PCNSE · Question #307
A system administrator runs a port scan using the company tool as part of vulnerability check. The administrator finds that the scan is identified as a threat and is dropped by the firewall. After…
The correct answer is B. Add the tool IP address to the reconnaissance protection source address exclusion in the Zone. Port scanning behavior is detected and blocked by the Zone Protection profile's Reconnaissance Protection feature, not the DoS Protection profile (eliminating C). Simply removing the Zone Protection profile (A) would weaken security for all traffic, not just the tool. Changing…
Question
A system administrator runs a port scan using the company tool as part of vulnerability check. The administrator finds that the scan is identified as a threat and is dropped by the firewall. After further investigating the logs, the administrator finds that the scan is dropped in the Threat Logs. What should the administrator do to allow the tool to scan through the firewall?
Options
- ARemove the Zone Protection profile from the zone setting.
- BAdd the tool IP address to the reconnaissance protection source address exclusion in the Zone
- CAdd the tool IP address to the reconnaissance protection source address exclusion in the DoS
- DChange the TCP port scan action from Block to Alert in the Zone Protection profile.
How the community answered
(20 responses)- A5% (1)
- B85% (17)
- C10% (2)
Explanation
Port scanning behavior is detected and blocked by the Zone Protection profile's Reconnaissance Protection feature, not the DoS Protection profile (eliminating C). Simply removing the Zone Protection profile (A) would weaken security for all traffic, not just the tool. Changing the action to Alert (D) would still allow scanning but generates alerts - however, the best practice is to keep the Block action and whitelist the specific tool. The correct approach is to add the scanner's IP address to the Reconnaissance Protection Source Address Exclusion list within the Zone Protection profile (B), allowing the authorized tool to scan while maintaining protection against external threats.
Topics
Community Discussion
No community discussion yet for this question.