nerdexam
Palo_Alto_Networks

NETSEC-PRO · Question #13

Which functionality does an NGFW use to determine whether new session setups are legitimate or illegitimate?

The correct answer is B. SYN cookies. To prevent SYN flood attacks, the NGFW uses SYN cookies to validate legitimate session SYN cookies allow the firewall to verify the legitimacy of new session requests without allocating resources until the handshake is completed. This prevents SYN flood attacks from exhausting sy

Threat Prevention and DoS Protection

Question

Which functionality does an NGFW use to determine whether new session setups are legitimate or illegitimate?

Options

  • ASYN bit
  • BSYN cookies
  • CRandom Early Detection (RED)
  • DSYN flood protection

How the community answered

(48 responses)
  • A
    10% (5)
  • B
    81% (39)
  • C
    2% (1)
  • D
    6% (3)

Explanation

To prevent SYN flood attacks, the NGFW uses SYN cookies to validate legitimate session SYN cookies allow the firewall to verify the legitimacy of new session requests without allocating resources until the handshake is completed. This prevents SYN flood attacks from exhausting system resources. SYN cookies mitigate resource exhaustion by ensuring only legitimate connections are

Topics

#SYN cookies#DoS protection#session management#flood protection

Community Discussion

No community discussion yet for this question.

Full NETSEC-PRO Practice