nerdexam
Palo_Alto_Networks

PCNSE · Question #494

An engineer is configuring Packet Buffer Protection on ingress zones to protect from single- session DoS attacks. Which sessions does Packet Buffer Protection apply to?

The correct answer is D. It applies to existing sessions and is global. Packet Buffer Protection (PBP) is designed to protect against single-session DoS attacks that exhaust the firewall's packet buffer resources. When enabled on ingress zones, PBP is 'global' in that it monitors and enforces packet buffer usage across all traffic entering that zone

Submitted by hassan_iq· Apr 18, 2026Deploy and Configure

Question

An engineer is configuring Packet Buffer Protection on ingress zones to protect from single- session DoS attacks. Which sessions does Packet Buffer Protection apply to?

Options

  • AIt applies to existing sessions and is not global
  • BIt applies to new sessions and is global
  • CIt applies to new sessions and is not global
  • DIt applies to existing sessions and is global

How the community answered

(31 responses)
  • B
    3% (1)
  • C
    6% (2)
  • D
    90% (28)

Explanation

Packet Buffer Protection (PBP) is designed to protect against single-session DoS attacks that exhaust the firewall's packet buffer resources. When enabled on ingress zones, PBP is 'global' in that it monitors and enforces packet buffer usage across all traffic entering that zone rather than being scoped to a specific policy or flow. Critically, it applies to existing sessions - once the packet buffer usage exceeds configured thresholds, PBP begins dropping or blocking traffic from existing sessions that are consuming excessive buffer space. It does not wait for new session establishment to take action, which is what makes it effective against attacks already in progress.

Topics

#Packet Buffer Protection#DoS Prevention#Session Handling#Security Features

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice