Courseiva
Manage, Monitor and Operate →mediumMultiple Choice

PCNSE Manage, Monitor and Operate Practice Question

A network security engineer is validating a newly deployed firewall. The security policy is configured to allow web traffic from the Trust zone to the Untrust zone. After a user reports that a website is unreachable, the engineer runs the CLI command 'show session all filter source 10.1.1.50' and sees no active sessions. Which CLI command should the engineer use next to determine why the session was not established?

⚠ Common exam trap

The trap here is assuming that viewing the security policy configuration is sufficient to diagnose why a session was not created, when in fact a policy simulation is needed to see the actual match result.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

test security-policy-match application ssl from Trust to Untrust source 10.1.1.50 destination 203.0.113.10 destination-port 443 protocol 6

The most direct way to determine why a session was not established is to simulate the policy lookup for the exact traffic flow. The 'test security-policy-match' command evaluates the five-tuple against the current ruleset and returns the matching rule or the reason for denial, such as implicit deny or no matching rule. This quickly identifies policy misconfigurations without generating live traffic, making it the correct choice for troubleshooting a missing session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    show counter global filter delta yes

    Why it's wrong here

    This command shows global counters that can indicate drops, but it does not evaluate a specific five-tuple against the security policy. It provides aggregate statistics, not per-flow policy decisions. While useful for identifying broad issues like packet drops, it would not directly explain why a particular session from 10.1.1.50 to 203.0.113.10 on port 443 was not established.

  • ✗

    show running security-policy

    Why it's wrong here

    This command displays the entire security policy configuration. While it shows the rules, it does not simulate the match for the specific traffic flow. The engineer would have to manually interpret rule order, zones, addresses, and applications, which is error-prone. It does not provide a definitive answer about why this specific session was not created.

  • ✓

    test security-policy-match application ssl from Trust to Untrust source 10.1.1.50 destination 203.0.113.10 destination-port 443 protocol 6

    Why this is correct

    This command simulates the policy lookup for a specific flow and returns the matching rule or the reason for denial, such as 'implicit deny' or 'no matching rule'. It is the correct next step because it directly tests the policy configuration without generating live traffic, helping the engineer pinpoint whether the security policy is the cause of the missing session.

  • ✗

    show session info

    Why it's wrong here

    This command displays summary information about current sessions, such as the number of active sessions and session table utilization. It does not provide details about a specific flow or why a session was not established. Since the engineer already knows there are no sessions for that source, this command would not help diagnose the policy match failure.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.