A would be the correct answer here. It is a UDP connection on port 443. This would trigger unknown-udp. Incomplete is used in TCP connections only.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
1-3 packets exchanged ---> incomplete, because not even TCP handshake was completed
4-10 packets exchanged ---> insufficient data, because TCP was completed but we did not see enough packets to precisely determine what application is it
11-more packets exchanged ---> if we can't determine what is the app, it is marked as "unknown"
here is the link why A is best answer, it said that 11 packet is already unknown
https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-insufficient-data/td-p/63535
not-applicable for any deny action.
incomplete is for tcp connection with open but not complete 3 way HS, or not enough data to identify the tcp application.(incomplete is used only for tcp connection)
now both unknown-udp and insufficint-data are used for udp.
againe the question and/or answer are poorly writen.
My answer would be both A and C.
NOT: A
A seems to be correct. For UDP, the firewall only requires the first packet to identify the app, since its a udp connection on port 443, I would go with unknown-udp
for udp the aplication type can only be unknown-udp or not-aplicable. insuficient-data or incomplete is for TCP. then unknown-udp if the traffic is allowed and not-aplicable if the traffic is not allowed (dicarded). So A should be the correct one.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
scally
Highly Voted 2 years, 4 months agoCro13
Most Recent 4 months, 1 week agoSkyderAmzLee
5 months, 3 weeks ago327c7c8
9 months, 3 weeks agoJRKhan
1 year agonews088
1 year, 4 months agokuaiquchifan
1 year, 6 months agoThelioNN
1 year, 7 months agokanuwow
1 year, 9 months agodaytonadave2011
1 year, 10 months agojavim
2 years agoTAKUM1y
2 years, 2 months agoTAKUM1y
2 years, 2 months agoconfusion
2 years, 2 months agodatz
2 years, 3 months agoDrNick0
2 years, 4 months ago