Valid PCNSE7 Dumps shared by ExamDiscuss.com for Helping Passing PCNSE7 Exam! ExamDiscuss.com now offer the newest PCNSE7 exam dumps, the ExamDiscuss.com PCNSE7 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com PCNSE7 dumps with Test Engine here:
A Palo Alto Networks firewall is being targeted by an NTP Amplification attack and is being flooded with tens of thousands of bogus UDP connections per second to a single destination IP address and port. Which option, when enabled with the correct threshold, would mitigate this attack without dropping legitimate traffic to other hosts inside the network?
Correct Answer: D
Explanation/Reference: Step 1: Configure a DoS Protection profile for flood protection. 1. Select Objects > Security Profiles > DoS Protection and Add a profile Name. 2. Select Classified as the Type. 3. For Flood Protection, select the check boxes for all of the following types of flood protection: * SYN Flood * UDP Flood * ICMP Flood * ICMPv6 Flood * Other IP Flood Step 2: Configure a DoS Protection policy rule that specifies the criteria for matching the incoming traffic. This step include: (Optional) For Destination Address, select Any or enter the IP address of the device you want to protect. References: https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/policy/configure-dos- protection-against-flooding-of-new-sessions