ExamGecko
Question list
Search
Search

List of questions

Search

Question 13 - JN0-335 discussion

Report
Export

On an SRX Series firewall, what are two ways that Encrypted Traffic Insights assess the threat of the traffic? (Choose two.)

A.
It decrypts the file in a sandbox.
Answers
A.
It decrypts the file in a sandbox.
B.
It validates the certificates used.
Answers
B.
It validates the certificates used.
C.
It decrypts the data to validate the hash.
Answers
C.
It decrypts the data to validate the hash.
D.
It reviews the timing and frequency of the connections.
Answers
D.
It reviews the timing and frequency of the connections.
Suggested answer: B, D

Explanation:

Encrypted Traffic Insights is a feature that enables the SRX Series firewall and the ATP Cloud to detect malicious threats that are hidden in encrypted traffic without decrypting the traffic. It does so by analyzing the metadata and connection patterns of the encrypted sessions. Two ways that Encrypted Traffic Insights assess the threat of the traffic are:

It validates the certificates used: The SRX Series firewall extracts the server certificate from the encrypted session and compares its signature with a blocklist of known malicious certificates provided by ATP Cloud. If there is a match, the session is blocked and reported as a threat.

It reviews the timing and frequency of the connections: The SRX Series firewall sends the connection details, such as source and destination IP addresses, ports, protocols, and timestamps, to ATP Cloud. ATP Cloud applies behavior analysis and machine learning algorithms to detect anomalous or suspicious patterns of connections, such as high frequency, low duration, or unusual timing.

asked 18/09/2024
Adam Vce
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first