Weekend Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

500-285 Exam Dumps - Cisco Additional Online Exams Questions and Answers

Question # 4

Which option describes the two basic components of Sourcefire Snort rules?

Options:

A.

preprocessor configurations to define what to do with packets before the detection engine sees them, and detection engine configurations to define exactly how alerting is to take place

B.

a rule statement characterized by the message you configure to appear in the alert, and the rule body that contains all of the matching criteria such as source, destination, and protocol

C.

a rule header to define source, destination, and protocol, and the output configuration to determine which form of output to produce if the rule triggers

D.

a rule body that contains packet-matching criteria or options to define where to look for content in a packet, and a rule header to define matching criteria based on where a packet originates, where it is going, and over which protocol

Buy Now
Question # 5

Which mechanism should be used to write an IPS rule that focuses on the client or server side of a TCP communication?

Options:

A.

the directional operator in the rule header

B.

the "flow" rule option

C.

specification of the source and destination ports in the rule header

D.

The detection engine evaluates all sides of a TCP communication regardless of the rule options.

Buy Now
Question # 6

One of the goals of geolocation is to identify which option?

Options:

A.

the location of any IP address

B.

the location of a MAC address

C.

the location of a TCP connection

D.

the location of a routable IP address

Buy Now
Question # 7

Which option is not a characteristic of dashboard widgets or Context Explorer?

Options:

A.

Context Explorer is a tool used primarily by analysts looking for trends across varying periods of time.

B.

Context Explorer can be added as a widget to a dashboard.

C.

Widgets offer users an at-a-glance view of their environment.

D.

Widgets are offered to all users, whereas Context Explorer is limited to a few roles.

Buy Now
Question # 8

Which interface type allows for bypass mode?

Options:

A.

inline

B.

switched

C.

routed

D.

grouped

Buy Now
Question # 9

FireSIGHT recommendations appear in which layer of the Policy Layers page?

Options:

A.

Layer Summary

B.

User Layers

C.

Built-In Layers

D.

FireSIGHT recommendations do not show up as a layer.

Buy Now
Question # 10

Which option is used to implement suppression in the Rule Management user interface?

Options:

A.

Rule Category

B.

Global

C.

Source

D.

Protocol

Buy Now
Question # 11

Which option is derived from the discovery component of FireSIGHT technology?

Options:

A.

connection event table view

B.

network profile

C.

host profile

D.

authentication objects

Buy Now
Question # 12

The IP address::/0 is equivalent to which IPv4 address and netmask?

Options:

A.

0.0.0.0

B.

0.0.0.0/0

C.

0.0.0.0/24

D.

The IP address::/0 is not valid IPv6 syntax.

Buy Now
Exam Code: 500-285
Exam Name: Securing Cisco Networks with Sourcefire IPS
Last Update: Mar 10, 2025
Questions: 59
500-285 pdf

500-285 PDF

$28.5  $94.99
500-285 Engine

500-285 Testing Engine

$33  $109.99
500-285 PDF + Engine

500-285 PDF + Testing Engine

$43.5  $144.99