Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

SCP Exam SC0-451 Topic 5 Question 85 Discussion

Actual exam question for SCP's SC0-451 exam
Question #: 85
Topic #: 5
[All SC0-451 Questions]

You are configuring your new IDS machine, and are creating new rules. You enter the following rule: Alert tcp any any -> 10.0.10.0/24 any (msg: "NULL scan detected"; flags: 0;) What is the effect of this rule?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

Eulah
7 months ago
Makes sense now. D seems correct, focused on one direction only.
upvoted 0 times
...
Huey
7 months ago
No, the rule specifies one direction with '->'. I'd go with \\ D.
upvoted 0 times
...
Cheryll
7 months ago
But why not C? It mentions both directions.
upvoted 0 times
...
Marg
7 months ago
I think it's D. The rule alerts for NULL scans in one direction.
upvoted 0 times
...
Eulah
8 months ago
Yeah, the choices are confusing.
upvoted 0 times
...
Cheryll
8 months ago
This question looks tricky.
upvoted 0 times
...
Tracey
9 months ago
Yes, it seems like it. It's designed to capture those specific scans.
upvoted 0 times
...
Larae
9 months ago
So, it's a logging rule specifically for NULL scans from that network?
upvoted 0 times
...
Tracey
9 months ago
I think the effect of this rule is to capture NULL scans originating from the 10.0.10.0/24 network.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77