A would be the correct answer here. It is a UDP connection on port 443. This would trigger unknown-udp. Incomplete is used in TCP connections only.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC
1-3 packets exchanged ---> incomplete, because not even TCP handshake was completed
4-10 packets exchanged ---> insufficient data, because TCP was completed but we did not see enough packets to precisely determine what application is it
11-more packets exchanged ---> if we can't determine what is the app, it is marked as "unknown"
here is the link why A is best answer, it said that 11 packet is already unknown
https://live.paloaltonetworks.com/t5/general-topics/best-practice-for-insufficient-data/td-p/63535
not-applicable for any deny action.
incomplete is for tcp connection with open but not complete 3 way HS, or not enough data to identify the tcp application.(incomplete is used only for tcp connection)
now both unknown-udp and insufficint-data are used for udp.
againe the question and/or answer are poorly writen.
My answer would be both A and C.
NOT: A
A seems to be correct. For UDP, the firewall only requires the first packet to identify the app, since its a udp connection on port 443, I would go with unknown-udp
for udp the aplication type can only be unknown-udp or not-aplicable. insuficient-data or incomplete is for TCP. then unknown-udp if the traffic is allowed and not-aplicable if the traffic is not allowed (dicarded). So A should be the correct one.
This section is not available anymore. Please use the main Exam Page.PCNSE Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
scally
Highly Voted 2 years, 8 months agoCro13
Most Recent 7 months, 4 weeks agoSkyderAmzLee
9 months, 1 week ago327c7c8
1 year, 1 month agoJRKhan
1 year, 3 months agonews088
1 year, 8 months agokuaiquchifan
1 year, 10 months agoThelioNN
1 year, 11 months agokanuwow
2 years agodaytonadave2011
2 years, 1 month agojavim
2 years, 3 months agoTAKUM1y
2 years, 5 months agoTAKUM1y
2 years, 6 months agoconfusion
2 years, 6 months agodatz
2 years, 7 months agoDrNick0
2 years, 7 months ago