PCNSA · Question #245
An administrator would like to block access to a web server, while also preserving resources and minimizing half-open sockets. What are two security policy actions the administrator can select?…
The correct answer is A. Reset server B. Reset both. Palo Alto Networks firewall protection is based on application intelligence, so in the case of TCP, a TCP session must be established before the application can be discovered. However, after a TCP session has been established, silent dropping of packets without sending a TCP…
Question
An administrator would like to block access to a web server, while also preserving resources and minimizing half-open sockets. What are two security policy actions the administrator can select? (Choose two.)
Options
- AReset server
- BReset both
- CDrop
- DDeny
How the community answered
(44 responses)- A77% (34)
- C16% (7)
- D7% (3)
Explanation
Palo Alto Networks firewall protection is based on application intelligence, so in the case of TCP, a TCP session must be established before the application can be discovered. However, after a TCP session has been established, silent dropping of packets without sending a TCP reset can be dangerous. The “drop” action could break the application and cause it to misbehave. An application might hang, continue to send packets, or unnecessarily hold system resources open. Therefore, the default “deny” action defined for more than half of the applications recognized by the firewall is to send a TCP reset.
Topics
Community Discussion
No community discussion yet for this question.