PCNSA · Question #51
Which prevention technique will prevent attacks based on packet count?
The correct answer is A. zone protection profile. Zone protection profiles include flood protection mechanisms that operate on packet counts and rates - for example, SYN flood, UDP flood, ICMP flood, and other volumetric DoS attacks. When packet counts exceed configured thresholds, the zone protection profile can alert…
Question
Which prevention technique will prevent attacks based on packet count?
Options
- Azone protection profile
- BURL filtering profile
- Cantivirus profile
- Dvulnerability profile
How the community answered
(52 responses)- A88% (46)
- B6% (3)
- C2% (1)
- D4% (2)
Explanation
Zone protection profiles include flood protection mechanisms that operate on packet counts and rates - for example, SYN flood, UDP flood, ICMP flood, and other volumetric DoS attacks. When packet counts exceed configured thresholds, the zone protection profile can alert, activate random early drop (RED), or use SYN cookies to mitigate the attack. URL filtering, antivirus, and vulnerability profiles all operate on application-layer content inspection, not raw packet volume counting.
Topics
Community Discussion
No community discussion yet for this question.