PCNSE Troubleshoot Practice Question
A user reports intermittent connectivity to a database server through the firewall. The session table shows active sessions, but the user experiences timeouts. What is the most likely cause?
⚠ Common exam trap
The trap here is that candidates see 'active sessions' in the table and assume the firewall is working correctly, overlooking that asymmetric routing can leave stale entries while actual data flow is disrupted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Asymmetric routing
Asymmetric routing causes the firewall to see only one direction of a TCP session, leading to session timeouts despite active session entries. When traffic from the client to the database server traverses one firewall and return traffic takes a different path, the firewall cannot properly track the TCP state, resulting in dropped packets and intermittent connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DNS resolution failure
Why it's wrong here
DNS resolution failure would prevent the client from finding the server at all, not produce intermittent timeouts while active sessions persist in the firewall table. It is tempting because name resolution problems cause connection failures, and would be correct if the user could not resolve the database hostname consistently.
- ✓
Asymmetric routing
Why this is correct
Asymmetric routing causes return traffic to bypass the firewall, so it never sees the full session and drops packets mid-flow. Sessions appear active in the table, yet the user times out, matching the intermittent connectivity symptom described.
- ✗
Security policy configured with service 'any'
Why it's wrong here
Service 'any' permits every port, so the firewall cannot match the database's specific application and its timeout handling; sessions linger while replies are dropped. It is tempting because 'any' quickly unblocks traffic, and it would be correct for a lab or troubleshooting rule where all ports must pass.
- ✗
Incomplete TCP three-way handshake
Why it's wrong here
An incomplete TCP three-way handshake produces sessions that never reach established state, so the firewall would not show them as active; timeouts with active sessions point elsewhere. It is tempting because handshake failures cause timeouts, and would be correct if the session table showed only SYN or half-open entries.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.