Skip to Main Content
SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285
book

SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285

by Todd Lammle, Alex Tatistcheff, John Gay
October 2015
Intermediate to advanced content levelIntermediate to advanced
432 pages
9h 55m
English
Sybex
Content preview from SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide: Exam 500-285

Chapter 6 Intrusion Event Analysis

THE SSFIPS EXAM TOPICS COVERED IN THIS CHAPTER INCLUDE THE FOLLOWING:

  • ✓ 3.0 Event Analysis
  • ✓ 3.1 Understand the role that geolocation plays in analysis
  • ✓ 3.2 Be familiar with the interfaces for analysis, including the Dashboard, Workflows and Context Explorer

The world of network intrusion detection is a dynamic place where new vulnerabilities are discovered daily, new attacks are launched continuously, and networks themselves are in a constant state of flux. Vendors ceaselessly respond by creating and releasing a steady stream of software patches to address vulnerabilities, and teams like Cisco Talos (formerly VRT) are continuously rolling out new rules to protect against attacks. It’s a never-ending ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

CCIE Security v4.0 Practice Labs

CCIE Security v4.0 Practice Labs

Natalie Timms
CCNA Data Center DCICT 200-155 Official Cert Guide

CCNA Data Center DCICT 200-155 Official Cert Guide

Navaid Shamsee, David Klebanov, Hesham Fayed, Ahmed Afrose, Ozden Karakok

Publisher Resources

ISBN: 9781119155034Purchase book