PrepAway - Latest Free Exam Questions & Answers

Which of the following ACLs provides the BEST protection against the above attack and any further attacks from

A security analyst is reviewing the following packet capture of an attack directed at a company’s server
located in the DMZ:Which of the following ACLs provides the BEST protection against the above attack and any further
attacks from the same IP, while minimizing service interruption?

PrepAway - Latest Free Exam Questions & Answers

A.
DENY TCO From ANY to 172.31.64.4

B.
Deny UDP from 192.168.1.0/24 to 172.31.67.0/24

C.
Deny IP from 192.168.1.10/32 to 0.0.0.0/0

D.
Deny TCP from 192.168.1.10 to 172.31.67.4

8 Comments on “Which of the following ACLs provides the BEST protection against the above attack and any further attacks from

    1. Dugan Nash says:

      I think the clue that points to TCP is “Flags[S]” It looks like the attacker is sending SYN packets to the server and finds out what ports are open when/if they respond with a SYN/ACK.




      2



      0
  1. Black says:

    For me best answer is C, because the question says “any further attacks from the same IP”.
    If you don’t use ACL in C, the attacker can start trying other IP address on the network.




    2



    0

Leave a Reply