Juniper
JN0-632 · Question #39
An attacker from IP address 1.1.1.2 is filling your SRX Series device's session table with TCP sessions that have all completed a legitimate three-way handshake. What will help throttle the attack?
The correct answer is D. limit-session source-ip-based. See the full explanation below for the reasoning.
Question
An attacker from IP address 1.1.1.2 is filling your SRX Series device's session table with TCP sessions that have all completed a legitimate three-way handshake. What will help throttle the attack?
Options
- Asyn-flood destination-threshold
- Bsyn-ack-ack-proxy
- Climit-session destination-ip-based
- Dlimit-session source-ip-based
How the community answered
(34 responses)- A3% (1)
- B18% (6)
- C6% (2)
- D74% (25)
Community Discussion
No community discussion yet for this question.