ExamGecko
Question list
Search
Search

Related questions











Question 261 - PCNSE discussion

Report
Export

A network security administrator wants to enable Packet-Based Attack Protection in a Zone Protection profile.

What are two valid ways to enable Packet-Based Attack Protection? (Choose two.)

A.
ICMP Drop
Answers
A.
ICMP Drop
B.
TCP Drop
Answers
B.
TCP Drop
C.
TCP Port Scan Block
Answers
C.
TCP Port Scan Block
D.
SYN Random Early Drop
Answers
D.
SYN Random Early Drop
Suggested answer: B, D

Explanation:

Packet-Based Attack Protection is a feature of Zone Protection Profiles that allows the firewall to drop packets that are malformed, spoofed, or part of a port scan. TCP Drop and SYN Random Early Drop are two options under Packet-Based

Attack Protection that can be enabled to protect against TCPbased attacks. TCP Drop enables the firewall to check for spoofed IP addresses, mismatched overlapping TCP segments, and invalid IP options. SYN Random Early Drop enables the firewall to drop SYN packets randomly when the SYN queue is full, preventing SYN flood attacks. ICMP Drop and TCP Port Scan Block are not valid options under Packet-Based Attack Protection

asked 23/09/2024
Lin Sun
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first