Firewall - DROP or DENY

What is the best policy for rules that respond to probes, DROP or DENY?

Dropping packets increases the cost of doing probes as it takes longer
to probe a machine.  On the other hand, DENY is probably more "friendly"
to legitimate (no-evil-intended) connection requests.   Is there really
any significant benefit to using DROP vs DENY, other than costing
potential attackers more time?


