logo

Crowdly

Browser

Add to Chrome

While configuring Wazuh to automatically respond to SSH brute-force login attemp...

✅ The verified answer to this question is available below. Our community-reviewed solutions help you understand the material better.

While configuring Wazuh to automatically respond to SSH brute-force login attempts during a lab exercise, a student sets up an `<active-response>` block in the `ossec.conf` file. However, the automated blocking does not trigger as expected. Upon reviewing the configuration, the instructor points out that the `<rules_id>` field was missing. Why is it essential to correctly insert the `<rules_id>` in the `<active-response>` configuration?
0%
0%
0%
0%
More questions like this

Want instant access to all verified answers on moodle.polytechnic.bh?

Get Unlimited Answers To Exam Questions - Install Crowdly Extension Now!

Browser

Add to Chrome