Which Sourcefire event action should you choose if you want to block only malicious traffic from a particular end user?
A. Allow with inspection
B. Allow without inspection
C. Block
D. Trust
E. Monitor
One Comment on “Which Sourcefire event action should you choose if you …”
megatronsays:
“Allow with Inspection allows all traffic except for malicious traffic from a particular end-user. The
other options are too restrictive, too permissive, or don’t exist.”
“Allow with Inspection allows all traffic except for malicious traffic from a particular end-user. The
other options are too restrictive, too permissive, or don’t exist.”
0
0