Exam PCNSE All QuestionsBrowse all questions from this exam
Question 125

The firewall determines if a packet is the first packet of a new session or if a packet is part of an existing session using which kind of match?

    Correct Answer: B

    The firewall typically uses a 5-tuple match to determine if a packet is the first packet of a new session or part of an existing session. The 5-tuple includes the Source IP Address, Destination IP Address, Source Port, Destination Port, and Protocol. This combination is sufficient to uniquely identify a session in network communications.

Discussion
MS_NWOption: A

A On a Palo Alto Networks firewall, a session is defined by two uni-directional flows each uniquely identified by a 6-tuple key: source-address, destination-address, source-port, destination-port, protocol, and security-zone. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVECA0

PaloSteve

This is an AMAZING article to get to know a session in DETAIL.

mmedOption: A

confirm A

certprep2021Option: A

A https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVECA0

MarshpillowzOption: A

A is correct

SarbiOption: B

It is always 5 tuples.