nerdexam
Palo_Alto_Networks

NETSEC-ANALYST · Question #234

An administrator is investigating a log entry for a session that is allowed and has the end reason of aged-out. Which two fields could help in determining if this is normal? (Choose two.)

The correct answer is A. Packets sent/received B. IP Protocol. When monitoring the traffic logs using Monitor > logs > Traffic, some traffic is seen with the Session End Reason as aged-out. Any traffic that uses UDP or ICMP is seen will have session end reason as aged-out in the traffic log. This is because unlike TCP, there is there is no…

Monitoring and Troubleshooting

Question

An administrator is investigating a log entry for a session that is allowed and has the end reason of aged-out. Which two fields could help in determining if this is normal? (Choose two.)

Options

  • APackets sent/received
  • BIP Protocol
  • CAction
  • DDecrypted

How the community answered

(27 responses)
  • A
    81% (22)
  • C
    15% (4)
  • D
    4% (1)

Explanation

When monitoring the traffic logs using Monitor > logs > Traffic, some traffic is seen with the Session End Reason as aged-out. Any traffic that uses UDP or ICMP is seen will have session end reason as aged-out in the traffic log. This is because unlike TCP, there is there is no way for a graceful termination of UDP session and so aged-out is a legitimate session-end reason for UDP (and ICMP) sessions. Link: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMjLCAW

Topics

#traffic logs#aged-out session#log analysis#troubleshooting sessions

Community Discussion

No community discussion yet for this question.

Full NETSEC-ANALYST Practice