PrepAway - Latest Free Exam Questions & Answers

What is the effect of this rule?

You are configuring your new IDS machine, and are creating new rules. You enter the following
rule:
Alert tcp any any -> 10.0.10.0/24 any (msg: “SYN-FIN scan detected”; flags: SF;)
What is the effect of this rule?

PrepAway - Latest Free Exam Questions & Answers

A.
This is an alert rule, designed to notify you of SYN-FIN scans of the network in one direction.

B.
This is an alert rule, designed to notify you of SYN-FIN scans of the network in either direction.

C.
This is a logging rule, designed to capture SYN-FIN scans.

D.
This is a logging rule, designed to notify you of SYN-FIN scans.

E.
This is an alert rule, designed to notify you of SYN-FIN scans originating from the 10.0.10.0/24
network.


Leave a Reply