nerdexam
Juniper

JN0-336 · Question #84

Click the Exhibit button. You are asked to create a security policy that will automatically add infected hosts to the infected hosts feed and block further communication through the SRX Series…

The correct answer is A. Add a security intelligence policy to the permit portion of the security policy. To create a security policy that will automatically add infected hosts to the infected hosts feed and block further communication through the SRX Series device, you need to add a security intelligence policy to the permit portion of the security policy. A security intelligence…

Juniper Advanced Threat Prevention (ATP)

Question

Click the Exhibit button. You are asked to create a security policy that will automatically add infected hosts to the infected hosts feed and block further communication through the SRX Series device. What needs to be added to this configuration to complete this task?

Options

  • AAdd a security intelligence policy to the permit portion of the security policy.
  • BAdd an action to the permit portion of the security policy.
  • CAdd logging to the permit portion of the security policy.
  • DAdd a match rule to the security policy with an appropriate threat level.

How the community answered

(43 responses)
  • A
    81% (35)
  • B
    12% (5)
  • C
    5% (2)
  • D
    2% (1)

Explanation

To create a security policy that will automatically add infected hosts to the infected hosts feed and block further communication through the SRX Series device, you need to add a security intelligence policy to the permit portion of the security policy. A security intelligence policy is a policy that allows you to block or monitor traffic from malicious sources based on threat intelligence feeds from Juniper ATP Cloud or other providers. One of the feeds that you can use is the Infected-Hosts feed, which contains IP addresses of hosts that are infected with malware and communicate with command-and-control servers. You can create a profile and a rule for the Infected-Hosts feed and specify the threat level and the action to take for the infected hosts. Then, you can link the security intelligence policy with the firewall policy and apply it to the traffic that you want to protect. Reference: = Security Intelligence Overview, Configuring Security Intelligence Policy, Configure the Security Intelligence Policy on the SRX Series

Topics

#security intelligence policy#infected hosts feed#security policy action#ATP integration

Community Discussion

No community discussion yet for this question.

Full JN0-336 Practice