nerdexam
Juniper

JN0-533 · Question #51

A host in the untrust zone sends 1000 SYN packets in a single second to a host in your trust zone destined for port 80. Juniper JN0-533 Exam Referring to the exhibit, which statement describes the…

The correct answer is D. It will reply with SYN-ACK packets. See the full explanation below for the reasoning.

Question

A host in the untrust zone sends 1000 SYN packets in a single second to a host in your trust zone destined for port 80. Juniper JN0-533 Exam Referring to the exhibit, which statement describes the behavior of the ScreenOS device? ssg5-> get conf | include syn set zone untrust screen syn-flood attack-threshold 625 set zone untrust screen syn-flood alarm-threshold 250 set zone untrust screen syn-flood timeout 20 set zone untrust screen syn-flood queue-size 1000 set zone untrust screen syn-flood set flow syn-proxy syn-cookie

Options

  • AIt will maintain this state for all 1000 connection attempts.
  • BIt will begin to drop the SYN packets.
  • CIt will block further connection attempts from this host for 20 seconds.
  • DIt will reply with SYN-ACK packets.

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    16% (3)
  • C
    5% (1)
  • D
    74% (14)

Community Discussion

No community discussion yet for this question.

Full JN0-533 Practice