nerdexam
Juniper

JN0-635 · Question #9

Referring to the configuration shown in the exhibit, which statement explains why traffic matching the IDP signature DNS:OVERFLOW:TOO-LONG-TCP-MSG is not being stopped by the SRX Series device?

The correct answer is B. The IDP policy idp-pol1 is not configured as active. See the full explanation below for the reasoning.

Question

Referring to the configuration shown in the exhibit, which statement explains why traffic matching the IDP signature DNS:OVERFLOW:TOO-LONG-TCP-MSG is not being stopped by the SRX Series device?

Exhibit

JN0-635 question #9 exhibit

Options

  • AThe security policy dmz-pol1 has an action of permit.
  • BThe IDP policy idp-pol1 is not configured as active.
  • CThe IDP rule r2 has an ip-action value of notify.
  • DThe IDP rule r1 has an action of ignore-connection.

How the community answered

(19 responses)
  • A
    5% (1)
  • B
    79% (15)
  • C
    11% (2)
  • D
    5% (1)

Community Discussion

No community discussion yet for this question.

Full JN0-635 Practice