ExamGecko
Question list
Search
Search

Related questions











Question 269 - 300-710 discussion

Report
Export

An engineer is configuring a custom intrusion rule on Cisco FMC. The engineer needs the rule to search the payload or stream for the string '|45 5* 26 27 4 0A|*. Which Keyword must the engineer use with this stung lo create an argument for packed inspection?

A.

metadata

Answers
A.

metadata

B.

Content

Answers
B.

Content

C.

Protected _ content

Answers
C.

Protected _ content

D.

data

Answers
D.

data

Suggested answer: B

Explanation:

The content keyword is used to specify a string or pattern to search for in the payload or stream of a packet. The string must be enclosed in quotation marks and can use modifiers such as nocase, depth, offset, and so on. The string can also use hexadecimal notation by using a pipe symbol (|) before and after the hexadecimal characters. For example, content:'|45 5* 26 27 4 0A|' will match any payload or stream that contains the hexadecimal bytes 45 526 27 4 0A followed by any number of bytes2

asked 07/10/2024
Julius Nammeh
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first