PrepAway - Latest Free Exam Questions & Answers

Category: 642-532

Exam 642-532: Securing Networks Using Intrusion Prevention Systems

How could this be done?

By manipulating the TTL on a TCP packet, an attacker could desynchronize inspection. Signature
1308 (TTL evasion) fires when the TTL for any packet in a TCP session is higher than the lowestobserved TTL for that session. Signature 1308 rewrites all TTLs to the lowest-observed TTL, and
produces an alert. You would like to have the signature continue to modify packets inline but avoid
generating alerts.
How could this be done?


Page 4 of 7« First...23456...Last »