
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 115 -
Enter or delete the IP addresses of hosts and networks that can access the sensor via Telnet,
FTP, SSH, and scp.
Reference: Cisco Intrusion Detection System Sensor Getting Started Version 3.1
Note by 2
nd
TestKing writer: I think the answers don’t conform to the latest course manual.
Telnet – requires an IP address that has been assigned to the command and control interface
via the CLI setup command. Must be enabled to allow telnet access. Telnet is DISABLED
by default.
SSH – Requires an IP address that has been assigned to the command and control interface via
the CLI setup command and uses a supported SSH client. The SSH server in the sensor is
ENABLED by default.
HTTPS – Requires an IP address that has been assigned to the command and control interface
via the CLI setup command and uses a supported web browser. HTTPS is ENABLED by
default but can be disabled.
Cisco Secure Intrusion Detection System 4 chap 7 page 23
QUESTION NO: 6
What Cisco IDS Sensor secure shell operation enables a network security administrator
to remove hosts from the list of those previously connected to devices?
A. Generate new Sensor SSH keys.
B. Generate new Director SSH keys.
C. Manage the Sensor’s known hosts file.
D. Manage the Director’s known hosts file.
Answer: C
Explanation: Access to the probe is determined by a ACL but note in chap 12 the MC deals
with SSH key generation.
Sensor#config t
Sensor#(Config)#service host
Sensor#(config-host)networkParams
Sensor#(config-host-net) accesslist ip address 10.0.2.0 netmask 255.255.255.0 ----adds an
entire network to the access list
Cisco Secure Intrusion Detection System 4 chap 9 page 31
QUESTION NO: 7
Which Cisco IDS service must be running if a Sensor is capturing network traffic?
A. Managed
B. Captured
C. Snifferd
D. Packetd
E. Trafficd
Answer: D
Comentarios a estos manuales