Fortinet
NSE8_810 · Question #25
Click the Exhibit button. The exhibit shows the configuration of a service protection profile (SPP) in a FortiDDoS device. Which two statements are true about the traffic matching being inspected by…
The correct answer is A. Traffic that does not match any SPP policy will be inspected by this SPP. B. FortiDDoS will not send a SYN/ACK if a SYN packet is coming from an IP address that is not in the legitimate IP (LIP) address table. Explanation/Reference:
Advanced Threat Protection and Content Inspection
Question
Click the Exhibit button. The exhibit shows the configuration of a service protection profile (SPP) in a FortiDDoS device. Which two statements are true about the traffic matching being inspected by this SPP? (Choose two.)
Exhibit
Options
- ATraffic that does not match any SPP policy will be inspected by this SPP.
- BFortiDDoS will not send a SYN/ACK if a SYN packet is coming from an IP address that is not in the legitimate IP (LIP) address table.
- CFortiDDoS will start dropping packets as soon as the traffic exceeds the configured minimum threshold.
- DSYN packets with payloads will be dropped.
How the community answered
(35 responses)- A74% (26)
- C9% (3)
- D17% (6)
Explanation
Explanation/Reference:
Topics
#FortiDDoS#SPP configuration#SYN flood protection#LIP table
Community Discussion
No community discussion yet for this question.
