The questions that follow give you a bigger challenge than the exam itself by using an openended question format. By reviewing now with this more difficult question format, you can exercise your memory better and prove your conceptual and factual knowledge of this chapter. The answers to these questions are found in the appendix.
For more practice with exam-like question formats, use the exam engine on the CD-ROM.
Which two fields uniquely identify a signature?
What does the Signature Fidelity Rating indicate?
What does the Alert Severity level indicate?
What values can you assign to the Event Count Key field?
What does the Event Count Key specify?
What is the Meta Event Generator?
When configuring a signature with the Meta signature engine, which engine-specific parameters do you need to specify?
Explain Application Policy Enforcement and identify which signature engines support this capability.
What are some of the checks provided by the AIC HTTP signature engine?
Signature tuning involves changing which signature parameters?
Signature tuning does not usually involve changing which signature parameters?
What are the four high-level steps involved in creating a custom signature?
What are the factors that you need to consider when choosing a signature engine for a new signature?
What is the difference between adding a new signature and creating a new signature by using the cloning functionality?
What regex matches the following patterns: ABXDF, ABXXDF, and ABD?