nerdexam
Palo_Alto_Networks

PCNSE · Question #31

A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens thousands of bogus UDP connections per second to a single destination IP address and…

The correct answer is D. Classified DoS Protection Policy using destination IP only with a Protect action. A Classified DoS Protection Policy using destination IP only with a Protect action is the best mitigation here. 'Classified' mode applies per-source or per-destination thresholds individually, meaning only the single destination IP being flooded will be rate-limited once it…

Submitted by satoshi_tk· Apr 18, 2026Operate

Question

A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens thousands of bogus UDP connections per second to a single destination IP address and post. Which option when enabled with the correction threshold would mitigate this attack without dropping legitirnate traffic to other hosts insides the network?

Options

  • AZone Protection Policy with UDP Flood Protection
  • BQoS Policy to throttle traffic below maximum limit
  • CSecurity Policy rule to deny trafic to the IP address and port that is under attack
  • DClassified DoS Protection Policy using destination IP only with a Protect action

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    4% (1)
  • C
    4% (1)
  • D
    80% (20)

Explanation

A Classified DoS Protection Policy using destination IP only with a Protect action is the best mitigation here. 'Classified' mode applies per-source or per-destination thresholds individually, meaning only the single destination IP being flooded will be rate-limited once it exceeds the configured threshold. All other destination IPs inside the network continue to receive traffic normally. Option A (Zone Protection with UDP Flood) applies a single aggregate threshold across the entire zone, which could inadvertently drop legitimate UDP traffic to other hosts if the combined flood volume exceeds the zone threshold. Option C (Security Policy deny) would permanently block all traffic to that IP, including legitimate traffic once the attack stops. Option B (QoS) throttles bandwidth but does not selectively protect a single destination from connection-rate floods.

Topics

#DoS Protection#NTP Amplification#UDP Flood#Security Mitigation

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice