Courseiva

NetSec-Architect Practice Question: NGFW And Cloud Delivered Security Services Architecture

An architect is troubleshooting a scenario where internal clients are experiencing intermittent connectivity issues to specific SaaS applications. Packet captures reveal that the Palo Alto Networks firewall is resetting connections due to TCP out-of-window anomalies detected by the Threat Prevention engine. What is the correct architectural adjustment?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Investigate for asymmetric routing paths and adjust TCP Strict Check options or stream normalization settings if necessary.

Asymmetric routing or intermediate load balancers can cause TCP sequence numbers to appear out-of-window to the firewall. Adjusting TCP strict checking or resolving asymmetric routing ensures legitimate sessions are not dropped.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Increase the TCP Three-Way Handshake timeout value in the zone protection profile to 300 seconds.

    Why it's wrong here

    Zone protection profiles do not manage TCP handshake timeouts for established application sessions.

  • Disable all SSL Decryption profiles globally to prevent TCP sequence number re-writing by the proxy engine.

    Why it's wrong here

    Disabling decryption removes security visibility and does not address network-level TCP state issues.

  • Configure a static NAT policy mapping all internal RFC 1918 addresses to a single public IP.

    Why it's wrong here

    Port overload NAT does not resolve TCP sequence out-of-window errors caused by routing topology.

  • Investigate for asymmetric routing paths and adjust TCP Strict Check options or stream normalization settings if necessary.

    Why this is correct

    Asymmetric routing causes state mismatches; adjusting strict checks or routing paths resolves out-of-window packet drops.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This NetSec-Architect question is part of Courseiva's 228-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint

This NetSec-Architect practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Architect exam.