ACE is my thought.
D is eliminated due to falling into "insufficient data"
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
App-ID labels the traffic as insufficient-data when not enough data is received in the payload to identify the application. In this case, the three-way TCP handshake completes, but not enough data follows the handshake to identify the traffic.
Incomplete in the application field:
Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application.
One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.
C is most likely a cause of Unknown-tcp, TCP handshake, but the application was not identified. I presumed the correct answer is ADE.
Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was "NO ENOUGH" data after the handshake to identify the application. In other words that traffic being seen is not really an application.
Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application.
One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.
Insufficient data means not enough data to identify the application. So for example, if the three-way TCP handshake completed and there was one data packet after the handshake but that one data packet was not enough to match any of our signatures, then user will see insufficient data in the application field of the traffic log.
ADE makes sense - from the KB :
"Incomplete means that either the three-way TCP handshake did not complete (E) OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application." (A and D both)
A is wrong. If TCP connection was established yet App-ID still doesn't have enough data to identify the application. The application must be flag as unknown-tcp or unknown-udp.
WRONG - D - There is not enough application data after the TCP connection was established. | Not enough APP Data meaning - Insufficient data in the application field:
B - Cant B
So answer: ACE
Incomplete in the application field:
Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application.
One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.
Insufficient data in the application field:
Insufficient data means not enough data to identify the application. So for example, if the three-way TCP handshake completed and there was one data packet after the handshake but that one data packet was not enough to match any of our signatures, then user will see insufficient data in the application field of the traffic log.
ACE is my thought as well.
E would come up as 'incomplete' in the logs because the tcp session never fully establishes; i.e., the firewall didn't capture the threeway handshake.
As per palo document: Incomplete means that either the three-way TCP handshake did not complete
That means - session will be created after initial SYN packet. If no packets were seen and session expired with only 1 SYN app will be incomplete. So E is the correct option.
This section is not available anymore. Please use the main Exam Page.PCNSE Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
imokenzo
Highly Voted 2 years, 10 months agoSCCUser
Most Recent 4 months agoMetgatz
10 months, 2 weeks agoMetgatz
11 months, 2 weeks agosujss
1 year, 6 months agoDenskyDen
1 year, 10 months agoDenskyDen
1 year, 9 months agoscally
2 years, 2 months agosecdaddy
2 years, 3 months agosecdaddy
2 years, 3 months agoharrypogi
2 years, 5 months agolildevil
1 year, 5 months agoscanossa
8 months, 3 weeks agodatz
2 years, 5 months agoAbuHussain
2 years, 8 months agoshinichi_88
2 years, 10 months agohairysnowman
2 years, 10 months agohairysnowman
2 years, 10 months agoGivemeMoney
2 years, 10 months agoElvenking
2 years, 7 months agoLoloshikovichev
2 years, 7 months agohairysnowman
2 years, 10 months ago