Courseiva
Troubleshoot →hardMultiple Select

PCNSE Troubleshoot Practice Question

A Palo Alto Networks firewall administrator is troubleshooting why a session was terminated with the flag 'tcp-rst-from-client'. The administrator wants to identify possible causes for this termination flag. Which two factors can cause a session to be terminated with 'tcp-rst-from-client'? (Choose two.)

⚠ Common exam trap

The trap here is assuming that any abnormal termination involves a RST, when in fact RSTs are specific to certain TCP state violations or application closures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The client application was closed abruptly, causing the operating system to send a RST.

The 'tcp-rst-from-client' flag indicates that the client sent a TCP RST packet. Common causes include the client application being closed abruptly, leading the OS to send a RST, or the client receiving a SYN-ACK for a connection it did not initiate, which triggers a RST. Other options like out-of-order packets or zero window do not cause RSTs. Security policy blocks would result in a different flag. Therefore, the correct factors are abrupt application closure and unexpected SYN-ACK.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The client application was closed abruptly, causing the operating system to send a RST.

    Why this is correct

    When a client application is closed abruptly (e.g., killed via Task Manager), the operating system may send a TCP RST to tear down the connection instead of a normal FIN. This results in a session termination with 'tcp-rst-from-client'. This is a common cause and should be considered when troubleshooting such flags.

  • ✗

    The firewall's security policy blocked the traffic, causing the client to send a RST.

    Why it's wrong here

    If the firewall's security policy blocked the traffic, the firewall would drop the packet, and the session would be terminated with a 'policy-deny' flag, not 'tcp-rst-from-client'. The client would not send a RST because it would not receive a response. Therefore, this is not a cause of the client sending a RST.

  • ✗

    The client's TCP window size was reduced to zero, triggering a RST from the client.

    Why it's wrong here

    A zero window size indicates that the client's receive buffer is full, and it will advertise a zero window to the sender. This does not cause the client to send a RST; instead, it pauses data transmission until the window opens. A RST is not generated due to a zero window. Thus, this option is incorrect.

  • ✓

    The client's TCP stack received a SYN-ACK for a connection that it did not initiate, prompting a RST.

    Why this is correct

    If a client receives a SYN-ACK without having sent a SYN (e.g., due to a spoofed packet or a stale connection), its TCP stack will respond with a RST to terminate the unexpected connection attempt. This can result in 'tcp-rst-from-client'. This is a known behavior and can occur in scenarios with asymmetric routing or session reuse.

  • ✗

    The client received a packet that was out of order and sent a RST in response.

    Why it's wrong here

    Out-of-order packets are typically handled by TCP's reassembly mechanisms; they do not cause a RST to be sent. A RST is sent when a segment arrives that does not match any existing connection or when there is a protocol violation. Out-of-order packets are normal in IP networks and are buffered, not reset. Therefore, this is not a valid cause.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.