Cisco IDS/IPS Fundamentals Flashcards

1
Q

Which method should you implement when it is not acceptable for an attack to reach its intended victim?

A

IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A company has hired you to determine whether attacks are happening against the server farm, and it does not want any additional delay added to the network. Which deployment method should be used?

A

IDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why does IPS have the ability to prevent an ICMP-based attack from reaching the intended victim?

A

The IPS is inline with the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which method of IPS uses a baseline of normal network behavior and looks for deviations from that baseline?

A

Anomaly-based IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which type of implementation required custom signatures to be created by the administrator?

A

Policy-based IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which method requires participation in global correlation involving groups outside your own enterprise?

A

Reputation-based IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which if the micro-engines contains signatures that can only match on a single packet, as opposed to a flow of packets?

A

Atomic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which properties directly associated with a signature?

A

ASR, SFR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Is assigning aggressive IPS responses to specific signatures best practices?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the name of Cisco cloud-based services for IPS correlation?

A

SIO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Name three Next-Generation IPS (NGIPS) solution?

A

NGIPSv, ASA with FirePOWER, FirePOWER 8000 series appliances

How well did you know this?
1
Not at all
2
3
4
5
Perfectly