nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #167

An administrator has configured a Security policy where the matching condition includes a single application, and the action is deny. If the application's default deny action is reset-both, what…

The correct answer is D. It sends a TCP reset to the client-side and server-side devices. The default deny action for an application can be set to one of three options: - Silently drop the traffic. - Send a TCP reset to the server-side device. - Send a TCP reset to both the client-side and server-side devices. In this case, the default deny action for the…

Security Policy Configuration

Question

An administrator has configured a Security policy where the matching condition includes a single application, and the action is deny. If the application's default deny action is reset-both, what action does the firewall take?

Options

  • AIt silently drops the traffic.
  • BIt silently drops the traffic and sends an ICMP unreachable code.
  • CIt sends a TCP reset to the server-side device.
  • DIt sends a TCP reset to the client-side and server-side devices.

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    11% (2)
  • C
    6% (1)
  • D
    78% (14)

Explanation

The default deny action for an application can be set to one of three options: - Silently drop the traffic. - Send a TCP reset to the server-side device. - Send a TCP reset to both the client-side and server-side devices. In this case, the default deny action for the application is set to "reset-both", so the firewall will send a TCP reset to both the client-side and server-side devices when the traffic is denied.

Topics

#deny action#reset-both#application default deny#Security policy actions

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice