BlackFriday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

SCP Exam SC0-451 Topic 5 Question 85 Discussion

Actual exam question for SCP's SC0-451 exam
Question #: 85
Topic #: 5
[All SC0-451 Questions]

You are configuring your new IDS machine, and are creating new rules. You enter the following rule: Alert tcp any any -> 10.0.10.0/24 any (msg: "NULL scan detected"; flags: 0;) What is the effect of this rule?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

Eulah
5 months ago
Makes sense now. D seems correct, focused on one direction only.
upvoted 0 times
...
Huey
5 months ago
No, the rule specifies one direction with '->'. I'd go with \\ D.
upvoted 0 times
...
Cheryll
5 months ago
But why not C? It mentions both directions.
upvoted 0 times
...
Marg
6 months ago
I think it's D. The rule alerts for NULL scans in one direction.
upvoted 0 times
...
Eulah
6 months ago
Yeah, the choices are confusing.
upvoted 0 times
...
Cheryll
7 months ago
This question looks tricky.
upvoted 0 times
...
Tracey
7 months ago
Yes, it seems like it. It's designed to capture those specific scans.
upvoted 0 times
...
Larae
7 months ago
So, it's a logging rule specifically for NULL scans from that network?
upvoted 0 times
...
Tracey
7 months ago
I think the effect of this rule is to capture NULL scans originating from the 10.0.10.0/24 network.
upvoted 0 times
...

Save Cancel