nerdexam
Fortinet

NSE8_810 · Question #25

Click the Exhibit button. The exhibit shows the configuration of a service protection profile (SPP) in a FortiDDoS device. Which two statements are true about the traffic matching being inspected by…

The correct answer is A. Traffic that does not match any SPP policy will be inspected by this SPP. B. FortiDDoS will not send a SYN/ACK if a SYN packet is coming from an IP address that is not in the legitimate IP (LIP) address table. Explanation/Reference:

Advanced Threat Protection and Content Inspection

Question

Click the Exhibit button. The exhibit shows the configuration of a service protection profile (SPP) in a FortiDDoS device. Which two statements are true about the traffic matching being inspected by this SPP? (Choose two.)

Exhibit

NSE8_810 question #25 exhibit

Options

  • ATraffic that does not match any SPP policy will be inspected by this SPP.
  • BFortiDDoS will not send a SYN/ACK if a SYN packet is coming from an IP address that is not in the legitimate IP (LIP) address table.
  • CFortiDDoS will start dropping packets as soon as the traffic exceeds the configured minimum threshold.
  • DSYN packets with payloads will be dropped.

How the community answered

(35 responses)
  • A
    74% (26)
  • C
    9% (3)
  • D
    17% (6)

Explanation

Explanation/Reference:

Topics

#FortiDDoS#SPP configuration#SYN flood protection#LIP table

Community Discussion

No community discussion yet for this question.

Full NSE8_810 Practice