You want to create a custom IDP signature for a new HTTP attack on your SRX device. You have
the exact string that identifies the attack. Which two additional elements do you need to define
your custom signature? (Choose two.)
A.
service context
B.
protocol number
C.
direction
D.
source IP address of the attacker
Explanation:
Reference: http://rtoodtoo.net/2011/09/22/how-to-write-srx-idp-custom-attacksignature/
Right answer : look at JIPS book chapter 5 page 20 :
custom signature terminology:
– service binding (application)
– pattern
– context
– direction
answer is A and C
juniper (or anyone else?) have the JIPS book in PDF format?