nerdexam
Palo_Alto_Networks

PCNSE · Question #209

A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers. Which option will protect the individual servers?

The correct answer is D. Apply a classified DoS Protection Profile. DoS Protection Profiles on Palo Alto Networks NGFWs come in two modes: Aggregate (protects an entire zone based on total traffic volume) and Classified (protects individual IP addresses or servers by enforcing per-source or per-destination thresholds). Since the requirement is…

Submitted by viktor_hu· Apr 18, 2026Deploy and Configure

Question

A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers. Which option will protect the individual servers?

Options

  • AEnable packet buffer protection on the Zone Protection Profile.
  • BApply an Anti-Spyware Profile with DNS sinkholing.
  • CUse the DNS App-ID with application-default.
  • DApply a classified DoS Protection Profile.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    8% (2)
  • D
    83% (20)

Explanation

DoS Protection Profiles on Palo Alto Networks NGFWs come in two modes: Aggregate (protects an entire zone based on total traffic volume) and Classified (protects individual IP addresses or servers by enforcing per-source or per-destination thresholds). Since the requirement is to protect individual DNS servers from being overwhelmed, a Classified DoS Protection Profile is the correct choice - it tracks and limits connections on a per-server basis. Zone Protection Profiles with packet buffer protection address zone-level flooding, not individual server exhaustion. Anti-Spyware with DNS sinkholing addresses infected clients, not DoS volumetric attacks.

Topics

#DoS Protection#DNS Security#Security Profiles#Resource Exhaustion

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice