nerdexam
Palo_Alto_Networks

PCNSE · Question #318

To protect your firewall and network from single source denial of service (DoS) attacks that can overwhelm its packet buffer and cause legitimate traffic to drop, you can configure

The correct answer is D. PBP (Packet Buffer Protection). https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/packet-buffer-protection Packet Buffer Protection defends your firewall and network from single session DoS attacks that can overwhelm the firewall’s packet buffer and…

Submitted by olafpl· Apr 18, 2026Deploy and Configure

Question

To protect your firewall and network from single source denial of service (DoS) attacks that can overwhelm its packet buffer and cause legitimate traffic to drop, you can configure

Options

  • APBP (Protocol Based Protection)
  • BBGP (Border Gateway Protocol)
  • CPGP (Packet Gateway Protocol)
  • DPBP (Packet Buffer Protection)

How the community answered

(55 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    5% (3)
  • D
    91% (50)

Explanation

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/packet-buffer-protection Packet Buffer Protection defends your firewall and network from single session DoS attacks that can overwhelm the firewall’s packet buffer and cause legitimate traffic to drop. Although you don’t configure Packet Buffer Protection in a Zone Protection profile or in a DoS Protection profile or policy rule, Packet Buffer Protection defends ingress zones. While zone and DoS protection apply to new sessions (connections) and are granular, Packet Buffer Protection applies to existing sessions and is global.

Topics

#DoS Protection#Packet Buffer Protection#Firewall Security

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice