ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 302 - SY0-601 discussion

Report
Export

A security administrator needs to block a TCP connection using the corporate firewall, Because this connection is potentially a threat. the administrator not want to back an RST Which of the following actions in rule would work best?

A.
Drop
Answers
A.
Drop
B.
Reject
Answers
B.
Reject
C.
Log alert
Answers
C.
Log alert
D.
Permit
Answers
D.
Permit
Suggested answer: A

Explanation:

the difference between drop and reject in firewall is that the drop target sends nothing to the source, while the reject target sends a reject response to the source. This can affect how the source handles the connection attempt and how fast the port scanning is. In this context, a human might say that the best action to block a TCP connection using the corporate firewall is A. Drop, because it does not send back an RST packet and it may slow down the port scanning and protect against DoS attacks.

asked 02/10/2024
Hasan Elmas
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first