Courseiva
Core Concepts and ArchitecturemediumMultiple ChoiceObjective-mapped

PCNSE Core Concepts and Architecture Practice Question

An administrator notices that traffic from zone A to zone B is being dropped silently. Security rules are in place. Troubleshooting shows that the session does not appear in the session table. What is the most likely cause?

⚠ Common exam trap

Palo Alto Networks often tests the misconception that a deny rule or default rule would cause the session to be absent from the session table, but in Palo Alto firewalls, even denied sessions appear in the session table (with a deny action) — the absence of any session entry points specifically to asymmetric routing or a packet that never reached the firewall.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The traffic is taking an asymmetric path and the firewall sees only one direction.

When traffic is silently dropped and the session does not appear in the session table, it indicates that the firewall never saw the complete three-way TCP handshake or the first packet of the flow. Asymmetric routing causes the firewall to see only one direction of traffic (e.g., only the SYN from zone A to zone B but not the SYN-ACK return), so the firewall cannot create a session entry because it requires both directions to validate the state. This results in a silent drop without any session table entry or log entry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The traffic is being decrypted by an SSL Forward Proxy rule.

    Why it's wrong here

    Decryption does not cause drops; it may affect identification but not silent drops.

  • The traffic is taking an asymmetric path and the firewall sees only one direction.

    Why this is correct

    Asymmetric routing prevents session setup, causing silent drops.

  • The traffic is matched by a rule with action 'deny' and logging is disabled.

    Why it's wrong here

    Even with logging disabled, a denied session appears briefly in the session table.

  • The interzone default rule is set to deny.

    Why it's wrong here

    Default deny rules log drops, so they would not be silent.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.