nerdexam
Palo_Alto_Networks

PCNSA · Question #360

Which two Security profile actions can only be applied to DoS Protection profiles? (Choose two.)

The correct answer is C. SYN cookies D. Random Early Drop. SYN Cookies and Random Early Drop (RED) are DoS mitigation techniques that are exclusively available within DoS Protection profiles in PAN-OS. SYN Cookies is a mechanism to handle SYN flood attacks without consuming connection table resources, and RED is a congestion control…

Submitted by lars.no· Apr 18, 2026Securing Traffic

Question

Which two Security profile actions can only be applied to DoS Protection profiles? (Choose two.)

Options

  • AReset-server
  • BReset-both
  • CSYN cookies
  • DRandom Early Drop

How the community answered

(48 responses)
  • A
    8% (4)
  • B
    2% (1)
  • C
    90% (43)

Explanation

SYN Cookies and Random Early Drop (RED) are DoS mitigation techniques that are exclusively available within DoS Protection profiles in PAN-OS. SYN Cookies is a mechanism to handle SYN flood attacks without consuming connection table resources, and RED is a congestion control technique that randomly drops packets as traffic approaches threshold limits. Actions like Reset-server and Reset-both are general session termination actions available in other security profiles (e.g., Vulnerability Protection, Anti-Spyware) and are not exclusive to DoS Protection profiles.

Topics

#DoS Protection#Security Profiles#SYN Cookies#Random Early Drop

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice