nerdexam
Palo_Alto_Networks

PCNSA · Question #245

An administrator would like to block access to a web server, while also preserving resources and minimizing half-open sockets. What are two security policy actions the administrator can select?…

The correct answer is A. Reset server B. Reset both. Palo Alto Networks firewall protection is based on application intelligence, so in the case of TCP, a TCP session must be established before the application can be discovered. However, after a TCP session has been established, silent dropping of packets without sending a TCP…

Submitted by dimitri_ru· Apr 18, 2026Policy Evaluation and Management

Question

An administrator would like to block access to a web server, while also preserving resources and minimizing half-open sockets. What are two security policy actions the administrator can select? (Choose two.)

Options

  • AReset server
  • BReset both
  • CDrop
  • DDeny

How the community answered

(44 responses)
  • A
    77% (34)
  • C
    16% (7)
  • D
    7% (3)

Explanation

Palo Alto Networks firewall protection is based on application intelligence, so in the case of TCP, a TCP session must be established before the application can be discovered. However, after a TCP session has been established, silent dropping of packets without sending a TCP reset can be dangerous. The “drop” action could break the application and cause it to misbehave. An application might hang, continue to send packets, or unnecessarily hold system resources open. Therefore, the default “deny” action defined for more than half of the applications recognized by the firewall is to send a TCP reset.

Topics

#Security Policies#Firewall Actions#TCP Resets#Resource Management

Community Discussion

No community discussion yet for this question.

Full PCNSA Practice