exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 73 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 73
Topic #: 1
[All PCNSE Questions]

The administrator has enabled BGP on a virtual router on the Palo Alto Networks NGFW, but new routes do not seem to be populating the virtual router.
Which two options would help the administrator troubleshoot this issue? (Choose two.)

  • A. View the System logs and look for the error messages about BGP.
  • B. Perform a traffic pcap on the NGFW to see any BGP problems.
  • C. View the Runtime Stats and look for problems with BGP configuration.
  • D. View the ACC tab to isolate routing issues.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ChiaPet75
Highly Voted 4 years, 8 months ago
Correct: B,C ======= PAN-EDU-311 Advanced Troubleshooting Dynamic Routing module "Confirm virtual router runtime status on the active firewall, go to the Network > Virtual Router screen and click on More Runtime Stats" ======= https://live.paloaltonetworks.com/t5/general-topics/bgp-traffic-pcap/td-p/237407 For troubleshooting purposes it may be necessary to collect the PCAPs of the OSPF and BGP traffic that the Palo Alto Networks device is processing. The quickest way to perform troubleshooting is through the CLI. To start the BGP capture, use the following CLI command: > debug routing pcap bgp on
upvoted 28 times
hcir
8 months, 1 week ago
debug routing pcap bgp on is not a traffic pcap, but a management plane pcap
upvoted 2 times
...
Breyarg
3 years, 2 months ago
agreed. i have had to TS this a good few times and only these options actually seem relevant to real life.
upvoted 2 times
...
...
Edu147
Highly Voted 5 years, 7 months ago
Correct A,C
upvoted 10 times
nguyncute09
3 months, 3 weeks ago
shut up bitch
upvoted 1 times
...
tester12
5 years, 5 months ago
Why is not B instead of A ?
upvoted 1 times
jonboy22
2 years, 8 months ago
Probably because B requires more practical legwork than A or C do.
upvoted 2 times
...
...
...
af67d32
Most Recent 1 week, 1 day ago
Selected Answer: AC
how would a pcap help you identify the root cause of the problem (unless you know every bit of the bgp protocol decode), while system logs will display non-ambiguous messages such as peer restart, authentication failed... etc
upvoted 1 times
...
DSBlue
1 week, 6 days ago
Selected Answer: BC
For troubleshooting purposes it may be necessary to collect the PCAPs of the OSPF and BGP traffic that the Palo Alto Networks device is processing. The quickest way to perform troubleshooting is through the CLI.
upvoted 1 times
...
kambata
7 months, 3 weeks ago
Selected Answer: AC
Idiotic question, but of course you will check the logs before doing a capture ... B is also valid, but I would go with A and C
upvoted 2 times
...
hcir
8 months, 1 week ago
A and B. It cannot be C because in the runtime stats, you do not look for configuration issues.
upvoted 3 times
...
123XYZT
10 months, 2 weeks ago
I think is A and B
upvoted 2 times
...
techplus
1 year, 4 months ago
Selected Answer: AC
A & C are the correct answer
upvoted 2 times
...
sov4
1 year, 6 months ago
Selected Answer: AC
I would say AC. The question is very similar to the next on (#74) concerning OSPF. They're both routing protocols so it's reasonable to begin basic troubleshooting the same way -- look at the system logs and stats.
upvoted 2 times
...
playthegamewithme
1 year, 8 months ago
It cant be A because, the system logs doesn't generate logs when it comes to traffic, Ive been through the system logs loads of times and never seen BGP traffic errors being logged. B and C looks more relevant
upvoted 2 times
hcir
8 months, 1 week ago
system logs generates events related to bgp
upvoted 1 times
...
...
DenskyDen
2 years ago
Selected Answer: BC
Tested this.
upvoted 1 times
lildevil
1 year, 10 months ago
And your results?
upvoted 1 times
...
...
hdrnzienlaoroljol
2 years ago
Selected Answer: BC
B and C
upvoted 1 times
...
mic_mic
2 years, 1 month ago
Which two options would help the administrator troubleshoot this issue? Can it be A and B? When I view the Runtime Stats, can I troubleshoot? or only see the stats? When I look into the sytem log I see info why not onlu stats (just think out loud)
upvoted 2 times
...
TAKUM1y
2 years, 5 months ago
Selected Answer: BC
https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/network/network-virtual-routers/more-runtime-stats-for-a-virtual-router#id37f2aaf9-bb39-40e8-a838-33f22ccbc05e
upvoted 2 times
...
UFanat
2 years, 8 months ago
Selected Answer: BC
C is correct 100% Between A and B - i choose B: > debug routing pcap bgp on this command is designed for BGP troubleshooting as asked in the question
upvoted 1 times
...
datz
2 years, 8 months ago
so C is correct. Second answer = Could be A as inside system logs we can filter is based on BGP and see what errors we get. PCAP could possibly valid too.... Also if we are saying no new routes are being populated to vRouter, what is the point of checking runtime logs :/ zzz
upvoted 1 times
...
asdasd123123iu
2 years, 10 months ago
I think that A and C are correct. We can check BGP events on System tab and Virtual Router Runtime Status. Capturing traffic is required when we must check if connectivity between peers works correctly.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago