nerdexam
Palo_Alto_Networks

PCNSE · Question #568

While investigating a SYN flood attack, the firewall administrator discovers that legitimate traffic is also being dropped by the DoS profile. If the DoS profile action is set to Random Early Drop…

The correct answer is B. Change the SYN flood action from Random Early Drop to SYN cookies. SYN Flood Protection is the only type for which you set the drop Action. Start by setting the Action to SYN Cookies. SYN Cookies treats legitimate traffic fairly and only drops traffic that fails the SYN handshake, while using Random Early Drop drops traffic randomly, so RED…

Submitted by anjalisingh· Apr 18, 2026Operate

Question

While investigating a SYN flood attack, the firewall administrator discovers that legitimate traffic is also being dropped by the DoS profile. If the DoS profile action is set to Random Early Drop, what should the administrator do to limit the drop to only the attacking sessions?

Options

  • AEnable resources protection under the DoS Protection profile.
  • BChange the SYN flood action from Random Early Drop to SYN cookies.
  • CIncrease the activate rate for the SYN flood protection.
  • DChange the DoS Protection profile type from aggregate to classified.

How the community answered

(39 responses)
  • A
    13% (5)
  • B
    77% (30)
  • C
    8% (3)
  • D
    3% (1)

Explanation

SYN Flood Protection is the only type for which you set the drop Action. Start by setting the Action to SYN Cookies. SYN Cookies treats legitimate traffic fairly and only drops traffic that fails the SYN handshake, while using Random Early Drop drops traffic randomly, so RED may affect legitimate traffic. https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos- protection/zone-defense/zone-protection-profiles/flood-protection

Topics

#DoS Protection#SYN Flood#SYN Cookies#Security Profiles

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice