JN0-1331 · Question #100
Click the Exhibit button. Referring to the network shown in the exhibit, a SYN flood attacks is initiated by an attacker that has a public IP address from ISP B within the 200.200.10.0/24 prefix…
The correct answer is B. ISP A should implement an ingress firewall filter on router R3 to discard traffic originating from the D. ISP B should implement an ingress firewall filter on the router R5 interface connecting to the. See the full explanation below for the reasoning.
Question
Click the Exhibit button. Referring to the network shown in the exhibit, a SYN flood attacks is initiated by an attacker that has a public IP address from ISP B within the 200.200.10.0/24 prefix. The attacker is sending SYN packets to the victim, connected to ISP A, with destination address of 100.100.31.78 using spoofed source addresses at random from the 192.168.0.0/16 prefix. Which two design best practices would prevent this attack from working? (Choose two.)
Exhibits
Options
- AISP A should implement an ingress firewall filter on router R2 to discard traffic originating from the
- BISP A should implement an ingress firewall filter on router R3 to discard traffic originating from the
- CISP A should implement an ingress firewall filter on router R3 to discard traffic originating from the
- DISP B should implement an ingress firewall filter on the router R5 interface connecting to the
How the community answered
(25 responses)- A8% (2)
- B80% (20)
- C12% (3)
Community Discussion
No community discussion yet for this question.

