<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS sample question discussion in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-sample-question-discussion/m-p/598825#M92637</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ...  please post your questions to the Career certifications forum  !!!  they will be able to help you with any questions you need for your exam preparation !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Aug 2006 05:44:57 GMT</pubDate>
    <dc:creator>Fernando_Meza</dc:creator>
    <dc:date>2006-08-15T05:44:57Z</dc:date>
    <item>
      <title>IPS sample question discussion</title>
      <link>https://community.cisco.com/t5/network-security/ips-sample-question-discussion/m-p/598824#M92636</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;I am preparing for IPs and got confused with the below question. Please advise. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q : A new sensor is generating a great deal of false positive alerts on the web servers. Which two action will help to reduce the amount of the false positives. (choose two) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A. Create a policy that denies attackers inline and filters alert for event with high risk ratings. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;B. Lower the severity level of the signatures that are generating the false positives. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C. Lower fildility rating of signatures that are generating the false postives. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;D. Raise the Target Value Rating for your web servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E. Create a filter that filters out any alert whose target address is that of one of your web servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answers provided : A,D &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I feel "A" &amp;amp; "D" will not do any thing do to reduce the false postive generating and there could be denying of legitimate traffic also. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per me , Answer should be "B" and "E" . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact we should be defining event action over rides (instead of filters), "not to produce alert" for events with lower risk rating. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PLEASE SHARE YOUR VIEWS &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:10:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-sample-question-discussion/m-p/598824#M92636</guid>
      <dc:creator>ppathiya</dc:creator>
      <dc:date>2019-03-10T10:10:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPS sample question discussion</title>
      <link>https://community.cisco.com/t5/network-security/ips-sample-question-discussion/m-p/598825#M92637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ...  please post your questions to the Career certifications forum  !!!  they will be able to help you with any questions you need for your exam preparation !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2006 05:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-sample-question-discussion/m-p/598825#M92637</guid>
      <dc:creator>Fernando_Meza</dc:creator>
      <dc:date>2006-08-15T05:44:57Z</dc:date>
    </item>
  </channel>
</rss>

