PCNSE · Question #285
A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial-of-service attacks. How can the Palo Alto Networks NGFW be…
The correct answer is D. Add a tuned DoS Protection Profile. Protection profiles and DoS Protection policy rules combine to protect specific groups of critical resources and individual critical resources against session floods. Compared to Zone Protection profiles, which protect entire zones from flood attacks, DoS protection provides…
Question
A client has a sensitive application server in their data center and is particularly concerned about session flooding because of denial-of-service attacks. How can the Palo Alto Networks NGFW be configured to specifically protect this server against session floods originating from a single IP address?
Options
- AAdd an Anti-Spyware Profile to block attacking IP address
- BDefine a custom App-ID to ensure that only legitimate application traffic reaches the server
- CAdd QoS Profiles to throttle incoming requests
- DAdd a tuned DoS Protection Profile
How the community answered
(41 responses)- A12% (5)
- B5% (2)
- C2% (1)
- D80% (33)
Explanation
Protection profiles and DoS Protection policy rules combine to protect specific groups of critical resources and individual critical resources against session floods. Compared to Zone Protection profiles, which protect entire zones from flood attacks, DoS protection provides granular defense for specific systems, especially critical systems that users access from the internet and are often attack targets, such as web servers and database servers. Apply both types of protection because if you only apply a Zone Protection profile, then a DoS attack that targets a particular system in the zone can succeed if the total connections-per-second (CPS) doesn't exceed the zone's Activate and Maximum rates. DoS Protection is resource-intensive, so use it only for critical systems. Similar to Zone Protection profiles, DoS Protection profiles specify flood thresholds. DoS Protection policy rules determine the devices, users, zones, and services to which DoS Profiles apply. https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/zone-protection-and-dos- protection/zone-defense/dos-protection-profiles-and-policy-rules
Topics
Community Discussion
No community discussion yet for this question.