Probably C, since Strata Logging is designed to scale as you add locations or users. If the question had asked about where the logs are physically stored or latency concerns, that might point to a different option.
I always thought B since SP3 is designed for efficiency, so "no degradation" seemed right.
This is about the actual handshake check, not just protection: so it's B. SYN cookies let the NGFW validate if the client really got the SYN-ACK, proving legitimacy before a new session spins up. D (SYN flood protection) is broader but doesn't describe how legitimacy is determined. I think B's correct but correct me if I'm missing a catch here.
Seen similar on exams, best practice is A. Phased and off-peak upgrades lower the risk, plus config backups help recovery. Rolling out everywhere at once (like B) feels risky. Agree?
Yeah, it's C here. Rule evaluation is based on the priority value you set, not when the rule was created. D is a common trap since some firewall UIs do use creation order, but Cloud NGFW for AWS goes by explicit numerical priority. Seen similar on practice questions!