500-285 Sample Questions

500-285 Sample Questions & Answers

Access control policy ties with the Snort rules language used in IPS policy for the heaviest weight, alongside security intelligence and FireSIGHT object types, plus detecting network-based malware and investigating incidents.

Launch the full 500-285 simulator →

Showing 8 of 17 free samples.

  1. Question 1Advanced

    Object Management · Variable Sets

    A security architect is designing a variable set for a multi-tenant environment using FireSIGHT Management Center. Tenant A uses the 10.1.0.0/16 subnet, and Tenant B uses 10.2.0.0/16. Both tenants share the same Intrusion Policy but require distinct protection scopes. How should the architect configure the $HOME_NET variable to ensure the Intrusion Policy correctly identifies the protected network for each tenant's specific traffic flow when applied via Access Control Rules?

    Show answer & explanation

    Correct answer: B

    In FireSIGHT/Firepower, variables are linked to Intrusion Policies, but the assignment happens within the Access Control Policy (ACP). By creating different Variable Sets (e.g., Set_A with $HOME_NET=10.1.0.0/16 and Set_B with $HOME_NET=10.2.0.0/16), the administrator can reuse the same Intrusion Policy in different ACP rules while applying the correct network context for each rule.

  2. Question 2Intermediate

    IPS Policy and Configuration · Suppression

    An administrator observes that a critical business application using a proprietary TCP protocol on port 8888 is being dropped by the default 'Balanced Security and Connectivity' intrusion policy. The drops are triggered by a preprocessor anomaly. What is the most efficient method to allow this traffic without disabling the preprocessor globally?

    Show answer & explanation

    Correct answer: A

    Suppression rules allow an administrator to prevent specific signature or preprocessor events (identified by GID:SID) from firing for specific source or destination IP addresses. This stops the drop action for the authorized application without disabling the protection for the rest of the network.

  3. Question 3Intermediate

    FireSIGHT Technologies · Network Discovery

    While analyzing the Context Explorer, an analyst notices that the operating system information for several critical servers is listed as 'Unknown' or incorrect. This inaccuracy is affecting the FireSIGHT recommended rules generation. Which feature must be tuned to improve the accuracy of this passive discovery?

    Show answer & explanation

    Correct answer: C

    The Network Discovery Policy controls how the FirePOWER system collects data about the network assets (hosts, OS, applications, users). Tuning the networks being monitored and the active/passive discovery settings in this policy ensures accurate host profiling, which is essential for FireSIGHT recommendations.

  4. Question 4AdvancedSelect 2

    IPS Policy and Configuration · Snort Rules Language

    Which of the following Snort 2.9 rule headers is valid for alerting on traffic originating from the external network destined for the HTTP servers defined in the variable set? (Select TWO)

    Show answer & explanation

    Correct answers: B, E

    This is a standard valid header: Action (alert) Protocol (tcp) SourceIP ($EXTERNAL_NET) SourcePort (any) Direction (->) DestIP ($HTTP_SERVERS) DestPort ($HTTP_PORTS).

    This is also valid. It uses the negation operator (!) to specify traffic NOT from the home network (effectively external) destined for the home network on port 80.

  5. Question 5Intermediate

    Access Control Policy · Trust Rules

    A large enterprise is deploying Sourcefire IPS and wants to ensure that specific internal scanners do not trigger intrusion events during scheduled vulnerability assessments. The scanners use dynamic IP addresses from a dedicated DHCP pool (192.168.50.0/24). What is the most effective way to prevent these false positives without compromising security for other hosts?

    Show answer & explanation

    Correct answer: A

    A Trust rule allows traffic to pass without deep packet inspection (IPS). By placing a Trust rule for the scanner's subnet at the top of the Access Control Policy, traffic from the scanners is fast-pathed and will not trigger IPS signatures.

  6. Question 6Beginner

    Access Control Policy · Rule Actions

    True or False: In FireSIGHT Management Center, the 'Interactive Block' action in an Access Control Policy rule allows a user to bypass the block for a specific website if they acknowledge a warning page, but this only works for HTTP traffic unless SSL inspection is decrypting HTTPS.

    Show answer & explanation

    Correct answer: A

    True. The Interactive Block page is an HTML response injected by the device. If the traffic is encrypted (HTTPS) and not decrypted, the device cannot inject the HTML warning page into the stream, so the user will simply experience a connection reset or timeout instead of the interactive warning.

  7. Question 7Advanced

    FireSIGHT Technologies · Advanced Malware Protection

    A security engineer is troubleshooting an issue where file policies are not detecting malware in ZIP archives. The engineer suspects the archive depth limit is too low. In which policy configuration should the engineer verify the archive inspection depth settings?

    Show answer & explanation

    Correct answer: B

    While it might seem like a File Policy setting, archive inspection depth is actually a global setting often configured within the File Policy's advanced options or the specific malware protection configuration depending on the exact version, but 'File Policy' is the primary context for defining how files are handled.

  8. Question 8Beginner

    IPS Policy and Configuration · Deployment Modes

    Refer to the diagram below. A company has deployed Sourcefire sensors in passive mode connected to a SPAN port on the core switch. The administrator notices that while they receive IDS alerts, the system fails to block any attacks. What is the fundamental reason for this behavior?

    Show answer & explanation

    Correct answer: B

    In passive mode (IDS), the sensor receives a copy of the traffic via a SPAN or Tap port. Since it is not in the direct path of the packet flow (inline), it cannot drop or block the actual traffic; it can only generate alerts.

Ready for the real thing?

The full 500-285 simulator has every exam-style question, timed mode, and instant scoring.