nerdexam
Palo_Alto_Networks

PCNSC · Question #29

A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks. How can the Palo Alto…

The correct answer is B. Add a DoS Protection Profile with defined session count. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/dos-protection-profiles-and-policy-rules/dos-protection- profiles#ida42d52fa-3366-4695-bb4a-d39ebf3b6a5f

Complex Threat Prevention and Zero Trust Implementation

Question

A client has a sensitive application server in their data center and is particularly concerned about resource exhaustion because of distributed denial-of-service attacks. How can the Palo Alto Networks NGFW be configured to specifically protect tins server against resource exhaustion originating from multiple IP address (DDoS attack)?

Options

  • ADefine a custom App-ID to ensure that only legitimate application traffic reaches the server
  • BAdd a DoS Protection Profile with defined session count.
  • CAdd a Vulnerability Protection Profile to block the attack.
  • DAdd QoS Profiles to throttle incoming requests.

How the community answered

(29 responses)
  • A
    7% (2)
  • B
    83% (24)
  • C
    3% (1)
  • D
    7% (2)

Explanation

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/dos-protection-profiles-and-policy-rules/dos-protection- profiles#ida42d52fa-3366-4695-bb4a-d39ebf3b6a5f

Topics

#DDoS protection#DoS Protection Profile#resource exhaustion#session limits

Community Discussion

No community discussion yet for this question.

Full PCNSC Practice