Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

What are examples of evidence of compromises from inside network in conjunction with Bot-infected systems?

A.

Users surfing the website directly by IP address or using domains registered within the last 30 days.

B.

Trying to access web resources using explicit proxy servers instead of transparent ones.

C.

Repetitive access to the same specific Intranet web servers within business hours.

D.

Trying to access a web server via HTTP instead of HTTPS.

Which DNS Protection mechanism has been introduced with R81.20?

A.

Propagation of a Bogus IP as a response to a DNS request.

B.

Malware DNS Trap.

C.

ThreatCloud DNS Tunneling Protection.

D.

Synchronization of the /etc/hosts file from Protection servers.

How are SNORT rules constructed?

A.

The rule is contained on two lines. There are two logical sections: Rule Header and Rule Payload.

B.

The rule is contained on two lines. There are two logical sections: Rule Header and Rule Options.

C.

The rule is contained on one line. There are two logical sections: Rule Header and Rule Payload.

D.

The rule is contained on a single line. There are two logical sections: Rule Header and Rule Options.

What is the default SMS and SG update interval for IPS Protections (R80.20+)?

A.

Six hours

B.

Twelve hours

C.

Two hours

D.

Daily

What information is provided by "fwaccel stats"?

A.

This command is to enable acceleration on QoS packets.

B.

You can check the percentage of F2F connections along with the reason why those connections could not be accelerated.

C.

The command is used to examine traffic utilization statistics.

D.

You can check the SecureXL status of your Security Gateway.

Mike wants to block all files in the event of internal failure; what option should he choose?

A.

open system

B.

fail-close

C.

fail-open

D.

closed system

What does the profile cleanup option do?

A.

Adjusts all settings to Detect only

B.

Removes all Administrator overrides

C.

Deletes all Exemptions

D.

Removes corrupt updates

What is the default Anti-Virus protected scope interface settings?

A.

DMZ

B.

External and DMZ

C.

External

D.

All

Which is NOT true of Threat Prevention policy application?

A.

Only applied after traffic is accepted by Access Control Policy

B.

Traffic is matched against all applicable layers at the same time

C.

Only applies first matched rule

D.

Applied as ordered layer

You have to issue a Log filter to view IPS logs generated for user John Doe.

Which of the following is the correct filter?

A.

user:"John-Doe" AND (action:drop OR action:reject OR action:block)

B.

user:John Doe AND (action:drop OR action:reject OR action:block)

C.

user:"John Doe" AND (action:drop OR action:reject OR action:block)

D.

user:'John Doe' AND (action:drop OR action:reject OR action:block)