• Fri frakt över 249 kr
  • •
  • Snabba leveranser
  • •
  • Billiga böcker
Kundservice

Du är på sajten för privatpersoner.

Företag, bibliotek eller offentlig verksamhet?

Du handlar på classic.bokus.com, där alla dina funktioner finns intakta.
Till classic.bokus.com
Bokus logotyp. Gå till startsidan.
  • Erbjudanden
  • Nyheter
  • Student
  • Topplistor
  • Barn & ungdom
  • Bokus Play
  • E-böcker
  • Pocketböcker
  • Spel & pussel

10% rabatt på allt med kod NYSTART10 →

Sidfot

Mina sidor

    Hjälp

    • Kundservice
    • Vanliga frågor och svar
    • Frakt och leverans
    • Retur vid ångerrätt
    • Reklamera vara
    • Betalning
    • Köpvillkor
    • Allmänna villkor
    • Information om webbplatsens tillgänglighet

    Om Bokus

    • Om oss
    • Pressrum
    • För studenter
    • För företag
    • För bibliotek och offentlig verksamhet
    • För leverantörer
    • Hållbarhet

    Populärt

    • Aktuella erbjudanden
    • Presentkort
    • Studentlitteratur
    • Nya böcker
    • Topplistor
    • Signerade böcker
    • Engelska böcker

    Inspiration

    • Boktips
    • BookTok
    • Populära bokserier
    • Barnbokskaraktärer
    • Populära författare
    Logotyp för Bokus
    Följ oss på Facebook (extern länk)Följ oss på Instagram (extern länk)Följ oss på YouTube (extern länk)Följ oss på TikTok (extern länk)
    bokus @ CookiesAnpassa cookiesIntegritetspolicyKöpvillkor
    Till Citymail hemsida (extern länk)Till Budbee hemsida (extern länk)Till Postnord hemsida (extern länk)Till Schenker hemsida (extern länk)Till Early Bird hemsida (extern länk)Till Walleys hemsida (extern länk)
    1. Data och IT
    2. Nätverk och kommunikation

    SSFIPS Securing Cisco Networks with Sourcefire Intrusion Prevention System Study Guide

    Exam 500-285

    AvTodd Lammle,Alex Tatistcheff

    Häftad, Engelska, 2015

    518 kr

    Tillfälligt slut

    Beskrivning

    Cisco has announced big changes to its certification program.As of February 24, 2020, all current certifications will be retired, and Cisco will begin offering new certification programs.The good news is if you’re working toward any current CCNA certification, keep going. You have until February 24, 2020 to complete your current CCNA. If you already have CCENT/ICND1 certification and would like to earn CCNA, you have until February 23, 2020 to complete your CCNA certification in the current program.  Likewise, if you’re thinking of completing the current CCENT/ICND1, ICND2, or CCNA Routing and Switching certification, you can still complete them between now and February 23, 2020.  Up the ante on your FirePOWER with Advanced FireSIGHT Administration exam prepSecuring Cisco Networks with Sourcefire IPS Study Guide, Exam 500-285, provides 100% coverage of the FirePOWER with Advanced FireSIGHT Administration exam objectives. With clear and concise information regarding crucial next-generation network security topics, this comprehensive guide includes practical examples and insights drawn from real-world experience, exam highlights, and end of chapter reviews.  Learn key exam topics and powerful features of the Cisco FirePOWER Services, including FireSIGHT Management Center, in-depth event analysis, IPS tuning and configuration, and snort rules language.Gain access to Sybex's superior online learning environment that includes practice questions, flashcards, and interactive glossary of terms. Use and configure next-generation Cisco FirePOWER services, including application control, firewall, and routing and switching capabilitiesUnderstand how to accurately tune your systems to improve performance and network intelligence while leveraging powerful tools for more efficient event analysisComplete hands-on labs to reinforce key concepts and prepare you for the practical applications portion of the examinationAccess Sybex's online interactive learning environment and test bank, which includes an assessment test, chapter tests, bonus practice exam questions, electronic flashcards, and a searchable glossarySecuring Cisco Networks with Sourcefire IPS Study Guide, Exam 500-285 provides you with the information you need to prepare for the FirePOWER with Advanced FireSIGHT Administration examination.

    Produktinformation

    • Utgivningsdatum:2015-12-04
    • Mått:185 x 234 x 25 mm
    • Vikt:590 g
    • Format:Häftad
    • Språk:Engelska
    • Antal sidor:432
    • Förlag:John Wiley & Sons Inc
    • ISBN:9781119155034

    Utforska kategorier

    • Nätverk och kommunikation inom Data och IT
    • IT-säkerhet inom Data och IT

    Mer om författaren

    Todd Lammle, CCSI and SFCP (SourceFire Certified Professional), is the authority on Cisco networking. President of GlobalNet Training & Consulting, Inc., a network integration and training firm, Todd has worked with Fortune 500 companies for nearly 35 years. His Cisco book sales have reached almost 1,000,000 copies in print. John Gay is a Field Security Enablement Lead with Cisco Systems. Prior to Cisco's acquisition of Sourcefire, John served as Director of Instructional Delivery. He has worked in the security industry for over 15 years. Alex Tatistcheff, CISSP, GPEN, GCIH, GCIA, SFCE, is currently a Network Consulting Engineer for Cisco Security Solutions specializing in FireSIGHT. Prior to Cisco's acquisition of Sourcefire, he worked for over five years as a Senior Security Instructor.

    Innehållsförteckning

    • Introduction xv Assessment Test xxvChapter 1 Getting Started with FireSIGHT 1Industry Terminology 2Cisco Terminology 3FirePOWER and FireSIGHT 3Out with the Old… 4Appliance Models 5Hardware vs. Virtual Devices 6Device Models 6Defense Center Models 7FireSIGHT Licensing 8License Dependencies 9Network Design 9Inline IPS 10Passive IPS 11Router, Switch, and Firewall 11Policies 12The User Interface 13Initial Appliance Setup 14Setting the Management IP 15Initial Login 15Summary 17Hands-on Lab 17Review Questions 19Chapter 2 Object Management 21What Are Objects? 22Getting Started 23Network Objects 25Individual Network Objects 25Network Object Groups 25Security Intelligence 26Blacklist and Whitelist 26Sourcefire Intelligence Feed 27Custom Security Intelligence Objects 28Port Objects 29VLAN Tag 30URL Objects and Site Matching 31Application Filters 33Variable Sets 35File Lists 39Security Zones 41Geolocation 43Summary 44Hands-on Lab 45Exam Essentials 49Review Questions 51Chapter 3 IPS Policy Management 53IPS Policies 54Default Policies 55Policy Layers 56Creating a Policy 57Policy Editor 58Summary 65Hands-on Labs 65Hands-on Lab 3.1: Creating an IPS Policy 66Hands-on Lab 3.2: Viewing Connection Events 66Exam Essentials 66Review Questions 68Chapter 4 Access Control Policy 71Getting Started with Access Control Policies 72Security Intelligence Lists 75Blacklists, Whitelists, and Alerts 76Security Intelligence Page Specifics 77Configuring Security Intelligence 79Access Control Rules 86Access Control UI Elements 86Rule Categories 88A Simple Policy 97Saving and Applying 98Summary 100Hands]on Lab 100Exam Essentials 104Review Questions 105Chapter 5 FireSIGHT Technologies 107FireSIGHT Technologies 108Network Discovery Policy 109Discovery Information 114User Information 120Host Attributes 124Summary 126Hands-on Labs 126Hands-on Lab 5.1: Configuring a Discovery Policy 127Hands-on Lab 5.2: Viewing Connection Events 127Hands-on Lab 5.3: Viewing the Network Map 127Hands-on Lab 5.4: Creating Host Attributes 128Exam Essentials 128Review Questions 130Chapter 6 Intrusion Event Analysis 133Intrusion Analysis Principles 134False Positives 134False Negatives 135Possible Outcomes 135The Goal of Analysis 136The Dashboard and Context Explorer 136Intrusion Events 141An Introduction to Workflows 141The Time Window 142The Analysis Screen 145The Caveat 154Rule Comment 168Summary 175Hands]on Lab 175Exam Essentials 177Review Questions 178Chapter 7 Network]Based Malware Detection 181AMP Architecture 182SHA]256 183Spero Analysis 183Dynamic Analysis 183Retrospective Events 184Communications Architecture 184File Dispositions 185File Disposition Caching 185File Policy 185Advanced Settings 186File Rules 187File Types and Categories 191File and Malware Event Analysis 193Malware Events 194File Events 196Captured Files 197Network File Trajectory 199Context Explorer 203Summary 204Hands]on Lab 204Exam Essentials 205Review Questions 206Chapter 8 System Settings 209User Preferences 210Event Preferences 211File Preferences 211Default Time Windows 211Default Workflows 212System Configuration 212System Policy 215Health 217Health Monitor 217Health Policy 218Health Events 218Blacklist 220Health Monitor Alerts 221Summary 222Hands-on Lab 222Hands-on Lab 8.1: Creating a New System Policy 223Hands-on Lab 8.2: Viewing Health Information 223Exam Essentials 223Review Questions 225Chapter 9 Account Management 227User Account Management 228Internal versus External User Authentication 229User Privileges 229Predefined User Roles 230Creating New User Accounts 231Managing User Role Escalation 237Configuring External Authentication 239Creating Authentication Objects 240Summary 246Hands-on Lab 247Hands-on Lab 9.1: Configuring a User in the Local Database 247Hands-on Lab 9.2: Configuring Permission Escalation 247Exam Essentials 248Review Questions 249Chapter 10 Device Management 251Device Management 252Configuring the Device on the Defense Center 254NAT Configuration 266Virtual Private Networks 267Point-to-Point VPN 267Star VPN 269Mesh VPN 270Advanced Options 270Summary 271Hands-on Labs 271Hands-on Lab 10.1: Creating a Device Group 272Hands-on Lab 10.2: Renaming the Device 272Hands-on Lab 10.3: Modifying the Name of the Inline Interface Set 272Exam Essentials 273Review Questions 274Chapter 11 Correlation Policy 277Correlation Overview 278Correlation Rules, Responses, and Policies 279Correlation Rules 279Rule Options 284Responses 286Correlation Policy 291White Lists 295Traffic Profiles 301Summary 308Hands-on Lab 308Exam Essentials 309Review Questions 311Chapter 12 Advanced IPS Policy Settings 313Advanced Settings 314Preprocessor Alerting 316Application Layer Preprocessors 316SCADA Preprocessors 320Transport/Network Layer Preprocessors 320Specific Threat Detection 325Detection Enhancement 326Intrusion Rule Thresholds 327Performance Settings 327External Responses 330Summary 330Hands]on Lab 331Hands]on Lab 12.1: Modifying the HTTP Configuration Preprocessor 331Hands]on Lab 12.2: Enabling Inline Normalization 332Hands]on Lab 12.3: Demonstrating the Validation of Preprocessor Settings on Policy Commit 332Exam Essentials 333Review Questions 334Chapter 13 Creating Snort Rules 337Overview of Snort Rules 338Rule Headers 339The Rule Body 342Writing Rules 352Using the System GUI to Build a Rule 353Summary 355Exam Essentials 356Review Questions 357Chapter 14 FireSIGHT v5.4 Facts and Features 359Branding 360Simplified IPS Policy 361Network Analysis Policy 362Why Network Analysis? 365Access Control Policy 365General Settings 366Network Analysis and Intrusion Policies 366Files and Malware Settings 368Transport/Network Layer Preprocessor Settings 368Detection Enhancement Settings 368Performance/Latency Settings 369SSL Inspection 369SSL Objects 370New Rule Keywords 376File_type 376Protected_content 377Platform Enhancements 377International Enhancements 378Minor Changes 378Summary 378Appendix Answers to Review Questions 379Index 393