exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 279 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 279
Topic #: 1
[All PCNSE Questions]

An engineer is configuring Packet Buffer Protection on ingress zones to protect from single-session DoS attacks. Which sessions does Packet Buffer Protection apply to?

  • A. It applies to existing sessions and is not global
  • B. It applies to existing sessions and is global
  • C. It applies to new sessions and is global
  • D. It applies to new sessions and is not global
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
hcir
9 months ago
Indeed, the doc says "existing sessions and global", but in reality, PBP applies to existing and new sessions. PBP measures Connections per seconds and can drop packets of new sessions or discard existing sessions should they consume too many buffers. Basically, the doc is wrong, but for the PCNSE, we should of course answer "While zone and DoS protection apply to new sessions (connections) and are granular, Packet Buffer Protection applies to existing sessions and is global." If only globally applied, PBP drops packets using RED. When applied in a zone, it can also block (with the "block countdown threshold") for an amount of time
upvoted 2 times
...
JRKhan
1 year, 2 months ago
Selected Answer: B
PBP applies to existing sessions. It is enabled globally and if enabled globally can also be applied to zones.
upvoted 1 times
...
hifumi_daisuki
1 year, 3 months ago
Selected Answer: B
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/zone-defense/packet-buffer-protection Yes, Buffer Protection can apply on each zone. But from doc it said "You must enable Packet Buffer Protection globally in order for it to be active in zones." So there must be a global rule already being made. Thus I chose B.
upvoted 1 times
...
Whizdhum
1 year, 3 months ago
Selected Answer: B
Answer is B. Although you don’t configure Packet Buffer Protection in a Zone Protection profile or in a DoS Protection profile or policy rule, Packet Buffer Protection defends ingress zones. While zone and DoS protection apply to new sessions (connections) and are granular, Packet Buffer Protection applies to existing sessions and is global.
upvoted 1 times
...
RoamingFo
1 year, 4 months ago
Selected Answer: A
It Applied on existing sessions. It is not Global, yes there is a global control but there is also a zone control, so it can be disabled on some zone. Correct Answer is A
upvoted 1 times
...
Mocix
1 year, 5 months ago
What about "on ingress zones" part of the question? shouldn't the answer be A?
upvoted 1 times
...
confusion
2 years, 5 months ago
Selected Answer: B
B Global and applies to existing sessions.
upvoted 2 times
...
TAKUM1y
2 years, 5 months ago
Selected Answer: B
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/zone-defense/packet-buffer-protection
upvoted 4 times
...
datz
2 years, 5 months ago
Selected Answer: B
Packet Buffer Protection applies to existing sessions and is global. Correct
upvoted 2 times
...
kulpaddy
2 years, 6 months ago
Selected Answer: B
B correct answer. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/zone-protection-and-dos-protection/zone-defense/packet-buffer-protection
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago