exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 415 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 415
Topic #: 1
[All PCNSE Questions]

A system administrator runs a port scan using the company tool as part of vulnerability check. The administrator finds that the scan is identified as a threat and is dropped by the firewall. After further investigating the logs the administrator finds that the scan is dropped in the Threat Logs.

What should the administrator do to allow the tool to scan through the firewall?

  • A. Add the tool IP address to the reconnaissance protection source address exclusion in the DoS Protection profile.
  • B. Add the tool IP address to the reconnaissance protection source address exclusion in the Zone Protection profile.
  • C. Remove the Zone Protection profile from the zone setting.
  • D. Change the TCP port scan action from Block to Alert in the Zone Protection profile.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
chrisy042
Highly Voted 2 years, 1 month ago
Selected Answer: B
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/configure-zone-protection-to-increase-network-security/configure-reconnaissance-protection
upvoted 6 times
myname_1
2 years, 1 month ago
To further clarify it is B: There is no such section in DoS Protection Profiles The other options can open the gates to non-approved reconnaissance.
upvoted 3 times
...
...
Cro13
Most Recent 4 months, 1 week ago
Selected Answer: B
B because : Zone protection defends network zones against flood attacks, reconnaissance attempts, packet-based attacks, and attacks that use non-IP protocols. Tailor a Zone Protection profile to protect each zone (you can apply the same profile to similar zones). Denial-of-service (DoS) protection defends specific critical systems against flood attacks, especially devices that user access from the internet such as web servers and database servers, and protects resources from session floods
upvoted 1 times
...
Marshpillowz
11 months, 3 weeks ago
Selected Answer: B
Answer is B
upvoted 1 times
...
PaloSteve
1 year, 6 months ago
Updated link- https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/zone-protection-and-dos-protection/configure-zone-protection-to-increase-network-security/configure-reconnaissance-protection
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago