Juniper
JN0-533 · Question #51
A host in the untrust zone sends 1000 SYN packets in a single second to a host in your trust zone destined for port 80. Juniper JN0-533 Exam Referring to the exhibit, which statement describes the…
The correct answer is D. It will reply with SYN-ACK packets. See the full explanation below for the reasoning.
Question
A host in the untrust zone sends 1000 SYN packets in a single second to a host in your trust zone destined for port 80. Juniper JN0-533 Exam Referring to the exhibit, which statement describes the behavior of the ScreenOS device? ssg5-> get conf | include syn set zone untrust screen syn-flood attack-threshold 625 set zone untrust screen syn-flood alarm-threshold 250 set zone untrust screen syn-flood timeout 20 set zone untrust screen syn-flood queue-size 1000 set zone untrust screen syn-flood set flow syn-proxy syn-cookie
Options
- AIt will maintain this state for all 1000 connection attempts.
- BIt will begin to drop the SYN packets.
- CIt will block further connection attempts from this host for 20 seconds.
- DIt will reply with SYN-ACK packets.
How the community answered
(19 responses)- A5% (1)
- B16% (3)
- C5% (1)
- D74% (14)
Community Discussion
No community discussion yet for this question.