
642 -531
Leading the way in IT testing and certification tools, www.testking.com
- 92 -
E. String.UDP
Answer: E (or D)
Note: I am not sure why the original person who answered this question picked tcp but I think
that most email is delivered via tcp. However he/she is correct in that it is a string signature.
Off hand I have a slight doubt if most email is delivered via UDP or TCP. If you think that
most email is UDP pick E if you don’t then stay with the given answer.
ICMP is wrong.
Atomic is one packet and wrong.
The course manual does not give examples of String signatures.
Cisco Secure Intrusion Detection System 4 chap 13 page 41
Section 3: Explain the global Cisco IDS signature parameters (4
questions)
QUESTION NO: 1
Which of the following statements represents the most suitable description of a required
signature parameter attribute?
A. The signature parameter value cannot be modified for custom signatures.
B. The default signature parameter value cannot be changed.
C. The signature parameter must be defined for all signatures.
D. The signature parameter value can be defined for custom signatures only.
Answer: C
Explanation:
If a parameter is required, you must define it for all signatures—both default signatures and
custom signatures.
Reference:
Installing and Using the Cisco Intrusion Detection System Device Manager and Event
Viewer Version 4.0
Cisco Courseware 13-16
QUESTION NO: 2
Which of the following statements represents the best description of a protected
signature parameter attribute?
A. The signature parameter value cannot be modified for custom signatures.
B. The signature parameter value must be defined for all signatures.
C. The default signature parameter value cannot be changed.
D. The signature parameter value can be modified for custom signatures only.
Comentarios a estos manuales