| Exam Code/Number: | 500-280Join the discussion |
| Exam Name: | Securing Cisco Networks with Open Source Snort |
| Certification: | Cisco |
| Question Number: | 60 |
| Publish Date: | Aug 21, 2026 |
|
Rating
100%
|
|
On which protocol does Snort focus to decode, process, and alert on suspicious network traffic?
Which preprocessor maintains connection state so that attacks that manifest over multiple packets in a session can be detected?
Which statement about the detection engine configuration settings in snort.conf is true?