Courseiva
Troubleshoot →easyMultiple Select

PCNSE Troubleshoot Practice Question

Which TWO are valid methods to troubleshoot a firewall not passing traffic? (Choose two.)

⚠ Common exam trap

Candidates often assume rebooting or updating signatures will fix traffic issues, but these actions do not address the most common causes like policy misordering or session state problems, which are directly verifiable through the session table and policy order review.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the security policy order

Option C is correct because firewall policy is evaluated top-down, so a broader or more specific rule placed above the intended rule can shadow it and silently drop or block the traffic; verifying rule order confirms whether the matching permit rule is actually being reached. Option D is correct because the session table (e.g., 'show session all filter source x.x.x.x destination y.y.y.y' on Palo Alto, or 'conntrack -L'/'show conn' on other platforms) reveals whether a session was created, its state, and whether it was denied, which directly indicates where traffic is failing. Option A is not a troubleshooting method since rebooting only clears state temporarily and provides no diagnostic evidence of the root cause. Option B is not valid because changing the interface IP address alters the configuration rather than diagnosing the existing forwarding or policy problem. Option E is not valid because updating threat prevention signatures addresses content inspection, not the basic forwarding or policy issue being investigated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reboot the firewall

    Why it's wrong here

    Rebooting clears state but destroys logs, counters and session evidence needed to identify the drop, and rarely fixes a policy or routing fault. It is tempting because it restores service when the cause is a stuck process or exhausted session table, which is when it would be the right action.

  • ✗

    Change the interface IP address

    Why it's wrong here

    Changing the interface IP address alters the firewall's own addressing, which cannot diagnose why existing traffic is dropped and may break connectivity further. It is tempting because interface misconfiguration does cause outages, so it would be correct when the fault is a wrong subnet mask, gateway or duplicate address on that link.

  • ✓

    Verify the security policy order

    Why this is correct

    Verifying security policy order confirms that no earlier, broader rule is shadowing the intended permit, since PAN-OS evaluates rules top-down and stops at the first match. This directly satisfies the stem's troubleshooting requirement by ruling out misordering as the cause of dropped traffic.

  • ✓

    Check the session table for the traffic

    Why this is correct

    Inspecting the session table confirms whether the firewall created a session for the flow and reveals its state, such as active, discarded or pending. This directly satisfies the troubleshooting requirement by showing if traffic matched a security policy and progressed past session establishment, isolating drops caused by policy denial, asymmetric routing or resource limits.

  • ✗

    Update the threat prevention signature

    Why it's wrong here

    Threat prevention signatures inspect content of permitted flows; updating them cannot explain a flow being blocked before inspection, and may introduce new drops. It is tempting because signature issues do cause false positives, so it would be correct when traffic is permitted by policy but reset by an outdated or faulty content inspection profile.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.