nerdexam
Palo_Alto_Networks

PCNSE · Question #272

When configuring the firewall for packet capture, what are the valid stage types?

The correct answer is D. receive, firewall, transmit, and drop. Palo Alto Networks NGFWs support packet capture at four distinct pipeline stages: (1) receive - packets as they arrive on the ingress interface; (2) firewall - packets after the firewall policy lookup but before forwarding decisions; (3) transmit - packets leaving the egress inte

Submitted by satoshi_tk· Apr 18, 2026Configuration Troubleshooting

Question

When configuring the firewall for packet capture, what are the valid stage types?

Exhibit

PCNSE question #272 exhibit

Options

  • Areceive, management, transmit, and non-syn
  • Breceive, management, transmit, and drop
  • Creceive, firewall, send, and non-syn
  • Dreceive, firewall, transmit, and drop

How the community answered

(31 responses)
  • B
    6% (2)
  • C
    3% (1)
  • D
    90% (28)

Explanation

Palo Alto Networks NGFWs support packet capture at four distinct pipeline stages: (1) receive - packets as they arrive on the ingress interface; (2) firewall - packets after the firewall policy lookup but before forwarding decisions; (3) transmit - packets leaving the egress interface; and (4) drop - packets discarded by any firewall mechanism (policy deny, threat prevention, etc.). The terms 'management,' 'send,' and 'non-syn' do not correspond to valid packet capture stage types in PAN-OS.

Topics

#Packet Capture#Troubleshooting#Firewall Configuration#Diagnostic Tools

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice