Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam JN0-635 All Questions

View all questions & answers for the JN0-635 exam

Exam JN0-635 topic 1 question 2 discussion

Actual exam question from Juniper's JN0-635
Question #: 2
Topic #: 1
[All JN0-635 Questions]

Click the Exhibit button.

You have recently committed the IPS policy shown in the exhibit. When evaluating the expected behavior, you notice that you have a session that matches all the rules in your IPS policy.
In this scenario, which action would be taken?

  • A. drop packet
  • B. no-action
  • C. close-client-and-server
  • D. ignore-connection
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-idp-policy-rules-and-rulebases.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
M_Za
1 year, 4 months ago
C. close-client-and-server if not terminate flagged then When traffic matches multiple rules, the most severe IP action of all matched rules is applied. The most severe IP action is the Close Session action, the next in severity is the Drop/Block Session action, and then the Notify action. (no-action)
upvoted 1 times
...
joseph267
2 years, 7 months ago
Since traffic matches all rules it will be dropped by the first rule Answer - no action
upvoted 1 times
...
CiscoTest
2 years, 10 months ago
Ignore-Connection means the traffic will be permitted, but also that the IPS engine will ignore the rest of the connection and will not process it at all. This is useful for identifying connections (e.g., custom applications) that you do not want to inspect. After a session has been marked Ignore-Connection, the IPS engine will not process it. It’s important to keep that in mind, because an attack could be present later in the connection, but the IPS would not see it. If you only want to ignore a specific attack, but not ignore the rest of the connection, either put that attack in the Exempt rulebase (recommended) or configure the rule with No-Action. Correct response is D
upvoted 2 times
...
ashampoo1992
3 years ago
answer D is correct
upvoted 1 times
...
nickanme
3 years, 1 month ago
steps after ignore-connection will not be matched
upvoted 1 times
...
nickanme
3 years, 1 month ago
example: https://www.juniper.net/documentation/us/en/software/junos/idp-policy/topics/topic-map/security-idp-policies-overview.html#id-idp-policy-selection-for-unified-policies__d30629e398
upvoted 1 times
...
nickanme
3 years, 1 month ago
"A rulebase is an ordered set of rules that use a specific detection method to identify and prevent attacks. When traffic matches multiple rules, the most severe IP action of all matched rules is applied. The most severe IP action is the Close Session action, the next in severity is the Drop/Block Session action, and then the Notify action."
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...