ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 41 - JN0-636 discussion

Report
Export

You want to enforce I DP policies on HTTP traffic.

In this scenario, which two actions must be performed on your SRX Series device? (Choose two )

A.
Choose an attacks type in the predefined-attacks-group HTTP-All.
Answers
A.
Choose an attacks type in the predefined-attacks-group HTTP-All.
B.
Disable screen options on the Untrust zone.
Answers
B.
Disable screen options on the Untrust zone.
C.
Specify an action of None.
Answers
C.
Specify an action of None.
D.
Match on application junos-http.
Answers
D.
Match on application junos-http.
Suggested answer: A, D

Explanation:

To enforce IDP policies on HTTP traffic on an SRX Series device, the following actions must be performed:

Choose an attacks type in the predefined-attacks-group HTTP-All: This allows the SRX Series device to match on specific types of attacks that can occur within HTTP traffic. For example, it can match on SQL injection or cross-site scripting (XSS) attacks.

Match on application junos-http: This allows the SRX Series device to match on HTTP traffic specifically, as opposed to other types of traffic. It is necessary to properly identify the traffic that needs to be protected.

Disabling screen options on the Untrust zone and specifying an action of None are not necessary to enforce IDP policies on HTTP traffic. The first one is a feature used to prevent certain types of attacks, the second one is used to take no action in case of a match.

asked 18/09/2024
Naing Thet
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first