nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #171

An administrator would like to override the default deny action for a given application, and instead would like to block the traffic and send the ICMP code "communication with the destination is admin

The correct answer is B. Drop, send ICMP Unreachable. Silently drops the traffic; for an application, it overrides the default deny action. A TCP reset is not sent to the host/application. For Layer 3 interfaces, to optionally send an ICMP unreachable response to the client, set Action: Drop and enable the Send ICMP Unreachable chec

Security Policy Configuration

Question

An administrator would like to override the default deny action for a given application, and instead would like to block the traffic and send the ICMP code "communication with the destination is administratively prohibited". Which security policy action causes this?

Options

  • ADrop
  • BDrop, send ICMP Unreachable
  • CReset both
  • DReset server

How the community answered

(44 responses)
  • A
    7% (3)
  • B
    75% (33)
  • C
    2% (1)
  • D
    16% (7)

Explanation

Silently drops the traffic; for an application, it overrides the default deny action. A TCP reset is not sent to the host/application. For Layer 3 interfaces, to optionally send an ICMP unreachable response to the client, set Action: Drop and enable the Send ICMP Unreachable check box. When enabled, the firewall sends the ICMP code for communication with the destination is administratively prohibited--ICMPv4: Type 3, Code 13; ICMPv6: Type 1, Code 1. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClltCAC#:~:text= The% 20Deny%20action%20will%20tear,packets%20will%20be%20silently%20discarded.

Topics

#Drop action#ICMP unreachable#administratively prohibited#Security policy actions

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice