Question 5
5 pts
Given the following rule, choose the best description of what event would trigger an alert?
alert tcp any any -> any 21 (content: "site exec"; content "%"; msg: "Attack detected"; sid:1000003;)
Buffer overflow attempt using port 21 FTP
Any content coming into port 21
Ping scan of port 21