Palo_Alto_NetworksPalo_Alto_Networks
PCNSE · Question #547
PCNSE Question #547: Real Exam Question with Answer & Explanation
Sign in or unlock PCNSE to reveal the answer and full explanation for question #547. The question stem and answer options stay visible for context.
Submitted by satoshi_tk· Apr 18, 2026Configuration Troubleshooting
Question
A network engineer has discovered that asymmetric routing is causing a Palo Alto Networks firewall to drop traffic. The network architecture cannot be changed to correct this. Which two actions can be taken on the firewall to allow the dropped traffic permanently? (Choose two.)
Options
- ANavigate to Network > Zone Protection Click Add Select Packet Based Attack Protection >
- B> set session tcp-reject-non-syn no
- CNavigate to Network > Zone Protection Click Add Select Packet Based Attack Protection >
- D# set deviceconfig setting session tcp-reject-non-syn no
Unlock PCNSE to see the answer
You've previewed enough free PCNSE questions. Unlock PCNSE for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Asymmetric Routing#Session Settings#Zone Protection Profiles#TCP Handling