Click the Exhibit button.

Which two statements describe the output shown in the exhibit? (Choose two.)
Correct Answer: A,D
Explanation
Encrypted Traffic Insights is a feature of Juniper ATP Cloud and SRX Series firewalls that can detect malicious threats that are hidden in encrypted traffic without intercepting and decrypting the traffic. It permits organizations greater visibility and policy control over encrypted traffic, without requiring resource-intensive SSL Decryption1.
Encrypted Traffic Insights assesses the threat of the traffic by using two methods:
It validates the certificates used by the external servers that the internal hosts are trying to connect to. It compares the certificate signatures with a blocklist of known malicious certificates and also checks the certificate validity, issuer, and subject. If the certificate is invalid or matches a malicious signature, the connection is blocked or alerted2.
It reviews the timing and frequency of the connections to the external servers. It uses behavior analysis and machine learning to identify patterns and anomalies that indicate malicious activity, such as command and control (C&C) communications, botnet traffic, or data exfiltration. It also uses threat intelligence feeds to enrich the analysis and provide additional context2.
Encrypted Traffic Insights does not decrypt the file or the data in a sandbox or to validate the hash, as these methods would require breaking the encryption of the traffic, which would violate data privacy laws and introduce latency and performance issues21. References:
3: SRX5400, SRX5600, SRX5800 Firewalls Datasheet - Juniper Networks
2: Encrypted Traffic Insights Overview and Benefits | ATP Cloud | Juniper ...
1: Juniper Networks Expands Connected Security Portfolio with Encrypted ...