exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 356 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 356
Topic #: 1
[All PCNSE Questions]

While analyzing the Traffic log, you see that some entries show "unknown-tcp" in the Application column.
What best explains these occurrences?

  • A. A handshake did take place, but the application could not be identified.
  • B. A handshake took place, but no data packets were sent prior to the timeout.
  • C. A handshake did not take place, and the application could not be identified.
  • D. A handshake took place; however, there were not enough packets to identify the application.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
123XYZT
10 months, 1 week ago
Answer is A D is not correct, the key is there is not enough data, not packets, from Palo documentation: What is the unknown-tcp or unknown-udp that sometimes shows up in traffic logs? In terms of App-ID, these are connections where not enough data, or data that did not match any known applications's behavior, were transferred and App-ID was unable to identify a known application.
upvoted 1 times
...
Sarbi
2 years, 4 months ago
D can also be correct
upvoted 3 times
sujss
2 years ago
I think D is insufficient data
upvoted 4 times
...
halifax
2 years ago
Regardless of how many packets you receive, some applications are always in an unknown TCP state, this is by design.
upvoted 3 times
...
...
aatechler
2 years, 4 months ago
Selected Answer: A
unknown-tcp: Unknown-tcp means the firewall captured the three-way TCP handshake, but the application was not identified. This may be due to the use of a custom application for which the firewall does not have signatures
upvoted 1 times
...
confusion
2 years, 6 months ago
Selected Answer: A
A TAKUM1y and mysteryzjoker provide correct explanation
upvoted 1 times
...
TAKUM1y
2 years, 6 months ago
Selected Answer: A
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC#:~:text=unknown%2Dtcp%3A,firewall%20does%20not%20have%20signatures.
upvoted 2 times
...
mysteryzjoker
2 years, 7 months ago
Selected Answer: A
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClibCAC#:~:text=unknown%2Dtcp%3A,firewall%20does%20not%20have%20signatures.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago