ExamGecko
Question list
Search
Search

Related questions











Question 136 - PCNSE discussion

Report
Export

An engineer has been tasked with reviewing traffic logs to find applications the firewall is unable to identify with App-ID. Why would the application field display as incomplete?

A.
The client sent a TCP segment with the PUSH flag set.
Answers
A.
The client sent a TCP segment with the PUSH flag set.
B.
The TCP connection was terminated without identifying any application data.
Answers
B.
The TCP connection was terminated without identifying any application data.
C.
There is insufficient application data after the TCP connection was established.
Answers
C.
There is insufficient application data after the TCP connection was established.
D.
The TCP connection did not fully establish.
Answers
D.
The TCP connection did not fully establish.
Suggested answer: D

Explanation:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC Incomplete in the application field: Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application. One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.

asked 23/09/2024
Nogueira Elder
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first