Firepower Signature Engines Flashcards

1
Q

AIC

A

Web traffic analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Atomic

A

ARP - layer 2 ARP protocol
IP Advanced - IPv6 Layer 3 and ICMPv6 Layer 4
IP - Layer 4 transport protocols
IPv6 - IOS vulns simulated by malformed IPv6 traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Fixed

A

Parallel regex matches - ICMP/TCP/UDP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Flood

A

ICMP and UDP floods

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Meta

A

Events that occur in a related manner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Multi String

A

Matches several strings for one signature

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Normalizer

A

Enforce RFC compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Service

A

Specific protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

State

A

Stateful searches of strings in protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

String

A

Matches a regex string based on ICMP/TCP/UDP protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

String XL

A

Optimized operation of String

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Sweep

A

Sweeps from a single host, destination ports, and multiple ports with RPC requests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Traffic Anomaly

A

Inspects TCP/UDP and other traffic for worms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Traffic ICMP

A

Analyzes nonstandard protocols such as TFN2K/LOKI/DDOS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Trojan

A

Analyzes traffic from nonstandard protocols such as BO2K and TFN2K

How well did you know this?
1
Not at all
2
3
4
5
Perfectly