Question 1 of 30
A network security engineer is tasked with configuring the Sourcefire IPS to effectively mitigate a series of DDoS attacks targeting a web application. The engineer decides to implement a combination of signature-based and anomaly-based detection methods. Given the nature of the attacks, which configuration approach should the engineer prioritize to ensure optimal performance and minimal false positives while maintaining the integrity of legitimate traffic?
Configure the IPS to utilize a hybrid detection strategy that combines both signature and anomaly detection, with a focus on tuning the anomaly detection thresholds based on baseline traffic patterns.
Rely solely on signature-based detection to identify known attack patterns, disregarding anomaly detection to avoid complexity.
Implement only anomaly-based detection, as it is more effective in identifying new and unknown attack vectors without the need for predefined signatures.
Set the IPS to operate in passive mode, allowing it to monitor traffic without actively blocking any potential threats.

Preparing for CISCO 500-285 Securing Cisco Networks with Sourcefire IPS? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free