Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSA topic 1 question 150 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 150
Topic #: 1
[All PCNSA Questions]

An administrator would like to override the default deny action for a given application, and instead would like to block the traffic and send the ICMP code
`communication with the destination is administratively prohibited`.
Which security policy action causes this?

  • A. Drop
  • B. Drop, send ICMP Unreachable
  • C. Reset both
  • D. Reset server
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
Reference:
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-admin/policy/security-policy/security-policy-actions.html

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
LordScorpius
2 years ago
Selected Answer: B
Why not reset? Because "For a TCP session with a reset action, the firewall does not send an ICMP Unreachable response."
upvoted 3 times
...
error_909
2 years, 1 month ago
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClltCAC#:~:text=The%20Deny%20action%20will%20tear,packets%20will%20be%20silently%20discarded.
upvoted 1 times
error_909
2 years, 1 month ago
Answer is Drop and send icmp unrechable
upvoted 2 times
...
...
H3kerman
2 years, 5 months ago
Drop Silently drops the traffic; for an application, it overrides the default deny action. A TCP reset is not sent to the host/application. For Layer 3 interfaces, to optionally send an ICMP unreachable response to the client, set Action: Drop and enable the Send ICMP Unreachable check box. When enabled, the firewall sends the ICMP code for communication with the destination is administratively prohibited—ICMPv4: Type 3, Code 13; ICMPv6: Type 1, Code 1.
upvoted 4 times
LuisRG17
2 years, 4 months ago
I guess that the correct answer is B, because you will drop the request and additional you have to enable Send ICMP Unreachable to send the message
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...