nerdexam
Palo_Alto_Networks

PCNSE · Question #307

A system administrator runs a port scan using the company tool as part of vulnerability check. The administrator finds that the scan is identified as a threat and is dropped by the firewall. After…

The correct answer is B. Add the tool IP address to the reconnaissance protection source address exclusion in the Zone. Port scanning behavior is detected and blocked by the Zone Protection profile's Reconnaissance Protection feature, not the DoS Protection profile (eliminating C). Simply removing the Zone Protection profile (A) would weaken security for all traffic, not just the tool. Changing…

Submitted by tom_us· Apr 18, 2026Operate

Question

A system administrator runs a port scan using the company tool as part of vulnerability check. The administrator finds that the scan is identified as a threat and is dropped by the firewall. After further investigating the logs, the administrator finds that the scan is dropped in the Threat Logs. What should the administrator do to allow the tool to scan through the firewall?

Options

  • ARemove the Zone Protection profile from the zone setting.
  • BAdd the tool IP address to the reconnaissance protection source address exclusion in the Zone
  • CAdd the tool IP address to the reconnaissance protection source address exclusion in the DoS
  • DChange the TCP port scan action from Block to Alert in the Zone Protection profile.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    85% (17)
  • C
    10% (2)

Explanation

Port scanning behavior is detected and blocked by the Zone Protection profile's Reconnaissance Protection feature, not the DoS Protection profile (eliminating C). Simply removing the Zone Protection profile (A) would weaken security for all traffic, not just the tool. Changing the action to Alert (D) would still allow scanning but generates alerts - however, the best practice is to keep the Block action and whitelist the specific tool. The correct approach is to add the scanner's IP address to the Reconnaissance Protection Source Address Exclusion list within the Zone Protection profile (B), allowing the authorized tool to scan while maintaining protection against external threats.

Topics

#Zone Protection#Reconnaissance Protection#Exclusions#Security Profiles

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice