nerdexam
Palo_Alto_Networks

PSE-PRISMACLOUD · Question #14

A client has a sensitive internet-facing application server in Microsoft Azure and is concerned about resource exhaustion because of distributed denial-of-service attacks What can be configured on…

The correct answer is D. DoS Protection Profile with specific session counts. DoS Protection Profiles are specifically designed to defend individual hosts against resource exhaustion by enforcing granular session limits (concurrent sessions, new session rates, and half-open sessions) targeted at a specific source, destination, or both - making option D…

VM-Series NGFW Security Profiles

Question

A client has a sensitive internet-facing application server in Microsoft Azure and is concerned about resource exhaustion because of distributed denial-of-service attacks What can be configured on the VM-Series firewall to specifically protect this server against this type of attack?

Options

  • ACustom threat signature
  • BZone Protection Profile
  • CQoS Profile to limit incoming requests
  • DDoS Protection Profile with specific session counts

How the community answered

(51 responses)
  • A
    12% (6)
  • B
    6% (3)
  • C
    2% (1)
  • D
    80% (41)

Explanation

DoS Protection Profiles are specifically designed to defend individual hosts against resource exhaustion by enforcing granular session limits (concurrent sessions, new session rates, and half-open sessions) targeted at a specific source, destination, or both - making option D the precise tool for protecting a single sensitive server from DDoS floods.

Why the others are wrong:

  • A (Custom Threat Signature): Threat signatures detect malicious content (malware, exploits), not volumetric traffic floods that exhaust resources.
  • B (Zone Protection Profile): Zone Protection applies flood protection at the zone level (aggregate traffic entering a zone), not to a specific server - it's too broad for targeted host protection.
  • C (QoS Profile): QoS shapes and prioritizes traffic bandwidth but doesn't limit or drop sessions based on flood thresholds; it manages quality, not security.

Memory tip: Think of it as two layers - Zone Protection = the neighborhood (broad zone), DoS Protection Profile = the individual house (specific server). When the question says "specifically protect this server," that's your cue to pick the profile that targets a specific destination with session count thresholds: DoS Protection Profile.

Topics

#DoS Protection Profile#VM-Series#DDoS protection#session limits

Community Discussion

No community discussion yet for this question.

Full PSE-PRISMACLOUD Practice