View all questions & answers for the Palo Alto Next-Generation Firewall Engineer Exam Materials exam
Question 106 Discussion
Comments
Selected Answers: B
This section protects against:
Invalid IP headers (incorrect header lengths)
Illegal TCP flag combinations (like SYN + FIN, which should never occur in a normal TCP handshake)
A security administrator is hardening the ingress zone of an NGFW. The goal is to prevent attacks that rely on malformed IP address packets with incorrect header lengths or invalid TCP packets that have both the SYN and FIN flags set. Within which section of a Zone Protection profile should these protections be configured? (Choose one answer)
Brave-Dump Clients Votes