nerdexam
Palo_Alto_Networks

PCNSE · Question #665

A network security administrator wants to enable Packet-Based Attack Protection in a Zone Protection profile. What are two valid ways to enable Packet-Based Attack Protection? (Choose two.)

The correct answer is A. TCP Drop B. ICMP Drop. Network > Network Profiles > Zone Protection > Packet Based Attack Protection You can configure Packet Based Attack protection to drop the following types of packets: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/zone-protection-and-dos…

Submitted by saadiq_pk· Apr 18, 2026Deploy and Configure

Question

A network security administrator wants to enable Packet-Based Attack Protection in a Zone Protection profile. What are two valid ways to enable Packet-Based Attack Protection? (Choose two.)

Options

  • ATCP Drop
  • BICMP Drop
  • CSYN Random Early Drop
  • DTCP Port Scan Block

How the community answered

(26 responses)
  • A
    96% (25)
  • D
    4% (1)

Explanation

Network > Network Profiles > Zone Protection > Packet Based Attack Protection You can configure Packet Based Attack protection to drop the following types of packets: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/zone-protection-and-dos- protection/zone-defense/zone-protection-profiles/packet-based-attack-protection

Topics

#Zone Protection#Packet-Based Attack Protection#Security Profile Configuration#Threat Prevention

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice