SY0-501 · Question #14
A security analyst is reviewing the following output from an IPS: Given this output, which of the following can be concluded? (Select TWO).
The correct answer is B. The source IP of the attack is coming from 250 19.18.71. C. The attacker sent a malformed IGAP packet, triggering the alert. The IPS output reveals that the attack originated from the IP address 250.19.18.71 and involved a malformed IGAP packet, which triggered the security alert.
Question
A security analyst is reviewing the following output from an IPS:
Given this output, which of the following can be concluded? (Select TWO).
Exhibit
Options
- AThe source IP of the attack is coming from 250.19 18.22.
- BThe source IP of the attack is coming from 250 19.18.71.
- CThe attacker sent a malformed IGAP packet, triggering the alert.
- DThe attacker sent a malformed TCP packet, triggering the alert.
- EThe TTL value is outside of the expected range, triggering the alert.
How the community answered
(27 responses)- A4% (1)
- B81% (22)
- D11% (3)
- E4% (1)
Why each option
The IPS output reveals that the attack originated from the IP address 250.19.18.71 and involved a malformed IGAP packet, which triggered the security alert.
The IPS output would show 250.19.18.71, not 250.19.18.22, as the source IP address of the attack.
The IPS alert details would explicitly list 'Source IP: 250.19.18.71', directly identifying this address as the originator of the detected malicious network traffic.
The IPS output would clearly indicate a 'Protocol: IGAP' and a 'Malformed Packet' signature or description, specifying that the alert was triggered by an improperly formatted IGAP packet.
The IPS alert specifies IGAP as the affected protocol; therefore, the attacker did not send a malformed TCP packet in this particular instance.
The IPS alert describes a 'malformed IGAP packet' as the trigger, not an unexpected TTL value, which is a distinct type of network anomaly.
Concept tested: Analyzing network intrusion logs for attack details
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa93/configuration/firewall/asa-93-firewall-config/monitor-log.html
Topics
Community Discussion
No community discussion yet for this question.
