PrepAway - Latest Free Exam Questions & Answers

Category: 642-533

Exam 642-533: IPS – Implementing Cisco Intrusion Prevention Systems

How could this be done?

By manipulating the TTL on a TCP packet, an attacker could desynchronize inspection. Signature 1308 (TTL evasicn) fires when the TTL for any packet in a TCP session is higher than the lowest- observed TTL for that session. Signature 1308 rewrites all TTLs to the lowest-observed TTL, and produces an alert. You would like to have the signature continue to modify packets inline but avoid generating alerts.

How could this be done?


Page 3 of 1312345...10...Last »