
642-531
B. subscriptions
C. transaction log
D. queries
E. configuration
Answer: B, D
Page 123 Cisco Press CCSP CSIDS 2nd edition under Remote Data Exchange Protocol
The client can issue one of the following two types of event requests:
- Queries (used to retrieve events from the sensor based on a specified query)
- Subscriptions (enable a client to establish a live event feed with the sensor based on specific query criteria)
QUESTION 182
Which two classes of request and response messages are defined by RDEP? (Choose two.)
A. Event messages
B. Syslog messages
C. IP Log messages
D. PostOffice messages
E. CnC messages
Answer: A, C
Explanation:
RDEP defines the following classes of request and response messages:
1) Event messages - Include IDS alarm, status, and error messages. Monitoring applications such as IEV and
the Security Monitor use RDEP's event pull model to retrieve events from the Sensor. The pull model allows
the application to pull alarms at its own pace. As soon as the monitoring application connects to the Sensor and
requests alarms, the alarms are returned to the monitoring application console without delay. Alarms remain on
the Sensor until a 4-GB limit is reached and they are overwritten by new alarms. Since a large number of alarms
can be stored on the Sensor itself, the management application can pull alarms after being disconnected for a
long period of time without losing alarms.
2) IP log messages - Used by clients to retrieve IP log data from Sensors.
Cisco Courseware 6-7
QUESTION 183
Which Cisco IDS communication infrastructure parameters are required to enable the use of IDS Device
Manager to configure the Sensor? (Choose two)
A. Sensor organization name
B. Sensor group name
C. IDM group name
D. Sensor organization ID
E. IDM organization ID
Answer: A, D
Komentáře k této Příručce