管理者は、Web サーバーへのアクセスをブロックすると同時に、リソースを保護し、ハーフオープン ソケットを最小限に抑えたいと考えています。管理者が選択できるセキュリティ ポリシー アクションを 2 つ選択してください。(2つ選んでください。)
正解:A,B
Palo Alto Networks firewall protection is based on application intelligence, so in the case of TCP, a TCP session must be established before the application can be discovered. However, after a TCP session has been established, silent dropping of packets without sending a TCP reset can be dangerous. The "drop" action could break the application and cause it to misbehave. An application might hang, continue to send packets, or unnecessarily hold system resources open.
Therefore, the default "deny" action defined for more than half of the applications recognized by the firewall is to send a TCP reset.