You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has snort installed, and the second machine (192.168.0.150) has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort. You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine. What wireshark filter will show the connections from the snort machine to kiwi syslog machine?
A) tcp.dstport==514 && ip.dst==192.168.0.150
B) tcp.srcport==514 && ip.src==192.168.0.99
C) tcp.dstport==514 && ip.dst==192.168.0.0/16
D) tcp.srcport==514 && ip.src==192.168.150
Correct Answer:
Verified
Q184: You've just been hired to perform a
Q185: What is a "Collision attack" in cryptography?
A)
Q186: You have several plain-text firewall logs that
Q187: How does the Address Resolution Protocol (ARP)
Q188: When you are getting information about a
Q190: When you are testing a web application,
Q191: Which of the following parameters describe LM
Q192: You are performing information gathering for an
Q193: This asymmetry cipher is based on factoring
Q194: What is the process of logging, recording,
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents