Palo Alto Networks NGFW Engineer — Question 7

When configuring a Zone Protection profile, in which section (protection type) would an NGFW engineer configure options to protect against activities such as spoofed IP addresses and split handshake session establishment attempts?

Answer options

Correct answer: C

Explanation

The correct answer is C, as Packet-Based Attack Protection specifically addresses threats related to packet manipulation, including spoofed IPs and split handshake attempts. Options A, B, and D focus on different types of attacks; Flood Protection deals with high-volume attacks, Protocol Protection addresses issues with specific protocols, and Reconnaissance Protection is concerned with scanning and probing activities.