ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 44 - JN0-636 discussion

Report
Export

Exhibit

You are using ATP Cloud and notice that there is a host with a high number of ETI and C&C hits sourced from the same investigation and notice that some of the events have not been automatically mitigated.

Referring to the exhibit, what is a reason for this behavior?

A.
The C&C events are false positives.
Answers
A.
The C&C events are false positives.
B.
The infected host score is globally set bellow a threat level of 5.
Answers
B.
The infected host score is globally set bellow a threat level of 5.
C.
The infected host score is globally set above a threat level of 5.
Answers
C.
The infected host score is globally set above a threat level of 5.
D.
The ETI events are false positives.
Answers
D.
The ETI events are false positives.
Suggested answer: C

Explanation:

According to the Juniper documentation, the infected host score is a global setting that determines the minimum threat level required for a host to be considered infected and blocked by Juniper ATP Cloud. The infected host score can be configured from 1 to 10, where 1 is the lowest and 10 is the highest. The default infected host score is 5, which means that any host with a threat level of 5 or higher will be automatically blocked by Juniper ATP Cloud. However, the infected host score can be changed to a higher value, such as 6 or 7, to reduce the number of false positives and allow more traffic to pass through. In the exhibit, the host has a threat level of 5, which indicates that it is infected with malware and has attempted to contact command-and-control servers. However, some of the events have not been automatically mitigated, which means that the host has not been blocked by Juniper ATP Cloud. A possible reason for this behavior is that the infected host score is globally set above a threat level of 5, such as 6 or 7, which means that the host does not meet the minimum threshold for blocking. Therefore, the correct answer is C. The infected host score is globally set above a threat level of 5. Reference: [Configuring the Infected Host Score] 1, [Compromised Hosts: More Information] 2

1: https://www.juniper.net/documentation/us/en/software/sky-atp/atp-cloud-userguide/topics/task/sky-atp-infected-host-score.html 2:

https://www.juniper.net/documentation/us/en/software/sky-atp/atp-cloud-userguide/topics/concept/sky-atp-infected-host-overview.html

asked 18/09/2024
Nelson Mira
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first