PCNSE · Question #418
An organization's administrator has the funds available to purchase more firewalls to increase the organization's security posture. The partner SE recommends placing the firewalls as close as…
The correct answer is B. Yes. Firewalls are session-based, so they do not scale to millions of CPS. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/firewall-placement-for-dos-protection The firewall is a session-based device that isn’t designed to scale to millions of connections-per- second (CPS) to defend against…
Question
An organization's administrator has the funds available to purchase more firewalls to increase the organization's security posture. The partner SE recommends placing the firewalls as close as possible to the resources that they protect. Is the SE's advice correct, and why or why not?
Options
- ANo. Firewalls provide new defense and resilience to prevent attackers at every stage of the
- BYes. Firewalls are session-based, so they do not scale to millions of CPS.
- CNo. Placing firewalls in front of perimeter DDoS devices provides greater protection for sensitive
- DYes. Zone Protection profiles can be tailored to the resources that they protect via the
How the community answered
(46 responses)- A4% (2)
- B85% (39)
- C9% (4)
- D2% (1)
Explanation
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/firewall-placement-for-dos-protection The firewall is a session-based device that isn’t designed to scale to millions of connections-per- second (CPS) to defend against large volumetric DoS attacks.
Topics
Community Discussion
No community discussion yet for this question.