ExamGecko
Question list
Search
Search

Related questions











Question 310 - 200-201 discussion

Report
Export

Refer to the exhibit.

What is the outcome of the command?

A.

TCP rule that detects TCP packets with the SYN flag in an external FTP server

Answers
A.

TCP rule that detects TCP packets with the SYN flag in an external FTP server

B.

TCP rule that detects TCP packets with a SYN flag in the internal network

Answers
B.

TCP rule that detects TCP packets with a SYN flag in the internal network

C.

TCP rule that detects TCP packets with a ACK flag in the internal network

Answers
C.

TCP rule that detects TCP packets with a ACK flag in the internal network

D.

TCP rule that detects TCP packets with the ACK flag in an external FTP server

Answers
D.

TCP rule that detects TCP packets with the ACK flag in an external FTP server

Suggested answer: B

Explanation:

The command in the exhibit is a Snort rule that is configured to alert on TCP packets with the SYN flag set, where the source is not the home network (!$HOME_NET) and the destination is within the home network ($HOME_NET) on port 80. This rule is designed to detect potential SYN flood attacks targeting the internal network's web server on port 80.

asked 07/10/2024
MIGUEL PARADA VAZQUEZ
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first