
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 90 -
Answer: C
Explanation:
SERVICE.* Engines
Use the SERVICE engines to create signatures that deal with the Layer 5+ protocol of the
service. The DNS (TCP and UDP) engines support analysis of compressed messages and can
fire alarms on request/reply conditions and overflows. The RPC and PORTMAP engines are
fine tuned for RPC and Portmapper requests. Batch and fragmented messages are decoded and
analyzed.
Reference:
Cisco Courseware 13-41
QUESTION NO: 5
Which of the following signature engines would be the most appropriate to create a
custom signature that would inspect data at Layer 5 and above?
A STRING
B SWEEP
C ATOMIC
D SERVICE
Answer: D
Page 437 Cisco Press CCSP CSIDS 2nd edition under Cisco IDS Signature Engines
See: Table 13-6 Signature Engine Categories
Service: Used when services at OSI Layers 5, 6 and 7 require protocol analysis
Cisco Courseware 13-41
QUESTION NO: 6
When creating custom signatures using the TROJAN engines, which parameter values
are required?
A. protocol
B. source/destination IP addresses
C. regular expression strings
D. these signatures cannot be created
ANSWER: D
You cannot create custom signatures with Trojan engies.
Cisco Courseware 13-73
QUESTION NO: 7
Comentarios a estos manuales