IPS Flashcards

1
Q

Explain Exploits and Anomalies

A

Exploits are known confirmed attacked and detectable by IPS, WAF, or AV. Anomalies are unknown, or zero-day like high CPU on a device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What other features does the IPS engine help with (hint four answers)

A

App Control, and flow-based AV, Web filter, and email filter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the two IPS databases?

A

Regular
Extended

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When would you use the extended signature database?

A

When you have a high security environment, it may cause performance issues.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How can you handle a false positive outbreak of IPS signatures?

A

You can set the action to monitor while you investigate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a signature exemption?

A

You can specify the ip addresses to exempt from the signature while investigating false-positives outbreaks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Where are DoS policies processed?

A

They are processed early, in the kernel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the tree types of DoS attacks?

A

TCP SYN flood
ICMP sweep
TCP port scan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a TCP SYN flood DoS?

A

Attacker floods victim with incomplete TCP/IP connection requests, victim’s connection table becomes full

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is an ICMP sweep?

A

Attacker sends ICMP traffic to find targets. Attacker can then attack hosts that reply

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a TCP port Scan

A

Scans using TCP/IP request to varying destination ports. Identifies what ports are open.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What protocols can you configured for DoS Policy?

A

TCP, UDP, ICMP, STMP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What types of DoS can you configure in a DoS Policy?

A

Flood, sweep/scan, Source, destination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can you determine thresholds for DoS?

A

If you are not sure what threshold to configure you could put the policy in monitor mode.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Should you turn on all IPS signatures?

A

No, you should start with the most business-critical services.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Do DoS policies need SSL Inspection mode?

A

No, it doesn’t look at the packet payload, just volume, source etc,

17
Q

Does IPS require SSL inspection?

A

If you want to protect from attackers hiding attacks in encrypted environments.

18
Q

What does set np-accel-mode basic do?

A

offloads IPS processing to NP

19
Q

What does set cp-accel-mode basic do?

A

offloads basic IPS pattern matching to CP8 or CP9

20
Q

What does set cp-accel-mode advanced do?

A

offloads more basic IPS pattern matching to CP8 or CP9 z

21
Q

Which chipset uses Turbo to accelerate IPS sessions

A

SoC4

22
Q

should IPS cause high CPU usage?

A

no, if it is you can use diagnose test application ipsmonitor

23
Q

What does set fail-open enable do? (IPS)

A

traffic bypasses IPS inspection

24
Q

What does set fail-open disabled do?

A

packets are dropped when the IPS socket buffer is full.