What can the SMTP preprocessor in FirePOWER normalize?

What can the SMTP preprocessor in FirePOWER normalize?

What can the SMTP preprocessor in FirePOWER normalize?

A.
It can extract and decode email attachments in client to server traffic.

B.
It can look up the email sender.

C.
It compares known threats to the email sender.

D.
It can forward the SMTP traffic to an email filter server.

E.
It uses the Traffic Anomaly Detector.



Leave a Reply 1

Your email address will not be published. Required fields are marked *


Ss

Ss

A.

http://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Application_Layer_Preprocessors.html#ID-2244-00000b49

The SMTP Preprocessor
The SMTP preprocessor instructs the rules engine to normalize SMTP commands. The preprocessor can also extract and decode email attachments in client-to-server traffic and, depending on the software version, extract email file names, addresses, and header data to provide context when displaying intrusion events triggered by SMTP traffic.