PCNSE Deploy and Configure Firewalls • Timed 25 Questions
This is a timed practice session. You have 25 minutes to answer 25 questions — approximately 1 minute per question, matching real PCNSE exam pace. Answer every question before time expires.
Time remaining
25:00
Exam-pace drill
Allow 1 minute per question. On the real PCNSE exam you have approximately 72 seconds per question — this session trains you to maintain that pace under pressure.
You are deploying a pair of PA-5250 firewalls in active/passive HA mode for a large enterprise. The firewalls are configured with multiple virtual routers (VRs) to segment traffic: VR-A for internal corporate network, VR-B for DMZ, and VR-C for Internet edge. Each VR is associated with a separate Vsys. The HA pair uses IPsec tunnel monitoring to determine failover. The customer reports that after a recent configuration change, failover does not occur when the primary firewall's Internet-facing interface (ethernet1/1) goes down. You verify that the primary firewall detects the interface failure, but the secondary does not take over. The HA configuration shows: 'monitor failure only' set to 'link-status', 'monitor hold time' 1000ms, 'promotion hold time' 2000ms, and 'monitor failure condition' is 'any'. The IPsec tunnel monitoring is configured for tunnel to a remote site. The path monitoring includes the Internet-facing interface under VR-C. What is the most likely reason for the failover failure?
25 minute time limit — choose an answer to begin.
25 questions · 25 minute exam-pace drill.