nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #77

A network engineer observes a pattern of anomalous traffic hitting an external-facing zone, including a high volume of TCP packets that are not part of a new session handshake (non-SYN), and a large n

The correct answer is D. Packet-Based Attack Protection. Packet-Based Attack Protection is specifically designed to detect and mitigate abnormal or malformed packets such as non-SYN TCP packets and ICMP fragments, which are characteristic of packet-level attacks rather than floods, reconnaissance, or protocol misuse.

Threat Prevention

Question

A network engineer observes a pattern of anomalous traffic hitting an external-facing zone, including a high volume of TCP packets that are not part of a new session handshake (non-SYN), and a large number of ICMP fragments. The engineer decides to apply a Zone Protection profile to mitigate these potential threats. Which protection type within the profile must be configured?

Options

  • AProtocol Protection
  • BFlood Protection
  • CReconnaissance Protection
  • DPacket-Based Attack Protection

How the community answered

(48 responses)
  • A
    4% (2)
  • B
    8% (4)
  • C
    2% (1)
  • D
    85% (41)

Explanation

Packet-Based Attack Protection is specifically designed to detect and mitigate abnormal or malformed packets such as non-SYN TCP packets and ICMP fragments, which are characteristic of packet-level attacks rather than floods, reconnaissance, or protocol misuse.

Topics

#Zone Protection#Packet-Based Attacks#NGFW Configuration#Network Threat Mitigation

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice