nerdexam
Check_Point

156-915.76 · Question #144

Multi-Corp wants to implement IKE DoS protection to prevent a denial-of-service (DoS) attack from paralyzing its VPN Communities. Jerry needs to minimize the performance impact of implementing this…

The correct answer is C. Set both "Support IKE DoS protection from identified source", and "Support IKE DoS protection. See the full explanation below for the reasoning.

Question

Multi-Corp wants to implement IKE DoS protection to prevent a denial-of-service (DoS) attack from paralyzing its VPN Communities. Jerry needs to minimize the performance impact of implementing this new protection. Which of the following configurations would BEST enable this new protection with minimal impact to the organization?

Options

  • ASet "Support IKE DoS protection from identified source" to "Puzzles", and "Support IKE DoS
  • BSet both "Support IKE Dos protection from identified source", and "Support IKE DoS protection
  • CSet both "Support IKE DoS protection from identified source", and "Support IKE DoS protection
  • DSet "Support IKE DoS protection from identified source" to "Stateless", and "Support IKE DoS

How the community answered

(17 responses)
  • A
    6% (1)
  • B
    12% (2)
  • C
    76% (13)
  • D
    6% (1)

Community Discussion

No community discussion yet for this question.

Full 156-915.76 Practice