ExamGecko
Question list
Search
Search

Related questions











Question 65 - 312-50v12 discussion

Report
Export

You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has snort installed, and the second machine (192.168.0.150) has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort.

You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine. What Wireshark filter will show the connections from the snort machine to kiwi syslog machine?

A.
tcp.srcport= = 514 && ip.src= = 192.168.0.99
Answers
A.
tcp.srcport= = 514 && ip.src= = 192.168.0.99
B.
tcp.srcport= = 514 && ip.src= = 192.168.150
Answers
B.
tcp.srcport= = 514 && ip.src= = 192.168.150
C.
tcp.dstport= = 514 && ip.dst= = 192.168.0.99
Answers
C.
tcp.dstport= = 514 && ip.dst= = 192.168.0.99
D.
tcp.dstport= = 514 && ip.dst= = 192.168.0.150
Answers
D.
tcp.dstport= = 514 && ip.dst= = 192.168.0.150
Suggested answer: D
asked 18/09/2024
Owais Mansoor
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first