Click the Exhibit button
Referring to the configuration shown in the exhibit, which statement explains why traffic matching the IDP signature DNS :OVERFLOW:TOO-LONGTCP-MSG is not being stopped by the SRX Series device?
A. The security policy dmz-pol1 has an action of permit.
B. The IDP policy idp-pol1 is not configured as active.
C. The IDP rule r2 has an ip-action value of notify.
D. The IDP rule rl has an action of ignore-connection.
Junos OS allows you to configure multiple IDP policies, but a device can have only one active IDP policy at a time.
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-idp-policies-overview.html
set security idp active-policy