JN0-633 · Question #66
[edit security] user@srx# show idp ... application-ddos Webserver { service http; connection-rate-threshold 1000; context http-get-url { hit-rate-threshold 60000; value-hit-rate-threshold 30000…
The correct answer is A. The approved traffic results in 50,000 HTTP GET requests per minute. D. The IDP action is still in effect due to the timeout configuration. swconfig-security/appddos-protection-overview.html swconfig-security/appddos-proctecting-against.html#appddos-proctecting-against
Question
[edit security] user@srx# show idp ... application-ddos Webserver { service http; connection-rate-threshold 1000; context http-get-url { hit-rate-threshold 60000; value-hit-rate-threshold 30000; time-binding-count 10; time-binding-period 25; } } You are using AppDoS to protect your network against a bot attack, but noticed an approved application has falsely triggered the configured IDP action of drop. You adjusted your AppDoS configuration as shown in the exhibit. However, the approved traffic is still dropped. What are two reasons for this behavior? (Choose two.)
Options
- AThe approved traffic results in 50,000 HTTP GET requests per minute.
- BThe approved traffic results in 25 HTTP GET requests within 10 seconds from a single host.
- CThe active IDP policy has not been defined in the security configuration.
- DThe IDP action is still in effect due to the timeout configuration.
How the community answered
(27 responses)- A85% (23)
- B4% (1)
- C11% (3)
Explanation
swconfig-security/appddos-protection-overview.html swconfig-security/appddos-proctecting-against.html#appddos-proctecting-against
Topics
Community Discussion
No community discussion yet for this question.