ExamGecko
Question list
Search
Search

Related questions











Question 218 - PCNSE discussion

Report
Export

An engineer is tasked with configuring a Zone Protection profile on the untrust zone.

Which three settings can be configured on a Zone Protection profile? (Choose three.)

A.
Ethernet SGT Protection
Answers
A.
Ethernet SGT Protection
B.
Protocol Protection
Answers
B.
Protocol Protection
C.
DoS Protection
Answers
C.
DoS Protection
D.
Reconnaissance Protection
Answers
D.
Reconnaissance Protection
E.
Resource Protection
Answers
E.
Resource Protection
Suggested answer: B, C, D

Explanation:

B. Protocol Protection: Protocol protection is used to limit or block traffic that uses certain protocols or application functions. For example, a Zone Protection profile can be configured to block traffic that uses non-standard protocols, such as IP-in-IP, or to limit the number of concurrent sessions for certain protocols, such as SIP.

C. DoS Protection: DoS protection is used to protect against various types of denial-of-service (DoS) attacks, such as SYN floods, UDP floods, ICMP floods, and others. A Zone Protection profile can be configured to limit the rate of traffic for certain protocols or to drop traffic that matches specific patterns, such as malformed packets or packets with invalid headers.

D. Reconnaissance Protection: Reconnaissance protection is used to prevent attackers from gathering information about the network, such as by using port scans or other techniques. A Zone Protection profile can be configured to limit the rate of traffic for certain types of reconnaissance, such as port scans or OS fingerprinting, or to drop traffic that matches specific patterns, such as packets with invalid flags or payloads.

asked 23/09/2024
Okan YILDIZ
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first