nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #344

What is the default action for the SYN Flood option within the DoS Protection profile?

The correct answer is D. Random Early Drop. DoS Protection Profiles and Policy Rules work together to provide protection against flooding of many incoming SYN, UDP, ICMP, and ICMPv6 packets, and other types of IP packets. You determine what thresholds constitute flooding. In general, the DoS Protection profile sets the…

Threat Prevention

Question

What is the default action for the SYN Flood option within the DoS Protection profile?

Options

  • AReset-client
  • BAlert
  • CSinkhole
  • DRandom Early Drop

How the community answered

(15 responses)
  • A
    7% (1)
  • B
    13% (2)
  • C
    7% (1)
  • D
    73% (11)

Explanation

DoS Protection Profiles and Policy Rules work together to provide protection against flooding of many incoming SYN, UDP, ICMP, and ICMPv6 packets, and other types of IP packets. You determine what thresholds constitute flooding. In general, the DoS Protection profile sets the thresholds at which the firewall generates a DoS alarm, takes action such as Random Early Drop, and drops additional incoming connections. A DoS Protection policy rule configured to protect (rather than to allow or deny packets) determines the criteria for packets to match (such as source address) in order to be counted toward the thresholds. This flexibility allows you to block certain traffic, or allow certain traffic and treat other traffic as DoS traffic. When the incoming rate exceeds your maximum threshold, the firewall blocks incoming traffic from the source address.

Topics

#SYN flood#DoS protection profile#Random Early Drop#flood protection

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice