nerdexam
Juniper

JN0-632 · Question #151

A security alert has been issued for an application running on your network that exploits a buffer overflow to compromise the application. The security alert specifies that client-to-server…

The correct answer is A. A signature attack object for each of the specified strings. See the full explanation below for the reasoning.

Question

A security alert has been issued for an application running on your network that exploits a buffer overflow to compromise the application. The security alert specifies that client-to-server communication will contain the string "*~\hack-man?" or the string "\back*?/hat". Which type of IPS custom signature is required to block the traffic?

Options

  • AA signature attack object for each of the specified strings
  • BA compound attack object
  • CA protocol anomaly attack object
  • DA regular expression matching the identified strings

How the community answered

(15 responses)
  • A
    73% (11)
  • B
    13% (2)
  • C
    7% (1)
  • D
    7% (1)

Community Discussion

No community discussion yet for this question.

Full JN0-632 Practice