Want to pass your GIAC Certified Enterprise Defender (GCED) GCED exam in the very first attempt? Try Pass2lead! It is equally effective for both starters and IT professionals.
VCE
Why would the pass action be used in a Snort configuration file?
A. The pass action simplifies some filtering by specifying what to ignore.
B. The pass action passes the packet onto further rules for immediate analysis.
C. The pass action serves as a placeholder in the snort configuration file for future rule updates.
D. Using the pass action allows a packet to be passed to an external process.
E. The pass action increases the number of false positives, better testing the rules.
On which layer of the OSI Reference Model does the FWSnort utility function?
A. Physical Layer
B. Data Link Layer
C. Transport Layer
D. Session Layer
E. Application Layer
Which of the following is an outcome of the initial triage during incident response?
A. Removal of unnecessary accounts from compromised systems
B. Segmentation of the network to protect critical assets
C. Resetting registry keys that vary from the baseline configuration
D. Determining whether encryption is in use on in scope systems