nerdexam
Juniper

JN0-633 · Question #86

Click the Exhibit button. [edit security] user@srx# show idp { idp-policy NewPolicy { rulebase-exempt { rule 1 { description AllowExternalRule; match { source-address any; destination-address } } }…

The correct answer is C. You must configure the IPS rulebase. See the full explanation below for the reasoning.

Question

Click the Exhibit button. [edit security] user@srx# show idp { idp-policy NewPolicy { rulebase-exempt { rule 1 { description AllowExternalRule; match { source-address any; destination-address } } } } } You are performing the initial IDP installation on your new SRX device. You have configured the IDP exempt rulebase as shown in the exhibit, but the commit is not successful. Referring to the exhibit, what solves the issue?

Options

  • AYou must configure the destination zone match.
  • BYou must configure the IPS exempt accept action.
  • CYou must configure the IPS rulebase.
  • DYou must configure the IPS engine flow action to ignore.

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    19% (5)
  • C
    70% (19)
  • D
    4% (1)

Community Discussion

No community discussion yet for this question.

Full JN0-633 Practice