PrepAway - Latest Free Exam Questions & Answers

Which of the following Snort rules will log any tcp traffic from any IP address to any port between 1 and 1024

You are configuring your new IDS machine, where you have recently installed Snort. While you
are working with this machine, you wish to create some basic rules to test the ability to log traffic
as you desire.
Which of the following Snort rules will log any tcp traffic from any IP address to any port between 1
and 1024 on any host in the 10.0.10.0/24 network?

PrepAway - Latest Free Exam Questions & Answers

A.
log tcp 0.0.0.0/24 -> 10.0.10.0/24 1<>1024

B.
log tcp any any -> 10.0.10.0/24 1<>1024

C.
log tcp any any -> 10.0.10.0/24 1:1024

D.
log tcp 0.0.0.0/24 -> 10.0.10.0/24 1:1024

E.
log udp any any -> 10.0.10.0/24 1:1024


Leave a Reply