PCNSE · Question #362
A traffic log might list an application as "not-applicable" for which two reasons? (Choose two )
The correct answer is A. The firewall did not install the session D. There was not enough application data after the TCP connection was established. A traffic log might list an application as 'not-applicable' if the firewall did not fully establish the session for application identification processing, or if there was insufficient application data exchanged after the TCP connection was established to identify the application.
Question
A traffic log might list an application as "not-applicable" for which two reasons? (Choose two )
Options
- AThe firewall did not install the session
- BThe TCP connection terminated without identifying any application data
- CThe firewall dropped a TCP SYN packet
- DThere was not enough application data after the TCP connection was established
How the community answered
(23 responses)- A96% (22)
- C4% (1)
Why each option
A traffic log might list an application as 'not-applicable' if the firewall did not fully establish the session for application identification processing, or if there was insufficient application data exchanged after the TCP connection was established to identify the application.
If the firewall fails to fully install the session state or context required for deep packet inspection and application identification, the application will be listed as 'not-applicable' because the App-ID engine cannot process it.
This reason is very similar to option D, both pointing to a lack of application data for identification, and is therefore not a distinct second reason.
If a TCP SYN packet is dropped, no session is established for application identification to occur, and the log entry would typically show a deny or drop action, not 'not-applicable' for the application field.
When a TCP connection is established but there is insufficient application data exchanged before the session terminates, the firewall cannot gather enough information to identify the application, resulting in an 'incomplete' or 'not-applicable' status.
Concept tested: Palo Alto Networks App-ID 'not-applicable' status
Source: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/monitoring/use-syslog-for-monitoring/syslog-field-descriptions/traffic-log-fields
Topics
Community Discussion
No community discussion yet for this question.