection#network security controls

Community Discussion

No community discussion yet for this question.

Full H12-725_V4.0 Practice