Palo Alto Networks System Engineer – SASE — Question 15
Which action protects against port scans from the internet?
Answer options
- A. Apply App-ID Security policy rules to block traffic sourcing from the untrust zone.
- B. Assign Security profiles to Security policy rules for traffic sourcing from the untrust zone.
- C. Apply a Zone Protection profile on the zone of the ingress interface.
- D. Assign an Interface Management profile to the zone of the ingress surface.
Correct answer: C
Explanation
The correct answer is C because applying a Zone Protection profile effectively mitigates port scans by providing additional security measures for incoming traffic. Options A and B focus on blocking or securing traffic but do not specifically address port scans. Option D relates to interface management and does not directly prevent scanning activities.