nerdexam
F5

303 · Question #93

An LTM Specialist has detected that a brute force login attack is occurring against the SSH service via a BIG-IP management interface. Login attempts are occurring from many IPs within the internal…

The correct answer is C. modify/sys allow replace-all-with {''192.168.1.00/24'', ''192.16.254.0/23''}. Select C to overwrite the existing network's allow configuration over the specified network

Integration and Security

Question

An LTM Specialist has detected that a brute force login attack is occurring against the SSH service via a BIG-IP management interface. Login attempts are occurring from many IPs within the internal company network. BIG-IP SSH access restrictions are in place as follows:

The LTM Specialist has determined that SSH access should only occur from the 192.168.1.0/24 and 172.16.254.0/23 networks. Which tmsh command should the LTM Specialist use to permit access from the desired networks only?

Options

  • Amodify.sys sshd allow add {''192.168. 10/24 , '' ''172. 16 2540/23'')
  • Bmodify /sys sshd login disable (''10.0.00/8'', ''172 16.0 0/12'', ''192. 168.0.0/16'')
  • Cmodify/sys allow replace-all-with {''192.168.1.00/24'', ''192.16.254.0/23''}
  • Dmodify/sys sshd login enable {''192.166.10/24'''' ''172.16 254 0/23

How the community answered

(61 responses)
  • A
    2% (1)
  • B
    8% (5)
  • C
    85% (52)
  • D
    5% (3)

Explanation

Select C to overwrite the existing network's allow configuration over the specified network

Topics

#SSH access control#brute force mitigation#tmsh command#network ACL

Community Discussion

No community discussion yet for this question.

Full 303 Practice