Securing Cisco Networks with Sourcefire Intrusion Prevention System Free Sample Questions

Create a free account to browse all 17 sample questions. The full practice test includes 257 questions. Use the simulator for timed and flashcard mode.

Try Simulator

500-285 Sample Questions

  1. Question 1

    Q1

    What are the two categories of variables that you can configure in Object Management? A.System Default Variables and FireSIGHT-Specific VariablesB.System Default Variables and Procedural VariablesC.Default Variables and Custom VariablesD.Policy-Specific Variables and Procedural Variables

    Show answer & explanation

    Correct answer: C

  2. Question 2

    Q2

    Which option is true regarding the $HOME_NET variable? A.is a policy-level variableB.has a default value of "all"C.defines the network the active policy protectsD.is used by all rules to define the internal network

    Show answer & explanation

    Correct answer: C

  3. Question 3

    Q3

    Which option is one of the three methods of updating the IP addresses in Sourcefire Security Intelligence? A.subscribe to a URL intelligence feedB.subscribe to a VRTC.upload a list that you createD.automatically upload lists from a network share

    Show answer & explanation

    Correct answer: C

  4. Question 4

    Q4

    Which statement is true in regard to the Sourcefire Security Intelligence lists? A.The global blacklist universally allows all traffic through the managed device.B.The global whitelist cannot be edited.C.IP addresses can be added to the global blacklist by clicking on interactive graphs in Context Explorer.D.The Security Intelligence lists cannot be updated.

    Show answer & explanation

    Correct answer: C

  5. Question 5

    Q5

    A security architect is designing a variable set for a multi-tenant environment using FireSIGHT Management Center. Tenant A uses the 10.1.0.0/16 subnet, and Tenant B uses 10.2.0.0/16. Both tenants share the same Intrusion Policy but require distinct protection scopes. How should the architect configure the $HOME_NET variable to ensure the Intrusion Policy correctly identifies the protected network for each tenant's specific traffic flow when applied via Access Control Rules?

    Show answer & explanation

    Correct answer: D

    In FireSIGHT/Firepower, variables are linked to Intrusion Policies, but the assignment happens within the Access Control Policy (ACP). By creating different Variable Sets (e.g., Set_A with $HOME_NET=10.1.0.0/16 and Set_B with $HOME_NET=10.2.0.0/16), the administrator can reuse the same Intrusion Policy in different ACP rules while applying the correct network context for each rule.

  6. Question 6

    Q6

    An administrator observes that a critical business application using a proprietary TCP protocol on port 8888 is being dropped by the default 'Balanced Security and Connectivity' intrusion policy. The drops are triggered by a preprocessor anomaly. What is the most efficient method to allow this traffic without disabling the preprocessor globally?

    Show answer & explanation

    Correct answer: B

    Suppression rules allow an administrator to prevent specific signature or preprocessor events (identified by GID:SID) from firing for specific source or destination IP addresses. This stops the drop action for the authorized application without disabling the protection for the rest of the network.

  7. Question 7

    Q7

    While analyzing the Context Explorer, an analyst notices that the operating system information for several critical servers is listed as 'Unknown' or incorrect. This inaccuracy is affecting the FireSIGHT recommended rules generation. Which feature must be tuned to improve the accuracy of this passive discovery?

    Show answer & explanation

    Correct answer: C

    The Network Discovery Policy controls how the FirePOWER system collects data about the network assets (hosts, OS, applications, users). Tuning the networks being monitored and the active/passive discovery settings in this policy ensures accurate host profiling, which is essential for FireSIGHT recommendations.

  8. Question 8

    Q8Multiple answers

    Which of the following Snort 2.9 rule headers is valid for alerting on traffic originating from the external network destined for the HTTP servers defined in the variable set? (Select TWO)

    Show answer & explanation

    Correct answers: A, B

    This is a standard valid header: Action (alert) Protocol (tcp) SourceIP ($EXTERNAL_NET) SourcePort (any) Direction (->) DestIP ($HTTP_SERVERS) DestPort ($HTTP_PORTS).

    This is also valid. It uses the negation operator (!) to specify traffic NOT from the home network (effectively external) destined for the home network on port 80.

Register free to unlock 9 more sample questions

Create a free account to continue with the rest of the 500-285 sample set.

Lifetime One

Own this practice test forever.

$46.31
$43.99
one-time
  • Full access to 257 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon