PCNSE Practice Question: Managing Troubleshooting and High Availability
A network security engineer is troubleshooting a Palo Alto Networks firewall that is dropping traffic to a critical internal server. The engineer runs 'show session all filter destination 10.1.1.50' and sees sessions in the 'discard' state. The engineer wants to determine why these sessions are being discarded. Which action should the engineer take next?
⚠ Common exam trap
The trap here is assuming that global counters or packet captures directly reveal the discard reason, when in fact session-specific details are needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'show session id <session-id>' to view detailed session information including the discard reason.
The 'show session id' command provides detailed session information, including the discard reason, which is essential for troubleshooting why sessions are in the discard state. The other commands either provide aggregate data or require additional steps to correlate with the specific session, making them less efficient for this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run 'show session id <session-id>' to view detailed session information including the discard reason.
Why this is correct
The 'show session id' command displays detailed information about a specific session, including the reason it was discarded, such as policy deny, application identified as unknown, or threat detection. This is the correct next step to diagnose why sessions are in the discard state.
- ✗
Run 'show running resource-monitor' to check if the firewall is under resource stress.
Why it's wrong here
Resource monitoring shows CPU, memory, and session utilization but does not explain why individual sessions are discarded. Discards are typically due to policy or application identification issues, not resource exhaustion. This command is more appropriate for performance troubleshooting.
- ✗
Run 'show counter global filter severity drop' to identify the global counters that are incrementing.
Why it's wrong here
While global counters can indicate drops, they do not provide session-specific discard reasons. The engineer needs per-session details, which are available in 'show session id'. Global counters are useful for aggregate drop analysis but not for pinpointing why a particular session was discarded.
- ✗
Run 'debug dataplane packet-diag set filter match destination 10.1.1.50' to capture packets and analyze them.
Why it's wrong here
Packet capture can show whether packets are received and forwarded, but it does not directly reveal the firewall's internal reason for discarding a session. The discard reason is logged and viewable via session details. Packet analysis is more time-consuming and less direct for this purpose.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.