nerdexam
Check_Point

156-315.76 · Question #499

You are responsible for the IPS configuration of your Check Point firewall. Inside the Denial of service section you need to set the protection parameters against the Teardrop attack tool with high…

The correct answer is D. Some implementations of the TCP/IP IP fragmentation re-assembly code do not properly handle. See the full explanation below for the reasoning.

Question

You are responsible for the IPS configuration of your Check Point firewall. Inside the Denial of service section you need to set the protection parameters against the Teardrop attack tool with high severity. How would you characterize this attack tool? Give the BEST answer.

Exhibit

156-315.76 question #499 exhibit

Options

  • AHackers can send high volumes of non-TCP traffic in an effort to fill up a firewall State Table. This
  • BA remote attacker may attack a system by sending a specially crafted RPC request to execute
  • CSome implementations of TCP/IP are vulnerable to packets that are crafted in a particular way (a
  • DSome implementations of the TCP/IP IP fragmentation re-assembly code do not properly handle

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    12% (7)
  • D
    81% (47)

Community Discussion

No community discussion yet for this question.

Full 156-315.76 Practice