Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Securing Cisco Networks with Sourcefire IPS

Last Update 10 hours ago Total Questions : 60

The Securing Cisco Networks with Sourcefire IPS content is now fully updated, with all current exam questions added 10 hours ago. Deciding to include 500-285 practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our 500-285 exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these 500-285 sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Securing Cisco Networks with Sourcefire IPS practice test comfortably within the allotted time.

Question # 11

Which option is true when configuring an access control rule?

A.

You can use geolocation criteria to specify source IP addresses by country and continent, as well as destination IP addresses by country and continent.

B.

You can use geolocation criteria to specify destination IP addresses by country but not source IP addresses.

C.

You can use geolocation criteria to specify source and destination IP addresses by country but not by continent.

D.

You can use geolocation criteria to specify source and destination IP addresses by continent but not by country.

Question # 12

Context Explorer can be accessed by a subset of user roles. Which predefined user role is not valid for FireSIGHT event access?

A.

Administrator

B.

Intrusion Administrator

C.

Security Analyst

D.

Security Analyst (Read-Only)

Question # 13

When adding source and destination ports in the Ports tab of the access control policy rule editor, which restriction is in place?

A.

The protocol is restricted to TCP only.

B.

The protocol is restricted to UDP only.

C.

The protocol is restricted to TCP or UDP.

D.

The protocol is restricted to TCP and UDP.

Question # 14

When configuring an LDAP authentication object, which server type is available?

A.

Microsoft Active Directory

B.

Yahoo

C.

Oracle

D.

SMTP

Question # 15

Which statement is true when network traffic meets the criteria specified in a correlation rule?

A.

Nothing happens, because you cannot assign a group of rules to a correlation policy.

B.

The network traffic is blocked.

C.

The Defense Center generates a correlation event and initiates any configured responses.

D.

An event is logged to the Correlation Policy Management table.

Question # 16

Which list identifies the possible types of alerts that the Sourcefire System can generate as notification of events or policy violations?

A.

logging to database, SMS, SMTP, and SNMP

B.

logging to database, SMTP, SNMP, and PCAP

C.

logging to database, SNMP, syslog, and email

D.

logging to database, PCAP, SMS, and SNMP

Question # 17

Which statement is true in regard to the Sourcefire Security Intelligence lists?

A.

The global blacklist universally allows all traffic through the managed device.

B.

The global whitelist cannot be edited.

C.

IP addresses can be added to the global blacklist by clicking on interactive graphs in Context Explorer.

D.

The Security Intelligence lists cannot be updated.

Question # 18

What are the two categories of variables that you can configure in Object Management?

A.

System Default Variables and FireSIGHT-Specific Variables

B.

System Default Variables and Procedural Variables

C.

Default Variables and Custom Variables

D.

Policy-Specific Variables and Procedural Variables

Go to page: