Palo Alto Networks Certified Network Security Engineer (PCNSE)TroubleshootMedium

A network administrator is investigating a report of intermittent application failures for a critical internal web application. The Palo Alto Networks firewall is configured with a security policy allowing the application, and initial checks show traffic hitting the policy. However, logs indicate some sessions are being reset by the firewall. The administrator suspects a threat prevention profile might be aggressively blocking legitimate traffic. Which type of security profile is MOST likely causing the legitimate application traffic to be reset?

  1. AFile Blocking Profile
  2. BURL Filtering Profile
  3. CVulnerability Protection Profile
  4. DData Filtering Profile
Show answer & explanation

Correct answer: C. Vulnerability Protection Profile

A Vulnerability Protection Profile is designed to detect and prevent exploit attempts. If configured too aggressively or with signatures that are overly broad, it can mistakenly identify legitimate application traffic as an exploit and reset the session. This is a common cause for intermittent application failures when threat prevention is enabled.

Why the other options are wrong

  • A. File Blocking prevents specific file types from being downloaded/uploaded, not usually causing general application session resets unless a critical file transfer is involved.
  • B. URL Filtering blocks access to entire websites or categories, not typically causing session resets for valid application traffic unless the application itself tries to access a blocked URL.
  • D. Data Filtering prevents sensitive data from leaving the network, which would typically block data transfer, not reset the underlying application session for general failures.

Vulnerability Protection False Positives

Vulnerability Protection profiles, when configured aggressively, can sometimes generate false positives by misidentifying legitimate application traffic as exploit attempts, leading to session resets.

  • Uses signatures to detect exploits.
  • Can be configured with different actions (alert, reset, block).
  • Aggressive settings increase risk of false positives.

Memory trick: The firewall thinks the app is attacking, so it shuts it down!

More Troubleshoot questions