PCNSE Core Concepts and Architecture Practice Question
An administrator notices that traffic from zone A to zone B is being dropped silently. Security rules are in place. Troubleshooting shows that the session does not appear in the session table. What is the most likely cause?
⚠ Common exam trap
Palo Alto Networks often tests the misconception that a deny rule or default rule would cause the session to be absent from the session table, but in Palo Alto firewalls, even denied sessions appear in the session table (with a deny action) — the absence of any session entry points specifically to asymmetric routing or a packet that never reached the firewall.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic is taking an asymmetric path and the firewall sees only one direction.
When traffic is silently dropped and the session does not appear in the session table, it indicates that the firewall never saw the complete three-way TCP handshake or the first packet of the flow. Asymmetric routing causes the firewall to see only one direction of traffic (e.g., only the SYN from zone A to zone B but not the SYN-ACK return), so the firewall cannot create a session entry because it requires both directions to validate the state. This results in a silent drop without any session table entry or log entry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic is being decrypted by an SSL Forward Proxy rule.
Why it's wrong here
Decryption does not cause drops; it may affect identification but not silent drops.
- ✓
The traffic is taking an asymmetric path and the firewall sees only one direction.
Why this is correct
Asymmetric routing prevents session setup, causing silent drops.
- ✗
The traffic is matched by a rule with action 'deny' and logging is disabled.
Why it's wrong here
Even with logging disabled, a denied session appears briefly in the session table.
- ✗
The interzone default rule is set to deny.
Why it's wrong here
Default deny rules log drops, so they would not be silent.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 504 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.