mediumMultiple Choice
PCNSA Practice Question: Based on the exhibit, what is the most likely…
Exhibit
Refer to the exhibit. > show system info Hardware model: PA-5250 Serial number: 007200000123 Software version: 10.1.3 System uptime: 14 days, 3 hours, 22 minutes System time: Tue Jul 25 14:35:12 2023 Eth0/0: 192.168.1.1/24 Eth0/1: 10.0.0.1/24 Sessions active: 25000 Devices active: 120
Based on the exhibit, what is the most likely cause if the firewall is dropping new connections but existing sessions continue to work?
⚠ Common exam trap
Many candidates confuse session limit exhaustion with general resource starvation (like CPU or memory), but the key differentiator is that only new connections are affected while existing sessions remain fully functional, which is a hallmark of hitting the session table cap.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall has reached its session limit.
When a Palo Alto Networks firewall reaches its maximum session capacity (defined by the platform model and license), it will drop new connection attempts while maintaining existing sessions that are already in the session table. This behavior is by design to preserve established traffic. The session limit is a hard resource constraint, not a performance degradation, so existing flows continue uninterrupted until they age out or are terminated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The firewall has reached its session limit.
Why this is correct
When the session table is full, the firewall refuses new connection attempts while established sessions remain in the table and continue forwarding. This precisely matches the symptom of dropped new connections alongside working existing sessions.
- ✗
The management interface IP (192.168.1.1) is conflicting with another device.
Why it's wrong here
A management IP conflict would disrupt administrative access, not selectively block new sessions while permitting established ones. It is tempting because duplicate addresses cause intermittent connectivity, but that symptom would affect existing traffic too, unlike a policy or resource issue that only evaluates new flows.
- ✗
The firewall is low on CPU memory.
Why it's wrong here
Memory exhaustion would degrade or drop established sessions as well, and typically produces other resource alarms; it does not selectively permit existing flows. It is tempting because resource starvation is a common cause of dropped traffic, but session-table or policy problems explain the new-versus-established split.
- ✗
The software version 10.1.3 is buggy.
Why it's wrong here
A buggy software version would not reliably distinguish new connections from existing sessions, and the exhibit gives no crash or defect evidence. It is tempting because version-specific faults do cause drops, but a defect would affect traffic indiscriminately rather than only new flow setup.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 385 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.