ExamGecko
Question list
Search
Search

List of questions

Search

Question 88 - JN0-335 discussion

Report
Export

Which two statements are correct when considering IPS rule base evaluation? (Choose two.)

A.
IPS evaluates rules concurrently.
Answers
A.
IPS evaluates rules concurrently.
B.
IPS applies the most severe action to traffic matching multiple rules,
Answers
B.
IPS applies the most severe action to traffic matching multiple rules,
C.
IPS evaluates rules sequentially
Answers
C.
IPS evaluates rules sequentially
D.
IPS applies the least severe action to traffic matching multiple rules.
Answers
D.
IPS applies the least severe action to traffic matching multiple rules.
Suggested answer: A, B

Explanation:

The Intrusion Prevention System (IPS) is a feature that provides protection against network-based threats. The IPS uses a rule base to evaluate network traffic and apply actions based on the rules that match the traffic.

When evaluating the rule base, the IPS evaluates the rules concurrently (option A). This means that the IPS can apply multiple rules to the same traffic simultaneously.

If multiple rules match the same traffic, the IPS applies the most severe action (option B). This means that if there are conflicting actions specified in different rules, the IPS will apply the action that has the highest severity. For example, if one rule specifies a 'drop' action and another rule specifies a 'log' action for the same traffic, the IPS will drop the traffic because dropping has a higher severity than logging.

asked 18/09/2024
Robert Miletich
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first