500-285 Practice Questions
Prepare for 500-285 with more than an answer.
- Exam fee
- $300 USD
- Level
- Specialist
- Valid for
- 2 years
Domains covered on the exam 5
- Object Management20%
- Access Control Policy25%
- IPS Policy and Configuration25%
- Event Analysis20%
- FireSIGHT Technologies and Network-Based Malware Detection10%
- 1
Refer to the diagram below. A company has deployed Sourcefire sensors in passive mode connected to a SPAN port on the core switch. The administrator notices that while they receive IDS alerts, the system fails to block any attacks. What is the fundamental reason for this behavior?
Show answer details
Correct answer: C
In passive mode (IDS), the sensor receives a copy of the traffic via a SPAN or Tap port. Since it is not in the direct path of the packet flow (inline), it cannot drop or block the actual traffic; it can only generate alerts.
- 2
Review the following case study scenario:
GlobalCorp is a financial institution requiring strict compliance with PCI-DSS. They are implementing a Sourcefire IPS solution across three data centers.
Requirement 1: All credit card numbers (PAN) leaving the network must be detected and blocked.
Requirement 2: The system must identify and alert on any unencrypted Telnet or FTP sessions.
Requirement 3: Due to high throughput (10Gbps), performance is critical.Which specific configuration in the Intrusion Policy should be enabled to meet Requirement 1 while minimizing the performance impact described in Requirement 3?
Show answer details
Correct answer: C
The Sensitive Data Detection (SDD) preprocessor is designed for this task. However, regex matching for credit cards is CPU intensive. To meet the performance requirement, it is critical to scope the detection only to relevant egress traffic and specific protocols/ports via the Network Analysis Policy (NAP) rather than scanning every packet globally.
- 3
What is the primary function of the 'Sinkhole' object type in Object Management, and how is it utilized in an Access Control Policy?
Show answer details
Correct answer: B
A Sinkhole object contains an IP address (usually an internal remediation server). When used in a DNS policy within Access Control, if a client queries a blacklisted domain, the system returns the Sinkhole IP. This allows the administrator to identify the infected client (because it tries to connect to the sinkhole IP) and prevent the connection to the C&C server.
- 4
An organization wants to block all traffic from a specific country due to high rates of cyberattacks. However, they must allow traffic to their public web server (192.0.2.50) from that same country. Which strategy correctly implements this in the Access Control Policy?
Show answer details
Correct answer: B
Access Control Rules are processed top-down. To create an exception, you must place the more specific Allow rule (Country -> WebServer) with a lower index (higher position) than the broad Block rule (Country -> Any).
- 5
When configuring a Network Analysis Policy (NAP), what is the purpose of the 'Inline Normalization' preprocessor option?
Show answer details
Correct answer: A
Inline Normalization ensures that the traffic the IPS inspects is exactly what the destination host sees. It can modify the traffic stream to resolve ambiguities (like overlapping TCP segments) and forwards this normalized traffic, thereby neutralizing evasion attacks that rely on target host interpretation differences.
- 6
An administrator wants to ensure that all Access Control policies automatically inherit a specific set of base rules (e.g., blocking known bad IP lists) that cannot be overridden by lower-level administrators. How should this be structured?
Show answer details
Correct answer: A
FireSIGHT allows for Policy Inheritance. By creating a base policy with 'Mandatory' rules (locked rules) and setting it as the base (parent) for other policies, the child policies inherit these rules. Mandatory rules in the parent policy are enforced before any rules in the child policy.
- 7
What are the two categories of variables that you can configure in Object Management? A.System Default Variables and FireSIGHT-Specific VariablesB.System Default Variables and Procedural VariablesC.Default Variables and Custom VariablesD.Policy-Specific Variables and Procedural Variables
Show answer details
Correct answer: C
- 8
Which option is true regarding the $HOME_NET variable? A.is a policy-level variableB.has a default value of "all"C.defines the network the active policy protectsD.is used by all rules to define the internal network
Show answer details
Correct answer: C
