Palo_Alto_Networks
NETSEC-ANALYST · Question #90
Which action results in the firewall blocking network traffic without notifying the sender?
The correct answer is A. Drop. The difference between deny and drop is that deny will make a router (or other device) send an ICMP type 3 (destination unreachable) message response back, where drop will not notify the sending party that the device has be denied and just silently drop the traffic.
Security Policy
Question
Which action results in the firewall blocking network traffic without notifying the sender?
Options
- ADrop
- BDeny
- CReset Server
- DReset Client
How the community answered
(44 responses)- A75% (33)
- B5% (2)
- C7% (3)
- D14% (6)
Explanation
The difference between deny and drop is that deny will make a router (or other device) send an ICMP type 3 (destination unreachable) message response back, where drop will not notify the sending party that the device has be denied and just silently drop the traffic.
Topics
#security policy actions#Drop action#silent block#traffic handling
Community Discussion
No community discussion yet for this question.