PCNSE · Question #209
A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers. Which option will protect the individual servers?
The correct answer is D. Apply a classified DoS Protection Profile. DoS Protection Profiles on Palo Alto Networks NGFWs come in two modes: Aggregate (protects an entire zone based on total traffic volume) and Classified (protects individual IP addresses or servers by enforcing per-source or per-destination thresholds). Since the requirement is…
Question
A client is concerned about resource exhaustion because of denial-of-service attacks against their DNS servers. Which option will protect the individual servers?
Options
- AEnable packet buffer protection on the Zone Protection Profile.
- BApply an Anti-Spyware Profile with DNS sinkholing.
- CUse the DNS App-ID with application-default.
- DApply a classified DoS Protection Profile.
How the community answered
(24 responses)- A4% (1)
- B4% (1)
- C8% (2)
- D83% (20)
Explanation
DoS Protection Profiles on Palo Alto Networks NGFWs come in two modes: Aggregate (protects an entire zone based on total traffic volume) and Classified (protects individual IP addresses or servers by enforcing per-source or per-destination thresholds). Since the requirement is to protect individual DNS servers from being overwhelmed, a Classified DoS Protection Profile is the correct choice - it tracks and limits connections on a per-server basis. Zone Protection Profiles with packet buffer protection address zone-level flooding, not individual server exhaustion. Anti-Spyware with DNS sinkholing addresses infected clients, not DoS volumetric attacks.
Topics
Community Discussion
No community discussion yet for this question.