Courseiva
Troubleshoot →easyMultiple Choice

PCNSE Troubleshoot Practice Question

A user reports intermittent connectivity to a database server through the firewall. The session table shows active sessions, but the user experiences timeouts. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates see 'active sessions' in the table and assume the firewall is working correctly, overlooking that asymmetric routing can leave stale entries while actual data flow is disrupted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Asymmetric routing

Asymmetric routing causes the firewall to see only one direction of a TCP session, leading to session timeouts despite active session entries. When traffic from the client to the database server traverses one firewall and return traffic takes a different path, the firewall cannot properly track the TCP state, resulting in dropped packets and intermittent connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    DNS resolution failure

    Why it's wrong here

    DNS resolution failure would prevent the client from finding the server at all, not produce intermittent timeouts while active sessions persist in the firewall table. It is tempting because name resolution problems cause connection failures, and would be correct if the user could not resolve the database hostname consistently.

  • ✓

    Asymmetric routing

    Why this is correct

    Asymmetric routing causes return traffic to bypass the firewall, so it never sees the full session and drops packets mid-flow. Sessions appear active in the table, yet the user times out, matching the intermittent connectivity symptom described.

  • ✗

    Security policy configured with service 'any'

    Why it's wrong here

    Service 'any' permits every port, so the firewall cannot match the database's specific application and its timeout handling; sessions linger while replies are dropped. It is tempting because 'any' quickly unblocks traffic, and it would be correct for a lab or troubleshooting rule where all ports must pass.

  • ✗

    Incomplete TCP three-way handshake

    Why it's wrong here

    An incomplete TCP three-way handshake produces sessions that never reach established state, so the firewall would not show them as active; timeouts with active sessions point elsewhere. It is tempting because handshake failures cause timeouts, and would be correct if the session table showed only SYN or half-open entries.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.