PCNSE · Question #568
While investigating a SYN flood attack, the firewall administrator discovers that legitimate traffic is also being dropped by the DoS profile. If the DoS profile action is set to Random Early Drop…
The correct answer is B. Change the SYN flood action from Random Early Drop to SYN cookies. SYN Flood Protection is the only type for which you set the drop Action. Start by setting the Action to SYN Cookies. SYN Cookies treats legitimate traffic fairly and only drops traffic that fails the SYN handshake, while using Random Early Drop drops traffic randomly, so RED…
Question
While investigating a SYN flood attack, the firewall administrator discovers that legitimate traffic is also being dropped by the DoS profile. If the DoS profile action is set to Random Early Drop, what should the administrator do to limit the drop to only the attacking sessions?
Options
- AEnable resources protection under the DoS Protection profile.
- BChange the SYN flood action from Random Early Drop to SYN cookies.
- CIncrease the activate rate for the SYN flood protection.
- DChange the DoS Protection profile type from aggregate to classified.
How the community answered
(39 responses)- A13% (5)
- B77% (30)
- C8% (3)
- D3% (1)
Explanation
SYN Flood Protection is the only type for which you set the drop Action. Start by setting the Action to SYN Cookies. SYN Cookies treats legitimate traffic fairly and only drops traffic that fails the SYN handshake, while using Random Early Drop drops traffic randomly, so RED may affect legitimate traffic. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/zone-protection-profiles/flood-protection
Topics
Community Discussion
No community discussion yet for this question.