Valid 350-501 Dumps shared by ExamDiscuss.com for Helping Passing 350-501 Exam! ExamDiscuss.com now offer the newest 350-501 exam dumps, the ExamDiscuss.com 350-501 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com 350-501 dumps with Test Engine here:
Refer to the exihibit. Refer to the exhbit. ISP A has a BGP peering with ISP C with the maximum-prefix 150 configuration on R1. After a recent security breach on the ISP A network, a network engineer has been asked to enable a lightweight security mechanism to protect the R1 CPU and BGP membership from spoofing attacks. Which solution must ISP A implement?
Correct Answer: D
The Time to Live (TTL) security mechanism is a lightweight security feature that can protect against CPU and memory resource exhaustion due to a denial-of-service (DoS) attack. It works by setting a limit on the number of hops (TTL value) that BGP packets can traverse. By configuring neighbor 10.163.83.55 ttl-security hops 2, ISP A ensures that BGP packets received from ISP C must have a TTL value of at least 254 when they reach R1, as BGP packets decrement the TTL by 1 with each hop. This effectively prevents spoofing attacks from outside the directly connected network because any packets spoofed from further away would have a TTL that drops below the threshold before reaching R1.