Cisco
300-440 · Question #60
Refer to the exhibit. The policy has failed to stop DOS attacks from within the service VPN 100. The counter shows no logб but the destination network reported DOS attacks from network 10.10.0.0/16…
The correct answer is B. The policy direction must run from-tunnel rather than from-service. The policy direction should be from-tunnel instead of from-service to block inbound traffic from the SD-WAN fabric, which is where the DOS attacks are originating.
Operation
Question
Refer to the exhibit. The policy has failed to stop DOS attacks from within the service VPN 100. The counter shows no logб but the destination network reported DOS attacks from network 10.10.0.0/16. The engineer identified a misconfigured policy. Which setting is the source of the issue?
Exhibit
Options
- A"Echo-reply" must be matched instead of icmp-msg in protocol 1.
- BThe policy direction must run from-tunnel rather than from-service.
- CProtocol 1 must be completely blocked with all its options.
- D"Echo" must be matched rather than icmp-msg in protocol 1.
How the community answered
(25 responses)- A8% (2)
- B68% (17)
- C20% (5)
- D4% (1)
Explanation
The policy direction should be from-tunnel instead of from-service to block inbound traffic from the SD-WAN fabric, which is where the DOS attacks are originating.
Topics
#SD-WAN data policy#DoS prevention#service VPN#policy direction
Community Discussion
No community discussion yet for this question.
