exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 370 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 370
Topic #: 1
[All PCNSE Questions]

An engineer has been tasked with reviewing traffic logs to find applications the firewall is unable to identify with App-ID.
Why would the application field display as incomplete?

  • A. There is insufficient application data after the TCP connection was established.
  • B. The TCP connection was terminated without identifying any application data.
  • C. The TCP connection did not fully establish.
  • D. The client sent a TCP segment with the PUSH flag set.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
SCCUser
1 day, 9 hours ago
Selected Answer: A
Incomplete --> App-ID labels traffic as incomplete when either the three-way TCP handshake does not complete or when the handshake completes but no data follows the handshake. Traffic labeled as incomplete by App-ID is not really an application.
upvoted 1 times
...
Cro13
4 months ago
Selected Answer: C
1-3 packets exchanged ---> incomplete, because not even TCP handshake was completed 4-10 packets exchanged ---> insufficient data, because TCP was completed but we did not see enough packets to precisely determine what application is it 11-more packets exchanged ---> if we can't determine what is the app, it is marked as "unknown"
upvoted 4 times
...
ATRRHMN
6 months, 1 week ago
Selected Answer: C
As per EDU-210: Classifying (Labeling) TCP Traffic incomplete: Three-way handshake did not complete or was followed by no data For A, the label will be "insufficient-data"
upvoted 1 times
...
Marshpillowz
11 months, 2 weeks ago
Selected Answer: C
C is correct
upvoted 1 times
...
JRKhan
1 year ago
Selected Answer: C
Ignore the comment before, C is correct. Incomplete in the application field: Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application. One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
upvoted 2 times
...
JRKhan
1 year ago
Selected Answer: A
I believe A is correct. The key here is that the admin is reviewing traffic logs, if tcp handshake didnt complete then with default log settings it would not be recorded in the traffic log. The insufficient-data means that tcp session was established and logged after session ended but there wasnt enough data for the firewall to establish the application type.
upvoted 1 times
...
dgonz
1 year, 4 months ago
why not B?
upvoted 1 times
jhenao89
1 year, 1 month ago
B will be unknown-tcp
upvoted 1 times
...
...
sov4
1 year, 5 months ago
Selected Answer: C
C. TCP 3 way handshake didnt complete. 99% sure I saw this on the exam in July 2023
upvoted 2 times
...
Spippolo
1 year, 11 months ago
Selected Answer: C
"Incomplete" means that "either the three-way TCP handshake did not complete" or "the three-way TCP handshake **did** complete but there was no data after the handshake to identify the application." No data is the key.
upvoted 2 times
...
oelsayed
1 year, 12 months ago
Selected Answer: C
Agree on C
upvoted 1 times
...
Lexus1323
2 years ago
Selected Answer: C
https://live.paloaltonetworks.com/t5/blogs/discussion-of-the-week-application-incomplete/ba-p/286965
upvoted 1 times
...
confusion
2 years, 2 months ago
Selected Answer: C
C insufficient data would be if TCP was established, but not enough data to identify App
upvoted 1 times
...
Alen
2 years, 2 months ago
C is correct as per URL https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC Incomplete in the application field: Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application. One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.
upvoted 3 times
...
bimyo
2 years, 3 months ago
Selected Answer: C
most correct answer here is C as "Incomplete" is displayed in the application field if the three-way TCP handshake did not complete.
upvoted 2 times
...
mysteryzjoker
2 years, 3 months ago
Selected Answer: A
A - Unknown-tcp means the firewall captured the three-way TCP handshake, but the application was not identified.
upvoted 1 times
mysteryzjoker
2 years, 2 months ago
change my mind! C. A would show as "unknown tcp"
upvoted 1 times
...
...
secdaddy
2 years, 3 months ago
It could be A or C "Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was not enough data after the handshake to identify the application. In other words that traffic being seen is not really an application." https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
upvoted 4 times
secdaddy
2 years, 3 months ago
That being said there's also 'insufficient data' where there's not enough data after the three way handshake so incomplete is probably 'best' as did not fully establish so I think C.
upvoted 3 times
...
...
Gabuu
2 years, 3 months ago
I think it is A https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago