Topic: 300-710 topic 1 question 282

Which rule action is only available in Snort 3?

A.
Pass
B.
Generate
C.
Alert
D.
Rewrite

Re: 300-710 topic 1 question 282

D is correct

This YouTube video from Cisco clarifies it at 5:45 https://youtu.be/E7cHQBCM9Bc

Re: 300-710 topic 1 question 282

Fantastic research! It really can't be more exactly said ;-). Starting from 05:45 min the author starts mentioning the new rule "REWRITE" within Snort 3.
So, yes, the correct answer here is indeed: (D)

Re: 300-710 topic 1 question 282

Only Alert in this list is a valid snort 3 rule.

Re: 300-710 topic 1 question 282

That is incorrect. Both "Pass" and "Rewrite" are snort 3 rules. "Rewrite" in snort 3 is the equivalent of "Alert" in snort 2. Rewrite only exists in snort 3, not in snort 2. I posted a link to a "Cisco" Youtube video in my other comment. At 5:45 in the video, they literally show a slide explaining snort 2 and snort 3 rules.