Skip to main content

500-285 Real Exam Questions

Securing Cisco Networks with Sourcefire Intrusion Prevention System

60 questions available · Page 1 of 6

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

What are the two categories of variables that you can configure in Object Management?

  1. A

    System Default Variables and FireSIGHT-Specific Variables

  2. B

    System Default Variables and Procedural Variables

  3. C

    Default Variables and Custom Variables

  4. D

    Policy-Specific Variables and Procedural Variables

Show answer and explanation

Correct answer: C

Question 2 Single choice

A context box opens when you click on an event icon in the Network File Trajectory map for a file.

Which option is an element of the box?

  1. A

    Scan

  2. B

    Application Protocol

  3. C

    Threat Name

  4. D

    File Name

Show answer and explanation

Correct answer: B

Question 3 Single choice

Which Sourcefire feature allows you to send traffic directly through the device without inspecting it?

  1. A

    fast-path rules

  2. B

    thresholds or suppressions

  3. C

    blacklist

  4. D

    automatic application bypass

Show answer and explanation

Correct answer: A

Question 4 Single choice

What does packet latency thresholding measure?

  1. A

    the total elapsed time it takes to process a packet

  2. B

    the amount of time it takes for a rule to process

  3. C

    the amount of time it takes to process an event

  4. D

    the time span between a triggered event and when the packet is dropped

Show answer and explanation

Correct answer: A

Question 5 Single choice

The gateway VPN feature supports which deployment types?

  1. A

    SSL and HTTPS

  2. B

    PPTP and MPLS

  3. C

    client and route-based

  4. D

    point-to-point, star, and mesh

Show answer and explanation

Correct answer: D

Question 6 Single choice

Which interface type allows for VLAN tagging?

  1. A

    inline

  2. B

    switched

  3. C

    high-availability link

  4. D

    passive

Show answer and explanation

Correct answer: B

Question 7 Single choice

Which statement regarding user exemptions is true?

  1. A

    Non-administrators can be made exempt on an individual basis.

  2. B

    Exempt users have a browser session timeout restriction of 24 hours.

  3. C

    Administrators can be exempt from any browser session timeout value.

  4. D

    By default, all users cannot be exempt from any browser session timeout value.

Show answer and explanation

Correct answer: A

Question 8 Single choice

When you are editing an intrusion policy, how do you know that you have changes?

  1. A

    The Commit Changes button is enabled.

  2. B

    A system message notifies you.

  3. C

    You are prompted to save your changes on every screen refresh.

  4. D

    A yellow, triangular icon displays next to the Policy Information option in the navigation panel.

Show answer and explanation

Correct answer: D

Question 9 Single choice

Context Explorer can be accessed by a subset of user roles.

Which predefined user role is valid for FireSIGHT event access?

  1. A

    Administrator

  2. B

    Intrusion Administrator

  3. C

    Maintenance User

  4. D

    Database Administrator

Show answer and explanation

Correct answer: A

Question 10 Single choice

Which option describes Spero file analysis?

  1. A

    a method of analyzing the SHA-256 hash of a file to determine whether a file is malicious or not

  2. B

    a method of analyzing the entire contents of a file to determine whether it is malicious or not

  3. C

    a method of analyzing certain file characteristics, such as metadata and header information, to determine whether a file is malicious or not

  4. D

    a method of analyzing a file by executing it in a sandbox environment and observing its behaviors to determine if it is malicious or not

Show answer and explanation

Correct answer: C