nerdexam
Juniper

JN0-1331 · Question #100

Click the Exhibit button. Referring to the network shown in the exhibit, a SYN flood attacks is initiated by an attacker that has a public IP address from ISP B within the 200.200.10.0/24 prefix…

The correct answer is B. ISP A should implement an ingress firewall filter on router R3 to discard traffic originating from the D. ISP B should implement an ingress firewall filter on the router R5 interface connecting to the. See the full explanation below for the reasoning.

Question

Click the Exhibit button. Referring to the network shown in the exhibit, a SYN flood attacks is initiated by an attacker that has a public IP address from ISP B within the 200.200.10.0/24 prefix. The attacker is sending SYN packets to the victim, connected to ISP A, with destination address of 100.100.31.78 using spoofed source addresses at random from the 192.168.0.0/16 prefix. Which two design best practices would prevent this attack from working? (Choose two.)

Exhibits

JN0-1331 question #100 exhibit 1
JN0-1331 question #100 exhibit 2

Options

  • AISP A should implement an ingress firewall filter on router R2 to discard traffic originating from the
  • BISP A should implement an ingress firewall filter on router R3 to discard traffic originating from the
  • CISP A should implement an ingress firewall filter on router R3 to discard traffic originating from the
  • DISP B should implement an ingress firewall filter on the router R5 interface connecting to the

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    80% (20)
  • C
    12% (3)

Community Discussion

No community discussion yet for this question.

Full JN0-1331 Practice