Courseiva
TroubleshooteasyMultiple ChoiceObjective-mapped

PCNSE Troubleshoot Practice Question

A user reports intermittent connectivity to a database server through the firewall. The session table shows active sessions, but the user experiences timeouts. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates see 'active sessions' in the table and assume the firewall is working correctly, overlooking that asymmetric routing can leave stale entries while actual data flow is disrupted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Asymmetric routing

Asymmetric routing causes the firewall to see only one direction of a TCP session, leading to session timeouts despite active session entries. When traffic from the client to the database server traverses one firewall and return traffic takes a different path, the firewall cannot properly track the TCP state, resulting in dropped packets and intermittent connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • DNS resolution failure

    Why it's wrong here

    DNS failure would prevent initial connection, not cause intermittent timeouts with active sessions.

  • Asymmetric routing

    Why this is correct

    Asymmetric routing causes the firewall to see packets that don't match existing sessions, leading to drops or session re-creation.

  • Security policy configured with service 'any'

    Why it's wrong here

    Using 'any' service is permissive and would not cause intermittent drops.

  • Incomplete TCP three-way handshake

    Why it's wrong here

    Incomplete handshake would prevent session creation, but sessions already exist.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This PCNSE question is part of Courseiva's 504-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.