ExamGecko
Question list
Search
Search

List of questions

Search

Question 27 - JN0-335 discussion

Report
Export

A client has attempted communication with a known command-and-control server and it has reached the configured threat level threshold.

Which feed will the clients IP address be automatically added to in this situation?

A.
the command-and-control cloud feed
Answers
A.
the command-and-control cloud feed
B.
the allowlist and blocklist feed
Answers
B.
the allowlist and blocklist feed
C.
the custom cloud feed
Answers
C.
the custom cloud feed
D.
the infected host cloud feed
Answers
D.
the infected host cloud feed
Suggested answer: D

Explanation:

Infected hosts are internal hosts that have been compromised by malware and are communicating with external C&C servers3.Juniper ATP Cloud provides infected host feeds that list internal IP addresses or subnets of infected hosts along with a threat level3.Once the Juniper ATP Cloud global threshold for an infected host is met, that host is added to the infected host feed and assigned a threat level of 10 by the cloud4.You can also configure your SRX Series device to block traffic from these IP addresses using security policies4.

asked 18/09/2024
Arash Farivarmoheb
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first