Use CSA MC to configure rules
Questions derived from the Cisco Security Agent Guide, Chapter 4: Understanding CSA Policies, Modules, and Rules, CSA Rules, pp. 94-96. 642-513 – Securing Hosts Using Cisco Security Agent.
Objective: Use CSA MC to configure rules
SubObjective: Describe and configure the Network Shield Rule
Item Number: 642-5220.127.116.11
Multiple Answer, Multiple Choice
In the Network Shield Rule Configuration screen, which of the following checks are displayed under the IP Security Checks section? (Choose two.)
- Trace route
- Malicious packet
- ICMP covert channel
- Source routed packet
- Unrestricted network connectivity during boot
A. Trace route
D. Source routed packet
In the Network Shield Rule Configuration screen, the following checks are displayed under the IP Security Checks section:
- Invalid IP header: Ensures a consistent IP header
- Invalid IP address: Protects against invalid IP addresses.
- Source routed packet: Source routed packets are matched.
- Trace route: Traceroute packets are matched.
For more information, see Available Rule Types