nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #6

When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake…

The correct answer is C. Packet-Based Attack Protection. Packet-Based Attack Protection examines IP, TCP, ICMP, IPv6, and ICMPv6 packet headers to drop packets with undesirable characteristics like IP spoofing or malformed TCP options that enable split handshakes.

Policy and Security Profile Configuration

Question

When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?

Options

  • AFlood Protection
  • BProtocol Protection
  • CPacket-Based Attack Protection
  • DReconnaissance Protection

How the community answered

(39 responses)
  • B
    8% (3)
  • C
    87% (34)
  • D
    5% (2)

Explanation

Packet-Based Attack Protection examines IP, TCP, ICMP, IPv6, and ICMPv6 packet headers to drop packets with undesirable characteristics like IP spoofing or malformed TCP options that enable split handshakes.

Topics

#Zone Protection Profile#Palo Alto Networks#Packet-Based Attacks#NGFW Security

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice