exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 258 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 258
Topic #: 1
[All PCNSE Questions]

What are three reasons why an installed session can be identified with the "application incomplete" tag? (Choose three.)

  • A. There was no application data after the TCP connection was established.
  • B. The client sent a TCP segment with the PUSH flag set.
  • C. The TCP connection was terminated without identifying any application data.
  • D. There is not enough application data after the TCP connection was established.
  • E. The TCP connection did not fully establish.
Show Suggested Answer Hide Answer
Suggested Answer: ACE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
imokenzo
Highly Voted 2 years, 10 months ago
ACE is my thought. D is eliminated due to falling into "insufficient data" https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
upvoted 17 times
...
SCCUser
Most Recent 4 months ago
Selected Answer: ACD
App-ID labels the traffic as insufficient-data when not enough data is received in the payload to identify the application. In this case, the three-way TCP handshake completes, but not enough data follows the handshake to identify the traffic.
upvoted 1 times
...
Metgatz
10 months, 2 weeks ago
Selected Answer: ACE
A,C,E are the best options
upvoted 1 times
...
Metgatz
11 months, 2 weeks ago
Incomplete in the application field: Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application. One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete.
upvoted 1 times
...
sujss
1 year, 6 months ago
Selected Answer: ACE
D = insufficient data
upvoted 1 times
...
DenskyDen
1 year, 10 months ago
C is most likely a cause of Unknown-tcp, TCP handshake, but the application was not identified. I presumed the correct answer is ADE. Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was "NO ENOUGH" data after the handshake to identify the application. In other words that traffic being seen is not really an application.
upvoted 1 times
DenskyDen
1 year, 9 months ago
Reading it again. I'm going for ACE.
upvoted 2 times
...
...
scally
2 years, 2 months ago
Selected Answer: ACE
Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application. One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete. Insufficient data means not enough data to identify the application. So for example, if the three-way TCP handshake completed and there was one data packet after the handshake but that one data packet was not enough to match any of our signatures, then user will see insufficient data in the application field of the traffic log.
upvoted 4 times
...
secdaddy
2 years, 3 months ago
ADE makes sense - from the KB : "Incomplete means that either the three-way TCP handshake did not complete (E) OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application." (A and D both)
upvoted 1 times
secdaddy
2 years, 3 months ago
Never mind - I see your point re D = insufficient data.
upvoted 1 times
...
...
harrypogi
2 years, 5 months ago
A is wrong. If TCP connection was established yet App-ID still doesn't have enough data to identify the application. The application must be flag as unknown-tcp or unknown-udp.
upvoted 2 times
lildevil
1 year, 5 months ago
I gotta ask...how many TCP connections you see established yet get flagged as unknown-udp ?
upvoted 1 times
...
scanossa
8 months, 3 weeks ago
but A doesn´t say "not enough", it says "no application data" at all. So it is a different scenery
upvoted 1 times
...
...
datz
2 years, 5 months ago
Selected Answer: ACE
WRONG - D - There is not enough application data after the TCP connection was established. | Not enough APP Data meaning - Insufficient data in the application field: B - Cant B So answer: ACE Incomplete in the application field: Incomplete means that either the three-way TCP handshake did not complete OR the three-way TCP handshake did complete but there was no enough data after the handshake to identify the application. In other words that traffic being seen is not really an application. One example is, if a client sends a server a SYN and the Palo Alto Networks device creates a session for that SYN , but the server never sends a SYN ACK back to the client, then that session is incomplete. Insufficient data in the application field: Insufficient data means not enough data to identify the application. So for example, if the three-way TCP handshake completed and there was one data packet after the handshake but that one data packet was not enough to match any of our signatures, then user will see insufficient data in the application field of the traffic log.
upvoted 2 times
...
AbuHussain
2 years, 8 months ago
Selected Answer: ACE
its ACE
upvoted 2 times
...
shinichi_88
2 years, 10 months ago
ACE, just checked
upvoted 1 times
...
hairysnowman
2 years, 10 months ago
ACE is my thought as well. E would come up as 'incomplete' in the logs because the tcp session never fully establishes; i.e., the firewall didn't capture the threeway handshake.
upvoted 3 times
hairysnowman
2 years, 10 months ago
Ugh...just reread the question. ACE is right because of incomplete. Need more coffee...
upvoted 5 times
GivemeMoney
2 years, 10 months ago
ACE is right! D falls under Insufficient data and the question is for "application incomplete".
upvoted 2 times
Elvenking
2 years, 7 months ago
E is out because the session was installed per the question text.
upvoted 1 times
Loloshikovichev
2 years, 7 months ago
As per palo document: Incomplete means that either the three-way TCP handshake did not complete That means - session will be created after initial SYN packet. If no packets were seen and session expired with only 1 SYN app will be incomplete. So E is the correct option.
upvoted 2 times
...
...
...
...
hairysnowman
2 years, 10 months ago
I meant ACD*.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...