Courseiva
Troubleshoot →hardMultiple Choice

PCNSE Troubleshoot Practice Question

A security administrator is investigating why a session was terminated with the flag 'tcp-rst-from-server' in the traffic logs. The administrator has confirmed that the server is reachable and responding to pings. Which of the following is the most likely cause for this session termination?

⚠ Common exam trap

The trap here is equating basic IP reachability with application availability, overlooking that a RST often signals a closed port.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The server's TCP stack sent a RST packet because the application was not listening on the requested port.

A session terminated with 'tcp-rst-from-server' indicates that the server sent a TCP RST packet. This commonly occurs when the server receives a connection attempt for a port where no service is listening. While the server may respond to ICMP pings, that does not guarantee the application is available. Other causes like security policy blocks or zero window would produce different flags. Therefore, the correct answer is that the application is not listening on the port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The server's TCP window size was set to zero, causing the firewall to send a RST.

    Why it's wrong here

    A zero TCP window size indicates that the receiver's buffer is full, and it would send a window update to zero, but this does not cause a RST. The firewall does not send a RST in response to a zero window; instead, it would hold or drop packets. The 'tcp-rst-from-server' flag specifically indicates that the server sent the RST, not the firewall. Thus, this option is incorrect.

  • ✗

    The firewall's security policy blocked the traffic, causing the server to send a RST.

    Why it's wrong here

    If the firewall's security policy blocked the traffic, the firewall would drop the packet and the session would be terminated with a 'policy-deny' flag, not 'tcp-rst-from-server'. A RST from the server indicates that the server received the packet and actively rejected the connection. Therefore, a security policy block is not the cause of this specific flag.

  • ✗

    The server's operating system crashed and rebooted, sending a RST upon recovery.

    Why it's wrong here

    If the server crashed and rebooted, existing sessions would be terminated, but the server would not send a RST upon recovery for old sessions. It might send a RST if it receives packets for a session it no longer knows about, but that would be after the reboot. The scenario states the server is reachable and responding to pings, suggesting it is up. The most direct cause of a RST is the lack of a listening service, not a crash.

  • ✓

    The server's TCP stack sent a RST packet because the application was not listening on the requested port.

    Why this is correct

    When a server receives a TCP SYN for a port where no application is listening, it typically responds with a RST packet. This results in a session termination with 'tcp-rst-from-server'. The server being reachable via ping only confirms IP connectivity, not that the specific service is running. Therefore, the most likely cause is that the application is not listening on the port, leading to the RST.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.