exam questions

Exam PCNSA All Questions

View all questions & answers for the PCNSA exam

Exam PCNSA topic 1 question 256 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 256
Topic #: 1
[All PCNSA Questions]

An administrator would like to block access to a web server, while also preserving resources and minimizing half-open sockets.

What are two security policy actions the administrator can select? (Choose two.)

  • A. Reset server
  • B. Deny
  • C. Drop
  • D. Reset both
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
DlaEdu_Ex
5 months, 1 week ago
Selected Answer: AD
Palo Alto Networks firewall protection is based on application intelligence, so in the case of TCP, a TCP session must be established before the application can be discovered. However, after a TCP session has been established, silent dropping of packets without sending a TCP reset can be dangerous. The “drop” action could break the application and cause it to misbehave. An application might hang, continue to send packets, or unnecessarily hold system resources open. Therefore, the default “deny” action defined for more than half of the applications recognized by the firewall is to send a TCP reset. [Palo Alto Networks]
upvoted 1 times
...
OhEmGee
5 months, 2 weeks ago
Selected Answer: CD
The question is about 'generally' preserving the resources, without spelling out server side or client side. Best option in such a case is DROP and then RESET-BOTH. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/policy/security-policy/security-policy-actions
upvoted 2 times
DatITGuyTho1337
3 months, 2 weeks ago
I disagree on the DROP option, if selected, the application will misbehave and most likely keep the sockets open as well as continually send packets seeking a response.
upvoted 3 times
...
...
Selected Answer: AD
reset-server is useful when internal resources need to be protected from excessive resource consumption due to half-open sockets. reset-both will provide best user experience and protect servers' resources, but may facilitate malicious use.
upvoted 1 times
...
sjurka
7 months ago
Selected Answer: AD
Reset options to avoid half open sockets
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago