nerdexam
Palo_Alto_Networks

PCNSE · Question #168

A session in the Traffic log is reporting the application as "incomplete." What does "incomplete" mean?

The correct answer is B. The three-way TCP handshake did not complete.. An "incomplete" application in the Traffic log indicates that the firewall observed the initiation of a TCP connection but the three-way handshake did not successfully complete. This prevents the firewall from establishing a session or identifying the application.

Submitted by the_admin· Apr 18, 2026Operate

Question

A session in the Traffic log is reporting the application as "incomplete." What does "incomplete" mean?

Options

  • AThe three-way TCP handshake was observed, but the application could not be identified.
  • BThe three-way TCP handshake did not complete.
  • CThe traffic is coming across USP, and the application could not be identified.
  • DData was received but was instantly discarded because of a Deny policy was applied before App-

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    86% (19)
  • C
    9% (2)

Why each option

An "incomplete" application in the Traffic log indicates that the firewall observed the initiation of a TCP connection but the three-way handshake did not successfully complete. This prevents the firewall from establishing a session or identifying the application.

AThe three-way TCP handshake was observed, but the application could not be identified.

If the three-way TCP handshake was observed but the application could not be identified, the application would typically be reported as 'not-applicable' or 'unknown-tcp', not 'incomplete'.

BThe three-way TCP handshake did not complete.Correct

The 'incomplete' application state specifically signifies that the Palo Alto Networks firewall saw the initial SYN packet for a TCP connection, but the subsequent SYN-ACK and ACK packets required to complete the three-way TCP handshake were not observed.

CThe traffic is coming across USP, and the application could not be identified.

USP (User-ID Sensor Protocol) is unrelated to the application identification process or the 'incomplete' state of a TCP session; it's used for user mapping.

DData was received but was instantly discarded because of a Deny policy was applied before App-

Traffic being discarded by a Deny policy would typically show the application as identified (or 'unknown') with a 'deny' action, not 'incomplete' due to a failed handshake.

Concept tested: Traffic log session states (incomplete application)

Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-the-traffic-log/traffic-log-fields.html

Topics

#Traffic Logging#Session States#TCP Handshake#App-ID

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice