1.
Which signature engine is recommended for creating a custom signature for packet header matching?
2.
Which four features are supported on the Cisco ASA AIP-SSM but are not supported on the Cisco ASA AIP-SSC? (Choose four.)
3.
Which Cisco IPS appliance TCP session tracking mode should be used if packets of the same session are coming to the sensor over different interfaces, but should be treated as a single session?
4.
Which four configuration elements can the virtual sensor of an Cisco IPS appliance have? (Choose four.)
5.
Which value is not used by the Cisco IPS appliance in the risk rating calculation?
6.
In a centralized Cisco IPS appliance deployment, it may not be possible to connect an IPS appliance to every switch or segment in the network. So, an IPS appliance can be deployed to inspect traffic on ports that are located on multiple remote network switches. In this case, which two configurations required? (Choose two.)
7.
Which Cisco IPS appliance feature is best used to detect these two conditions? 1) The network starts becoming congested by worm traffic. 2) A single worm-infected source enters the network and starts scanning for other vulnerable hosts.
8.
What will happen if you try to recover the password on the Cisco IPS 4200 Series appliance on which password recovery is disabled?
9.
Which four networking tools does Cisco IME include that can be invoked for specific events, to learn more about attackers and victims using basic network reconnaissance? (Choose four.)
10.
The AIP-SSM CLI can be accessed from the ASA CLI by using which command?