Which option is best to use to capture only a subset of traffic (capturing traffic per-IP-address, per-protocol, or
per-application) off the switch backplane and copy it to the Cisco IPS appliance?
A Cisco Catalyst switch is experiencing packet drops on a SPAN destination port that is connected to an Cisco
IPS appliance. Which three configurations should be considered to resolve the packet drops issue? (Choose
three.)
From the Cisco IPS appliance CLI setup command, one of the options is "Modify default threat prevention
settings? [no]". What is this option related to?
Which Cisco IPS appliance feature is best used to detect these two conditions? 1) The network starts
becoming congested by worm traffic. 2) A single worm-infected source enters the network and starts scanning
for other vulnerable hosts.