PCNSE Manage, Monitor and Operate Practice Question
Exhibit
Log entry: time: 2024/09/15 10:23:45 serial_number: 007200000001 type: TRAFFIC subtype: start from zone: untrust to zone: trust source: 10.10.10.10 destination: 192.168.1.100 user: unknown application: web-browsing action: drop
Refer to the exhibit. Based on the log entry, what action was taken on this traffic?
⚠ Common exam trap
Palo Alto Networks often tests the distinction between 'drop' and 'reset' actions, where candidates may mistakenly assume a dropped packet generates a TCP reset, but in Palo Alto firewalls, 'drop' is silent and 'reset' explicitly sends RST packets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic was dropped.
The log entry shows the action field as 'drop', which indicates the firewall denied the traffic. In Palo Alto Networks firewalls, a 'drop' action means the packet was silently discarded without sending a TCP reset or ICMP unreachable message. Therefore, option C is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic was allowed with a reset.
Why it's wrong here
A reset indicates the firewall sent a TCP RST to terminate the session, whereas the log records a silent drop with no reset flag set. Allow-with-reset is tempting because it is the correct action when a security policy permits the connection but a threat or application signature then resets it.
- ✗
The action could not be determined.
Why it's wrong here
The log entry explicitly populates the action field with a defined verdict, so the action is determinable from the exhibit. Undetermined is tempting when a log shows only session-end reason codes without a clear action column, which is the scenario where you would genuinely have to infer the outcome.
- ✓
The traffic was dropped.
Why this is correct
The log records a drop action, meaning the firewall's security policy denied the session and no packet was forwarded to its destination. This satisfies the stem's requirement to identify the action taken on the exhibited traffic.
- ✗
The traffic was allowed and logged.
Why it's wrong here
The log's action field shows a deny or drop verdict, so no allow action was recorded for this session. Allow-and-log is tempting because it is the standard action for traffic matching a permissive security rule with logging enabled, which is what you would expect to see for legitimate permitted flows.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.