Juniper
JN0-541 · Question #59
You implement Traffic Anomaly detection and you find numerous alerts of port scans from your security auditing team that you want to ignore. You create an address book entry for the security audit…
The correct answer is B. Create a rule at the top of the Traffic Anomaly rulebase to ignore traffic from security audit team. See the full explanation below for the reasoning.
Question
You implement Traffic Anomaly detection and you find numerous alerts of port scans from your security auditing team that you want to ignore. You create an address book entry for the security audit team specifying the IP addresses of those machines. What should you do next?
Options
- ACreate a rule at the top of the Traffic Anomaly rule base to ignore traffic from security audit team,
- BCreate a rule at the top of the Traffic Anomaly rulebase to ignore traffic from security audit team.
- CCreate a rule at the top of the IDP rulebase to ignore traffic from security audit team, and make
- DCreate an exempt rule for the security audit team in the Exempt rulebase to ignore Traffic Anomalies.
How the community answered
(58 responses)- A3% (2)
- B72% (42)
- C9% (5)
- D16% (9)
Community Discussion
No community discussion yet for this question.