which threshold will the bot clients no longer be classified as malicious?

You are using the AppDoS feature to control against malicious bot client attacks. The bot
clients are using file downloads to attack your server farm. You have configured a context
value rate of 10,000 hits in 60 seconds. At which threshold will the bot clients no longer be
classified as malicious?

You are using the AppDoS feature to control against malicious bot client attacks. The bot
clients are using file downloads to attack your server farm. You have configured a context
value rate of 10,000 hits in 60 seconds. At which threshold will the bot clients no longer be
classified as malicious?

A.
9999 hits in 60 seconds

B.
7500 hits in 60 seconds

C.
5000 hits in 60 seconds

D.
8000 hits in 60 seconds



Leave a Reply 10

Your email address will not be published. Required fields are marked *


Anderson Carpejane

Anderson Carpejane

Answer correct is D

Mike

Mike

can you explain?

Mike

Mike

the question is about the botnet already specified as malicious and they want to know, when again he wont be considered malicious again…

then it depends on specified IDP action and/or IP-action. isn’t it?

pawel

pawel

“IDP also uses hysteresis for state transitions to avoid thrashing between the states. A default of 20% lower limit will be used from the configured connection and context thresholds for falling behind in state. For example. if you configure a context value-hit-rate-threshold of 10,000, IDP transitions from protocol analysis to bot client classification after 10000 hits in 60 seconds for identical context values, and falls behind in state only when such hits are smaller than 8000 in 60 seconds.”
Smaller, so B and C seem to be correct.

traffikator

traffikator

dude, questions asks for THRESHOLD value

Marta Perez

Marta Perez

Passed JN0-633 exam recently!

65 multiple choice questions, a little difficult to pass.

Pay close attention to questions on AppQoS, Routing (OSPF, BGP) in VPN (group, auto and hub-and-spoke), AppSecure, troubleshoot of IPSec, etc.

I learned valid JN0-633 dumps here:

http://www.passleader.com/jn0-633.html (209Q VCE and PDF)

Recommend to you!