Chapter Review Questions
Which is true regarding the DDoS prevention feature?
The feature is off by default
The feature is on by default with aggressive policers
The feature is on by default but requires policer configuration before any alerts or policing can occur
The feature is on by default with high policer rates that in most cases exceed system control plane capacity to ensure no disruption to existing functionality
Which is true about DDoS policers and RE protection policers evoked though a filter?
The lo0 policer is disabled when DDoS is in effect
The DDoS policers run first with the lo0 policer executed last
The lo0 policer is executed before and after the DDoS policers, once at ingress and again in the RE
Combining lo0 and DDoS policers is not permitted and a commit error is retuned
A strong RE protection filter should end with which of the following?
An accept all to ensure no disruption
A reject all, to send error messages to sources of traffic that is not permitted
A discard all to silently discard traffic that is not permitted
A log action to help debug filtering of valid/permitted services
Both C and D
A filter is applied to the main instance lo0.0 and a VRF is defined without its own lo0.n ifl. Which is true?
Traffic from the instance to the local control plane is filtered by the lo0.0 filter
Traffic from the instance to remote VRF destinations is filtered by the lo0.0 filter
Traffic from the instance to the local control plane is not filtered
None of the above. VRFs require a lo0.n ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access