nerdexam
Juniper

JN0-336 · Question #77

You administer a JSA host and want to include a rule that sets a threshold for excessive firewall denies and sends an SNMP trap after receiving related syslog messages from an SRX Series firewall…

The correct answer is B. offense. An offense rule in JSA is designed to aggregate multiple events or log entries based on specified criteria into a single offense, which can then trigger responses such as notifications or actions like sending an SNMP trap. This type of rule is well-suited for scenarios where…

Additional Security Services

Question

You administer a JSA host and want to include a rule that sets a threshold for excessive firewall denies and sends an SNMP trap after receiving related syslog messages from an SRX Series firewall. Which JSA rule type satisfies this requirement?

Options

  • Acommon
  • Boffense
  • Cflow
  • Devent

How the community answered

(30 responses)
  • A
    10% (3)
  • B
    80% (24)
  • C
    7% (2)
  • D
    3% (1)

Explanation

An offense rule in JSA is designed to aggregate multiple events or log entries based on specified criteria into a single offense, which can then trigger responses such as notifications or actions like sending an SNMP trap. This type of rule is well-suited for scenarios where you need to monitor for patterns or rates of events, such as excessive firewall denies, and take action when these exceed defined thresholds. Offense rules can analyze both event and flow data, making them highly versatile for comprehensive security monitoring.

Topics

#JSA#offense rule#SNMP trap#firewall deny threshold

Community Discussion

No community discussion yet for this question.

Full JN0-336 Practice