Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 12 Question 105 Discussion

Refer to the exhibit.An engineer must tune the Cisco IOS device to mitigate an attack that is broadcasting a large number of ICMP packets. The attack is sending the victim's spoofed source IP to a network using an IP broadcast address that causes devices in the network to respond back to the source IP address. Which action does the engineer recommend?
A) Use command ip verify reverse-path interface
B) Use global configuration command service tcp-keepalives-out
C) Use subinterface command no ip directed-broadcast
D) Use logging trap 6

Cisco 350-201 Exam - Topic 12 Question 105 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 105
Topic #: 12
[All 350-201 Questions]

Refer to the exhibit.

An engineer must tune the Cisco IOS device to mitigate an attack that is broadcasting a large number of ICMP packets. The attack is sending the victim's spoofed source IP to a network using an IP broadcast address that causes devices in the network to respond back to the source IP address. Which action does the engineer recommend?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Annabelle
9 months ago
I’m not sure about that, C seems too simplistic for such a complex attack.
upvoted 0 times
...
Catalina
9 months ago
No way, option D is the way to go for logging issues!
upvoted 0 times
...
Jamal
10 months ago
Surprised that people still use directed broadcasts in 2023!
upvoted 0 times
...
Annmarie
10 months ago
I think option A could help too, but not as effective as C.
upvoted 0 times
...
My
10 months ago
Definitely go with option C, it’s the best way to stop those broadcasts.
upvoted 0 times
...
Ty
10 months ago
I was leaning towards A as well, but I remember something about logging traps being useful in monitoring attacks. It's a bit confusing!
upvoted 0 times
...
Stephaine
11 months ago
I recall that directed broadcasts can cause issues, so C makes sense, but I wonder if there are other configurations that could help too.
upvoted 0 times
...
Ngoc
11 months ago
I'm not entirely sure, but I feel like option A could also be relevant. The reverse-path verification seems like it could help with spoofed IPs.
upvoted 0 times
...
Brice
11 months ago
I think the right answer might be C, using the no ip directed-broadcast command. I remember it being mentioned in a similar practice question about mitigating broadcast storms.
upvoted 0 times
...
Scot
11 months ago
I'm not too familiar with the "service tcp-keepalives-out" command in option B, so I'm not sure how that would help mitigate the ICMP packet attack. I think I'll have to rule that one out and focus on the other options.
upvoted 0 times
...
Abel
11 months ago
Okay, I've got it! The attack is using broadcast addresses to cause devices to respond to the spoofed source IP, so disabling directed broadcasts with the "no ip directed-broadcast" command in option C seems like the right move. I'm confident that's the best solution here.
upvoted 0 times
...
Felix
11 months ago
Hmm, I'm a bit confused here. The question mentions spoofed source IP addresses, so I'm not sure if the "ip verify reverse-path" command in option A would be the best approach. I'll need to think this through a bit more.
upvoted 0 times
...
Albina
11 months ago
This looks like a tricky one, but I think the key is to focus on mitigating the ICMP packet attack. I'm leaning towards option C - using the "no ip directed-broadcast" command to disable directed broadcasts on the subinterface.
upvoted 0 times
...
Nadine
1 year ago
I bet the engineer's next recommendation is to just unplug the router and hope the problem goes away. Problem solved!
upvoted 0 times
Valentin
1 year ago
C) Good point, that would definitely help mitigate the attack
upvoted 0 times
...
Lai
1 year ago
B) That might help, but I think the engineer should also consider using subinterface command no ip directed-broadcast
upvoted 0 times
...
Gerri
1 year ago
A) Use command ip verify reverse-path interface
upvoted 0 times
...
...
Nettie
1 year ago
Option A seems promising, but I'm not sure it's the complete solution. Verifying reverse-path forwarding is a good start, but we might need to do more.
upvoted 0 times
Dick
1 year ago
User 2: I agree, we should consider other options as well to fully protect the network.
upvoted 0 times
...
Rosann
1 year ago
User 1: Option A is a good start, but we might need to do more to mitigate the attack.
upvoted 0 times
...
...
Deeanna
1 year ago
Haha, Option D is a classic! Logging everything at level 6 is definitely not the way to go. Way too much data!
upvoted 0 times
...
Malcolm
1 year ago
I'm not sure Option B is relevant here. Enabling TCP keepalives doesn't seem to address the ICMP flooding issue.
upvoted 0 times
...
Hillary
1 year ago
Option C looks like the right choice here. Disabling IP directed broadcasts on the subinterface should help mitigate the attack.
upvoted 0 times
Shaquana
1 year ago
Let's implement the recommended solution and monitor the network for any improvements.
upvoted 0 times
...
Maryann
1 year ago
It's important to take action quickly to mitigate the impact of the attack.
upvoted 0 times
...
Louisa
1 year ago
Disabling IP directed broadcasts on the subinterface will definitely help in this situation.
upvoted 0 times
...
Annelle
1 year ago
I agree, option C is the best choice to prevent the attack.
upvoted 0 times
...
...
Hyun
1 year ago
I'm not sure, but I think option C could also be a good choice to prevent the attack.
upvoted 0 times
...
Honey
1 year ago
I agree with Alecia, that option makes sense to mitigate the attack.
upvoted 0 times
...
Alecia
1 year ago
I think the engineer should recommend using command ip verify reverse-path interface.
upvoted 0 times
...

Save Cancel