Answered step by step
Verified Expert Solution
Question
1 Approved Answer
Exercise #1b Rule to send alert when the source and destination addresses are the same. alert IP 192.168.1.1 any 192.168.1.1 any (msg: Source / Destination
Exercise \#1b Rule to send alert when the source and destination addresses are the same. alert IP 192.168.1.1 any 192.168.1.1 any (msg: "Source / Destination Addresses same.";) alert any any 80 any 443 (msg: "Source / Destination Addresses same.";) alert tcp 192.168.1.1 any 192.168.1.1 any (msg: "Source / Destination Addresses same.";) alert IP ip address any ip address any (msg: "sane ip address";) QUESTION 2 Exercise \#2b Rule to detect SNMP connection over UDP using default "public" is made Ans: Let protected address is 192.168.1.1 alert IP any any 192.168.1.1 161 (msg: "SNMP connection attempt over UDP using Public default.";content: "public";) Ans: Let protected address is 192.168.1.1 alert UDP any 161192.168.1.1 any (msg: "SNMP connection attempt over UDP using Public default." "content: "public";) Ans: Let protected address is 192.168.1.1 alert IP any 161 192.168.1.1 any (msg: "SNMP connection attempt over UDP using Public default.";content: "public";) Ans: Let protected address is 192.168.1.1 alert UDP any any 192.168.1.1 161 (msg: "SNMP connection attempt over UDP using Public default.";content: "public";)
Step by Step Solution
There are 3 Steps involved in it
Step: 1
Get Instant Access to Expert-Tailored Solutions
See step-by-step solutions with expert insights and AI powered tools for academic success
Step: 2
Step: 3
Ace Your Homework with AI
Get the answers you need in no time with our AI-driven, step-by-step assistance
Get Started