exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 370 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 370
Topic #: 1
[All PCNSE Questions]

An engineer has been tasked with reviewing traffic logs to find applications the firewall is unable to identify with App-ID.
Why would the application field display as incomplete?

  • A. There is insufficient application data after the TCP connection was established.
  • B. The TCP connection was terminated without identifying any application data.
  • C. The TCP connection did not fully establish.
  • D. The client sent a TCP segment with the PUSH flag set.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JackyCCK
1 month ago
Selected Answer: A
The ans is A, B & C. Please refer to the question 258. What are three reasons why an installed session can be identified with the "application incomplete" tag? CHOOSE THREE There was no application data after the TCP connection was established. The TCP connection was terminated without identifying any application data. The TCP connection did not fully establish.
upvoted 1 times
...
SCCUser
2 months, 3 weeks ago
Selected Answer: A
Incomplete --> App-ID labels traffic as incomplete when either the three-way TCP handshake does not complete or when the handshake completes but no data follows the handshake. Traffic labeled as incomplete by App-ID is not really an application.
upvoted 1 times
CarlosDV06
2 months, 2 weeks ago
Hello dude. Yea, indeed C is before A in that quote. However, most likely you will see incomplete as de application flag when you have sessions with packets sent to the server but without any response from it. Another: "choose the best "right" thing. A common sucky way of PANW to write down their exams questions lmao.
upvoted 1 times
...
...
Cro13
6 months, 4 weeks ago
Selected Answer: C
1-3 packets exchanged ---> incomplete, because not even TCP handshake was completed 4-10 packets exchanged ---> insufficient data, because TCP was completed but we did not see enough packets to precisely determine what application is it 11-more packets exchanged ---> if we can't determine what is the app, it is marked as "unknown"
upvoted 4 times
...
ATRRHMN
9 months ago
Selected Answer: C
As per EDU-210: Classifying (Labeling) TCP Traffic incomplete: Three-way handshake did not complete or was followed by no data For A, the label will be "insufficient-data"
upvoted 1 times
...
Marshpillowz
1 year, 2 months ago
Selected Answer: C
C is correct
upvoted 1 times
...
JRKhan
1 year, 2 months ago
Selected Answer: C
Ignore the comment before, C is correct. Incomplete in the application field: Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application. One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
upvoted 2 times
...
JRKhan
1 year, 2 months ago
Selected Answer: A
I believe A is correct. The key here is that the admin is reviewing traffic logs, if tcp handshake didnt complete then with default log settings it would not be recorded in the traffic log. The insufficient-data means that tcp session was established and logged after session ended but there wasnt enough data for the firewall to establish the application type.
upvoted 1 times
...
dgonz
1 year, 7 months ago
why not B?
upvoted 1 times
jhenao89
1 year, 4 months ago
B will be unknown-tcp
upvoted 1 times
...
...
sov4
1 year, 8 months ago
Selected Answer: C
C. TCP 3 way handshake didnt complete. 99% sure I saw this on the exam in July 2023
upvoted 2 times
...
Spippolo
2 years, 1 month ago
Selected Answer: C
"Incomplete" means that "either the three-way TCP handshake did not complete" or "the three-way TCP handshake **did** complete but there was no data after the handshake to identify the application." No data is the key.
upvoted 2 times
...
oelsayed
2 years, 2 months ago
Selected Answer: C
Agree on C
upvoted 1 times
...
Lexus1323
2 years, 3 months ago
Selected Answer: C
https://live.paloaltonetworks.com/t5/blogs/discussion-of-the-week-application-incomplete/ba-p/286965
upvoted 1 times
...
confusion
2 years, 5 months ago
Selected Answer: C
C insufficient data would be if TCP was established, but not enough data to identify App
upvoted 1 times
...
Alen
2 years, 5 months ago
C is correct as per URL https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC Incomplete in the application field: Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application. One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.
upvoted 3 times
...
bimyo
2 years, 6 months ago
Selected Answer: C
most correct answer here is C as "Incomplete" is displayed in the application field if the three-way TCP handshake did not complete.
upvoted 2 times
...
mysteryzjoker
2 years, 6 months ago
Selected Answer: A
A - Unknown-tcp means the firewall captured the three-way TCP handshake, but the application was not identified.
upvoted 1 times
mysteryzjoker
2 years, 5 months ago
change my mind! C. A would show as "unknown tcp"
upvoted 1 times
...
...
secdaddy
2 years, 6 months ago
It could be A or C "Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was not enough data after the handshake to identify the application. In other words that traffic being seen is not really an application." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
upvoted 4 times
secdaddy
2 years, 6 months ago
That being said there's also 'insufficient data' where there's not enough data after the three way handshake so incomplete is probably 'best' as did not fully establish so I think C.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago