Pass4itsure > Cisco > Proctored Exams > 500-285 > 500-285 Online Practice Questions and Answers

500-285 Online Practice Questions and Answers

Questions 4

Which option is true of the Packet Information portion of the Packet View screen?

A. provides a table view of events

B. allows you to download a PCAP formatted file of the session that triggered the event

C. displays packet data in a format based on TCP/IP layers

D. shows you the user that triggered the event

Buy Now
Questions 5

FireSIGHT uses three primary types of detection to understand the environment in which it is deployed. Which option is one of the detection types?

A. protocol layer

B. application

C. objects

D. devices

Buy Now
Questions 6

The collection of health modules and their settings is known as which option?

A. appliance policy

B. system policy

C. correlation policy

D. health policy

Buy Now
Questions 7

Context Explorer can be accessed by a subset of user roles. Which predefined user role is not valid for FireSIGHT event access?

A. Administrator

B. Intrusion Administrator

C. Security Analyst

D. Security Analyst (Read-Only)

Buy Now
Questions 8

Context Explorer can be accessed by a subset of user roles. Which predefined user role is valid for FireSIGHT event access?

A. Administrator

B. Intrusion Administrator

C. Maintenance User

D. Database Administrator

Buy Now
Questions 9

When configuring an LDAP authentication object, which server type is available?

A. Microsoft Active Directory

B. Yahoo

C. Oracle

D. SMTP

Buy Now
Questions 10

Alert priority is established in which way?

A. event classification

B. priority.conf file

C. host criticality selection

D. through Context Explorer

Buy Now
Questions 11

Which mechanism should be used to write an IPS rule that focuses on the client or server side of a TCP communication?

A. the directional operator in the rule header

B. the "flow" rule option

C. specification of the source and destination ports in the rule header

D. The detection engine evaluates all sides of a TCP communication regardless of the rule options.

Buy Now
Questions 12

Which option is a valid whitelist evaluation value?

A. pending

B. violation

C. semi-compliant

D. not-evaluated

Buy Now
Questions 13

Suppose an administrator is configuring an IPS policy and attempts to enable intrusion rules that require the operation of the TCP stream preprocessor, but the TCP stream preprocessor is turned off. Which statement is true in this situation?

A. The administrator can save the IPS policy with the TCP stream preprocessor turned off, but the rules requiring its operation will not function properly.

B. When the administrator enables the rules and then attempts to save the IPS policy, the administrator will be prompted to accept that the TCP stream preprocessor will be turned on for the IPS policy.

C. The administrator will be prevented from changing the rule state of the rules that require the TCP stream preprocessor until the TCP stream preprocessor is enabled.

D. When the administrator enables the rules and then attempts to save the IPS policy, the administrator will be prompted to accept that the rules that require the TCP stream preprocessor will be turned off for the IPS policy.

Buy Now
Exam Code: 500-285
Exam Name: Securing Cisco Networks with FireSIGHT Intrusion Prevention System (SSFIPS)
Last Update: Apr 21, 2024
Questions: 60
10%OFF Coupon Code: SAVE10

PDF (Q&A)

$45.99

VCE

$49.99

PDF + VCE

$59.99