QuestionQ4

PAN-OS Networking Configuration

When configuring a Zone Protection profile, under which section (protection type) would an NGFW engineer set options to defend against activities such as spoofed IP addresses and split-handshake session-establishment attempts?

  • A Flood Protection
  • B Protocol Protection
  • C Packet-Based Attack Protection
  • D Reconnaissance Protection
Explanation

Packet-Based Attack Protection includes IP Drop settings for spoofed IP addresses and TCP Drop settings for Split Handshake, which enforces the standard TCP three-way handshake.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!