JN0-336 · Question #83
Which two statements are correct about the Junos IPS feature? (Choose two.)
The correct answer is A. IPS is integrated as a security service on SRX Series devices. D. IPS uses protocol anomaly rules to detect unknown attacks. Junos IPS is a feature that provides intrusion prevention and detection services on SRX Series devices. It monitors network traffic and compares it against predefined signatures or custom rules to identify and block malicious or unwanted packets. Two statements that are correct…
Question
Which two statements are correct about the Junos IPS feature? (Choose two.)
Options
- AIPS is integrated as a security service on SRX Series devices.
- BIPS uses sandboxing to detect unknown attacks.
- CIPS is a standalone platform running on dedicated hardware or as a virtual device.
- DIPS uses protocol anomaly rules to detect unknown attacks.
How the community answered
(58 responses)- A95% (55)
- B3% (2)
- C2% (1)
Explanation
Junos IPS is a feature that provides intrusion prevention and detection services on SRX Series devices. It monitors network traffic and compares it against predefined signatures or custom rules to identify and block malicious or unwanted packets. Two statements that are correct about the Junos IPS feature are: IPS is integrated as a security service on SRX Series devices: Junos IPS is not a separate platform or device, but a security service that runs on SRX Series firewalls. It can be enabled and configured as part of the security policy on the SRX Series device and applied to specific zones, interfaces, or traffic flows. IPS uses protocol anomaly rules to detect unknown attacks: Junos IPS uses two types of rules to detect attacks: signature rules and protocol anomaly rules. Signature rules match traffic against known attack patterns or signatures and block them based on predefined actions. Protocol anomaly rules detect deviations from the expected behavior or structure of common protocols, such as TCP, UDP, ICMP, etc. Protocol anomaly rules can help identify unknown or zero-day attacks that may not have a signature yet. Intrusion Detection and Prevention for SRX Series Devices, Understanding Signature Rules and Protocol Anomaly Rules
Topics
Community Discussion
No community discussion yet for this question.