Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam PCNSA topic 1 question 145 discussion

Actual exam question from Palo Alto Networks's PCNSA
Question #: 145
Topic #: 1
[All PCNSA Questions]

An administrator has configured a Security policy where the matching condition includes a single application, and the action is drop.
If the application's default deny action is reset-both, what action does the firewall take?

  • A. It silently drops the traffic.
  • B. It silently drops the traffic and sends an ICMP unreachable code.
  • C. It sends a TCP reset to the server-side device.
  • D. It sends a TCP reset to the client-side and server-side devices.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
davidmdlp85
2 weeks, 1 day ago
Selected Answer: A
For traffic that matches the attributes defined in a security policy, you can apply the following actions: DROP Silently drops the traffic; for an application, it overrides the default deny action. A TCP reset is not sent to the host/application. For Layer 3 interfaces, to optionally send an ICMP unreachable response to the client, set Action: Drop and enable the Send ICMP Unreachable check box. When enabled, the firewall sends the ICMP code for communication with the destination is administratively prohibited—ICMPv4: Type 3, Code 13; ICMPv6: Type 1, Code 1.
upvoted 1 times
...
Notimig
5 months, 1 week ago
It's D Reset both= Sends a TCP reset to both the client-side and server-side devices.
upvoted 2 times
...
Andy222
7 months, 3 weeks ago
It looks like A. D would be valid, if the security policy action will be deny and not drop as mentioned in the question. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClltCAC
upvoted 1 times
...
blu_gandalf
11 months, 2 weeks ago
guys its D, i just had it in the Practice Exam, may-2023
upvoted 1 times
...
mr_flubber
11 months, 3 weeks ago
Selected Answer: A
It will not process the application profile and drop the traffic; A
upvoted 2 times
...
o0ZACK0o
1 year, 1 month ago
Selected Answer: A
The correct answer is A
upvoted 1 times
...
Tandos
1 year, 1 month ago
answer id D as on the Palo Alto practice exam link below https://beacon.paloaltonetworks.com/assessment_responses/report/16167409#assessment-response-details
upvoted 1 times
...
Neil_Neo234
1 year, 5 months ago
Selected Answer: A
Security policy action comes first. So the action will be drop
upvoted 2 times
...
DigitalEtrigan
1 year, 5 months ago
"the action is drop" this is stated in the question :) Drop: Silently drops the traffic; for an application, it overrides the default deny action. A TCP reset is not sent to the host/application.
upvoted 3 times
DigitalEtrigan
1 year, 5 months ago
So it is clearly A.
upvoted 2 times
...
...
FireACACIA
1 year, 5 months ago
The answer is D https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/policy/security-policy/security-policy-actions Reset both= Sends a TCP reset to both the client-side and server-side devices.
upvoted 2 times
...
Najmmm
1 year, 5 months ago
Selected Answer: A
correct answer is A
upvoted 2 times
...
froggy2638
1 year, 6 months ago
The correct answer is D. Reset-both => Sends a TCP reset to both the client-side and server-side devices. https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/objects/objects-security-profiles-vulnerability-protection
upvoted 1 times
kvothe86
1 year, 6 months ago
This link refers to action for a signatures: Objects>Security ProfilesVulnerability Protection, and not for the exam question. Please refrain from posting incorrect answers!
upvoted 4 times
...
...
TheMaster01
1 year, 7 months ago
Selected Answer: A
If a policy is set to drop, it will take precedence over the app I’d configuration
upvoted 3 times
...
reinaldopazsandoval
1 year, 7 months ago
Selected Answer: A
Should be A because the comment "and the action is drop" as is not a deny the security policy rule will not fall under the Deny APP default action.
upvoted 1 times
...
H3kerman
2 years, 5 months ago
Selected Answer: D
Reset Both For TCP, resets the connection on both the client and server ends. For UDP, drops the connection.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...