PrepAway - Latest Free Exam Questions & Answers

which threshold will the bot clients no longer be classified as malicious?

You are using the AppDoS feature to control against malicious bot client attacks. The bot
clients are using file downloads to attack your server farm. You have configured a context
value rate of 10,000 hits in 60 seconds. At which threshold will the bot clients no longer be
classified as malicious?

PrepAway - Latest Free Exam Questions & Answers

A.
9999 hits in 60 seconds

B.
7500 hits in 60 seconds

C.
5000 hits in 60 seconds

D.
8000 hits in 60 seconds

10 Comments on “which threshold will the bot clients no longer be classified as malicious?

      1. Mike says:

        the question is about the botnet already specified as malicious and they want to know, when again he wont be considered malicious again…

        then it depends on specified IDP action and/or IP-action. isn’t it?




        0



        0
  1. pawel says:

    “IDP also uses hysteresis for state transitions to avoid thrashing between the states. A default of 20% lower limit will be used from the configured connection and context thresholds for falling behind in state. For example. if you configure a context value-hit-rate-threshold of 10,000, IDP transitions from protocol analysis to bot client classification after 10000 hits in 60 seconds for identical context values, and falls behind in state only when such hits are smaller than 8000 in 60 seconds.”
    Smaller, so B and C seem to be correct.




    0



    0

Leave a Reply