Answered step by step
Verified Expert Solution
Link Copied!

Question

1 Approved Answer

Use the links to help you answer the 3 questions please: http://ossec-docs.readthedocs.org/en/latest/manual/index.html http://ossec-docs.readthedocs.org/en/latest/syntax/head_ossec_config.active-response.html 1. How would you configure active response to send the block to

Use the links to help you answer the 3 questions please:

http://ossec-docs.readthedocs.org/en/latest/manual/index.html

http://ossec-docs.readthedocs.org/en/latest/syntax/head_ossec_config.active-response.html

1. How would you configure active response to send the block to all agents?

2. When would you block a user vs block an IP (host-deny.sh vs firewall-drop.sh)? When would you want to use both in conjunction?

3. Looking in the rules directory for sshd, how would you add a threshold so that the server does not block on 1 failed login attempt? What do you believe would be the proper amount of attempts before blocking a user at the host firewall? And what timeframe?

Step by Step Solution

There are 3 Steps involved in it

Step: 1

blur-text-image

Get Instant Access to Expert-Tailored Solutions

See step-by-step solutions with expert insights and AI powered tools for academic success

Step: 2

blur-text-image

Step: 3

blur-text-image

Ace Your Homework with AI

Get the answers you need in no time with our AI-driven, step-by-step assistance

Get Started

Recommended Textbook for

More Books

Students also viewed these Databases questions

Question

1. Explain what is meant by ethical behavior.

Answered: 1 week ago

Question

1. What is Ebola ? 2.Heart is a muscle? 3. Artificial lighting?

Answered: 1 week ago

Question

LO1 Explain how the workforce is changing in unpredicted ways.

Answered: 1 week ago

Question

LO6 List the components of job descriptions.

Answered: 1 week ago