
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 75 -
The blocking device must have one of the following configured:
1) Telnet enabled - Telnet access should be allowed from the sensor
2) Secure shell (SSH) enabled - SSH access should be allowed from the sensor
QUESTION NO: 6
Which Sensor process is responsible for initialing shuns on a blocking device?
A. exec
B. NAC
C. blockd
D. shunStart
E. ACL Daemon
ANSWER: B
Explanation:
Network Access Controller (NAC) is used to initiate Sensor shunning on network devices.
Reference: page 120 of Ciscopress CCSP self study: CSIDS 2nd edition.
Cisco Courseware 6-4
QUESTION NO: 7
When designing IP blocking, why should you consider entry points?
A. They provide different avenues for the attacker to attack your networks.
B. They prevent all denial of service attacks.
C. They are considered critical hosts and should not be blocked.
D. They provide a method for the Sensor to route through the subnet to the managed
router.
Answer: A
Explanation:
Today’s networks have several entry points to provide reliability, redundancy, and resilience.
These entry points also represent different avenues for the attacker to attack your network.
You must identify all the entry points into your network and decide whether they need to also
participate in IP blocking.
Reference: Cisco Secure Intrusion Detection System (Ciscopress) page 467
Cisco Secure Intrusion Detection System 4 chap 15 page 8
Note: It is recommended that Sensors be placed at those network entry and exit points that
provide sufficient intrusion detection coverage. Cisco Secure Intrusion Detection System 4
chap 4 page 37
Comentarios a estos manuales