NetSec-Architect Practice Question: NGFW And Cloud Delivered Security Services Architecture
An architect is troubleshooting a scenario where internal clients are experiencing intermittent connectivity issues to specific SaaS applications. Packet captures reveal that the Palo Alto Networks firewall is resetting connections due to TCP out-of-window anomalies detected by the Threat Prevention engine. What is the correct architectural adjustment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Investigate for asymmetric routing paths and adjust TCP Strict Check options or stream normalization settings if necessary.
Asymmetric routing or intermediate load balancers can cause TCP sequence numbers to appear out-of-window to the firewall. Adjusting TCP strict checking or resolving asymmetric routing ensures legitimate sessions are not dropped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the TCP Three-Way Handshake timeout value in the zone protection profile to 300 seconds.
Why it's wrong here
Zone protection profiles do not manage TCP handshake timeouts for established application sessions.
- ✗
Disable all SSL Decryption profiles globally to prevent TCP sequence number re-writing by the proxy engine.
Why it's wrong here
Disabling decryption removes security visibility and does not address network-level TCP state issues.
- ✗
Configure a static NAT policy mapping all internal RFC 1918 addresses to a single public IP.
Why it's wrong here
Port overload NAT does not resolve TCP sequence out-of-window errors caused by routing topology.
- ✓
Investigate for asymmetric routing paths and adjust TCP Strict Check options or stream normalization settings if necessary.
Why this is correct
Asymmetric routing causes state mismatches; adjusting strict checks or routing paths resolves out-of-window packet drops.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
About these practice questions
This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.