PCNSE · Question #698
Which log type will help the engineer verify whether packet buffer protection was activated?
The correct answer is C. Threat. Packet Buffer Protection is a Zone Protection and DoS Protection feature that defends against packet buffer exhaustion attacks. When it activates (either in alert or block mode), PAN-OS records the event in the Threat log, categorized under the DoS sub-type. Traffic logs record s
Question
Which log type will help the engineer verify whether packet buffer protection was activated?
Options
- AData Filtering
- BConfiguration
- CThreat
- DTraffic
How the community answered
(31 responses)- A3% (1)
- B3% (1)
- C94% (29)
Explanation
Packet Buffer Protection is a Zone Protection and DoS Protection feature that defends against packet buffer exhaustion attacks. When it activates (either in alert or block mode), PAN-OS records the event in the Threat log, categorized under the DoS sub-type. Traffic logs record session-level forwarding decisions, Configuration logs record admin changes, and Data Filtering logs record DLP-related matches - none of these capture packet buffer protection activation events. Checking the Threat log is the correct place to confirm whether and when packet buffer protection triggered.
Topics
Community Discussion
No community discussion yet for this question.