NGFW-ENGINEER · Question #6
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake…
The correct answer is C. Packet-Based Attack Protection. Packet-Based Attack Protection examines IP, TCP, ICMP, IPv6, and ICMPv6 packet headers to drop packets with undesirable characteristics like IP spoofing or malformed TCP options that enable split handshakes.
Question
When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?
Options
- AFlood Protection
- BProtocol Protection
- CPacket-Based Attack Protection
- DReconnaissance Protection
How the community answered
(39 responses)- B8% (3)
- C87% (34)
- D5% (2)
Explanation
Packet-Based Attack Protection examines IP, TCP, ICMP, IPv6, and ICMPv6 packet headers to drop packets with undesirable characteristics like IP spoofing or malformed TCP options that enable split handshakes.
Topics
Community Discussion
No community discussion yet for this question.