exam questions

Exam 312-39 All Questions

View all questions & answers for the 312-39 exam

Exam 312-39 topic 1 question 11 discussion

Actual exam question from ECCouncil's 312-39
Question #: 11
Topic #: 1
[All 312-39 Questions]

Where will you find the reputation IP database, if you want to monitor traffic from known bad IP reputation using OSSIM SIEM?

  • A. /etc/ossim/reputation
  • B. /etc/ossim/siem/server/reputation/data
  • C. /etc/siem/ossim/server/reputation.data
  • D. /etc/ossim/server/reputation.data
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
adbjhn
3 months, 2 weeks ago
Selected Answer: D
/etc/ossim/server/reputation.data
upvoted 1 times
...
popocloud
4 months, 3 weeks ago
The answer is D. Module 4 pg 461
upvoted 2 times
...
froi2222
6 months, 1 week ago
information about the reputation of known IP addresses, which can be used to monitor traffic from known bad IP reputations and aid in security monitoring and incident response. LETTER D
upvoted 1 times
...
[Removed]
1 year, 2 months ago
The IP reputation list maintained by USM Appliance is stored on the USM Appliance Server in the /etc/ossim/server/reputation.data file. Activity, Reliability, and Priority values provided by OTX are saved with event information for those events having reputation data for either source or destination IP addresses. https://cybersecurity.att.com/documentation/usm-appliance/otx/using-otx-in-usm.htm
upvoted 2 times
...
rached1996
1 year, 3 months ago
Selected Answer: D
/etc/ossim/server/reputation.data
upvoted 2 times
...
iemvrm12
1 year, 5 months ago
D is correct.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago