Juniper
JN0-635 · Question #9
Referring to the configuration shown in the exhibit, which statement explains why traffic matching the IDP signature DNS:OVERFLOW:TOO-LONG-TCP-MSG is not being stopped by the SRX Series device?
The correct answer is B. The IDP policy idp-pol1 is not configured as active. See the full explanation below for the reasoning.
Question
Referring to the configuration shown in the exhibit, which statement explains why traffic matching the IDP signature DNS:OVERFLOW:TOO-LONG-TCP-MSG is not being stopped by the SRX Series device?
Exhibit
Options
- AThe security policy dmz-pol1 has an action of permit.
- BThe IDP policy idp-pol1 is not configured as active.
- CThe IDP rule r2 has an ip-action value of notify.
- DThe IDP rule r1 has an action of ignore-connection.
How the community answered
(19 responses)- A5% (1)
- B79% (15)
- C11% (2)
- D5% (1)
Community Discussion
No community discussion yet for this question.
