Fortinet
NSE8_812 · Question #151
A company wants to protect against Denial of Service attacks and has launched a new project. They want to block DoS attacks that go above a certain threshold and for some others they are just trying…
The correct answer is B. config firewall DoS-policy edit 1 set status enable set interface "wan1" set srcaddr "all" set dstaddr "all" set service "ALL TCP" "ALL UDP" config anomaly edit "tcp_syn_flood" set status enable set log enable set action block set threshold 1000 next edit "udp_flood" set status enable set log enable set threshold 2000 next end. See the full explanation below for the reasoning.
Question
A company wants to protect against Denial of Service attacks and has launched a new project. They want to block DoS attacks that go above a certain threshold and for some others they are just trying to get a baseline of activity for those types of attacks so they are letting the traffic pass through without action. Given the following: - The interface to the Internet is on WAN1. - There is no requirement to specify which addresses are being protected or protected from. - The protected is to extend to all services. - The tcp_syn_flood attacks are to be recorded and blocked. - The udp_flood attacks are to be recorded but not blocked. - The tcp_syn_flood attack's threshold is to be changed from the default to 1000. The exhibit shows the current DoS-policy. Which policy will implement the project requirements?
Options
- Aconfig firewall DoS-policy edit 1 set status enable set interface "wan1" set srcaddr "all" set dstaddr "all" set service "ALL TCP" "ALL UDP" config anomaly edit "tcp_syn_flood" set status enable set log enable set action block set threshold 1000 next edit "udp_flood" set status enable set log enable set threshold 1000 next end
- Bconfig firewall DoS-policy edit 1 set status enable set interface "wan1" set srcaddr "all" set dstaddr "all" set service "ALL TCP" "ALL UDP" config anomaly edit "tcp_syn_flood" set status enable set log enable set action block set threshold 1000 next edit "udp_flood" set status enable set log enable set threshold 2000 next end
- Cconfig firewall DoS-policy edit 1 set status enable set interface "wan1" set srcaddr "all" set dstaddr "all" set service "ALL TCP" "ALL UDP" config anomaly edit "tcp_syn_flood" set status enable set log enable set action block set threshold 1000 next edit "udp_flood" set log enable set status enable set action block set threshold 1000 next end
- Dconfig firewall DoS-policy edit 1 set status enable set interface "wan1" set srcaddr "all" set dstaddr "all" set service "ALL TCP" "ALL UDP" config anomaly edit "tcp_syn_flood" set status enable set log enable set action block set threshold 2000 next edit "udp_flood" set status enable set log enable set threshold 2000 next end
How the community answered
(25 responses)- A4% (1)
- B76% (19)
- C8% (2)
- D12% (3)
Community Discussion
No community discussion yet for this question.