1.
A Cisco IPS appliance running in a network environment with asymmetrical traffic flow is experiencing many false positive alerts that are triggered by the 13000 signature ID. What can the IPS administrator tune on the IPS to reduce the false positives?
2.
Which Cisco IPS appliance signature engine uses signature events as input to correlate different signatures into a higher level event?
3.
Referring to the monitor session 1 destination GigabitEthernet0/47 ingress Cisco Catalyst switch command, what does the "ingress" command option enable?
4.
From Cisco Security Manager, which external component or service is used to access in-depth signature information?
5.
Which mode consolidates alarms where the Cisco IPS appliance will generate an alert the first time that a signature fires on an address set and then only send a summary alert for all address sets over a given time interval?
6.
When setting up a Cisco IPS appliance in promiscuous mode, which Cisco Catalyst switch command is used to display information about all SPAN and remote SPAN sessions on the switch?
7.
What about this configuration command is true: ips inline fail-open sensor sensor_name?
8.
Which parameter is used to configure a signature to fire if the activity it detects happens a certain number of times for the same address set within a specified period of time?
9.
What is the maximum number of virtual sensors that a Cisco IPS 4200 Series appliance can support?
10.
Which Cisco IPS appliance CLI command is used to display information in the IPS Event Store?