nerdexam
Juniper

JN0-632 · Question #111

A security alert has been issued for an application running on your network that exploits a buffer overflow to compromise the application. The security alert specifies that initial client-to-server…

The correct answer is B. a compound attack object. See the full explanation below for the reasoning.

Question

A security alert has been issued for an application running on your network that exploits a buffer overflow to compromise the application. The security alert specifies that initial client-to-server communication will contain the string "~\hack-app", followed by the string "&&-phase-2//" or the string "\bad\7string". Which type of IPS custom signature is required to block the traffic?

Options

  • Aa signature attack object for each of the specified strings
  • Ba compound attack object
  • Ca protocol anomaly attack object
  • Da regular expression matching the identified strings

How the community answered

(28 responses)
  • A
    7% (2)
  • B
    71% (20)
  • C
    4% (1)
  • D
    18% (5)

Community Discussion

No community discussion yet for this question.

Full JN0-632 Practice