exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 561 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 561
Topic #: 1
[All PCNSE Questions]

After switching to a different WAN connection, users have reported that various websites will not load, and timeouts are occurring. The web servers work fine from other locations.

The firewall engineer discovers that some return traffic from these web servers is not reaching the users behind the firewall. The engineer later concludes that the maximum transmission unit (MTU) on an upstream router interface is set to 1400 bytes.

The engineer reviews the following CLI output for ethernet1/1.



Which setting should be modified on ethernet1/1 to remedy this problem?

  • A. Change the subnet mask from /23 to /24.
  • B. Lower the interface MTU value below 1500.
  • C. Adjust the TCP maximum segment size (MSS) value.
  • D. Enable the Ignore IPv4 Don't Fragment (DF) setting.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bubu3k
Highly Voted 10 months, 3 weeks ago
The question is stupid, but so are some of the answers here. MTU= max data inside a frame (layer 2 packet) size. MSS max TCP payload. MTU = MSS + 40 (IP header + TCP header). Setting a lower MTU would force a lower MSS. Decreasing MSS also lowers the MTU. Based on how vague B is I would go with C, but, in my book either can work and this question is just dumb the listed answers aren't correct. And for what is worth I'm pretty sure D might work as well
upvoted 10 times
nebulanerd
6 months, 3 weeks ago
I wholeheartedly agree with this comment.
upvoted 4 times
...
...
elemzy
Most Recent 1 month, 2 weeks ago
Selected Answer: C
A: Irrelevant B: Ambiguous. e.g 1490 lower than 1500 but still more that 1400 C: Works D: Works, but not sure this is an interface setting. Question asked for interface setting.
upvoted 1 times
...
scanossa
5 months, 3 weeks ago
This question was in my exam on July 23rd, 2024
upvoted 1 times
...
ATRRHMN
6 months, 1 week ago
Selected Answer: B
The issue is with the return traffic; packets larger than the MTU might be dropped/fragmented in a way that causes problems. The appropriate action is to adjust the TCP MSS to ensure that packets are smaller than the MTU of the upstream router. This will prevent fragmentation issues and ensure that traffic flows smoothly. Why not B? Lowering the interface MTU affects all traffic, potentially causing unnecessary overhead for traffic that doesn't need to be fragmented. Adjusting the TCP MSS specifically addresses the size of TCP packets, which is typically the type of traffic experiencing the issue in such scenarios.
upvoted 2 times
ALCOSTA35
1 month, 2 weeks ago
Why not B? because the MTU should be lower than 1400 not 1500.
upvoted 1 times
...
...
0d2fdfa
7 months, 2 weeks ago
Selected Answer: B
This is a bad question. But looking at the snippet. I think they want it to be MTU Lots of assumptions can be made about upstream routers. May be they all have lower MTU or some of them only.
upvoted 1 times
...
hcir
8 months, 2 weeks ago
C is the answer. It says that some upstream router has a low mtu, it does not say that the directly connected router does. Lowering the mtu would have the FW send ICMP need to fragment messages which might work but probably not.
upvoted 1 times
...
Marshpillowz
11 months, 2 weeks ago
Selected Answer: C
C is correct
upvoted 1 times
...
Kaifus
12 months ago
Selected Answer: C
Such a wack question and any network guy would troubleshoot this easily if we had hands on the network and could see the messages. My issue with adjusting the MTU is that it doesn't state that we have control over the entire WAN. What happens if the next router in the path has the same problem? Ideally you want to fragment (D) or lower your MSS (C). https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-release-notes/pan-os-9-1-release-information/features-introduced-in-pan-os-9-1/networking-features#:~:text=Ignore%20DF%20(don't%20fragment)%20Bit&text=You%20can%20configure%20the%20firewall,when%20enabled%20through%20the%20CLI. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN0gCAG Gonna go with C but could argue that D would possibly work as well if we had access to the client's command window :)
upvoted 2 times
...
JRKhan
12 months ago
Selected Answer: C
C is correct as per the link from pavtoor. If just MTU is lowered down on the firewall, the firewall will start dropping the packets since it cant fragment them. MSS will need to be lowered down to decrease the overall MTU size of the packets.
upvoted 1 times
...
brian7857ffs45
1 year, 1 month ago
Selected Answer: C
I don't like the wording of B, it says below 1500, well 1480 is below 1500 but would still not fix an MTU IP fragmentation issue as an example. It should say "lower the interface MTU value below 1400" for B to be correct.
upvoted 4 times
...
Shaun919
1 year, 1 month ago
Selected Answer: B
MTU has to match just like in networking for routing/switching. At least from my experience.
upvoted 1 times
...
anonymous1334232
1 year, 2 months ago
It must be B as it’s the pipe that determines the data that can be put through. The tcp segment determines the buffers which is applicable only if the data is reachable.
upvoted 1 times
...
Artbrut
1 year, 4 months ago
Selected Answer: C
Agree with pavtoor -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAolCAG&lang=en_US%E2%80%A9
upvoted 2 times
...
pavtoor
1 year, 4 months ago
Option C is correct. Refer to https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN0gCAG "Please note that even though adjusting the MSS value on the PA firewall solves the issue, the issue is not caused by the Firewall. The issue is caused by other hosts in the path that have lower MTU setting."
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago