NetSec-Pro NGFW And SASE Solution Functionality Practice Question
What is the effect of setting a Security Policy rule action to 'Drop' versus 'Reset-Both'?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reset-Both informs the client and server that the connection is closed.
'Drop' silently discards the packet, while 'Reset-Both' actively informs the sender and receiver that the connection is terminated.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reset-Both is only for TCP, while Drop is only for UDP.
Why it's wrong here
Both actions apply to various protocols.
- ✗
Drop is only available for inter-zone traffic.
Why it's wrong here
Drop is available for all traffic types.
- ✗
Drop consumes more firewall CPU cycles.
Why it's wrong here
Reset-Both is slightly more resource-intensive due to packet generation.
- ✓
Reset-Both informs the client and server that the connection is closed.
Why this is correct
Resetting allows the endpoints to clean up their state immediately.
About these practice questions
Courseiva writes every NetSec-Pro question from scratch — 191 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official Palo Alto Networks exam blueprint
This NetSec-Pro practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NetSec-Pro exam.