Courseiva

PCNSA Device Management and Services Practice Question

A company has a PA-5250 firewall in an active/passive HA pair. During a maintenance window, the administrator upgrades the passive firewall from PAN-OS 10.0 to 10.1. After the upgrade, the passive firewall fails to synchronize with the active firewall. The active firewall remains at 10.0. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates may focus on connectivity or timer issues (options A or B) rather than recognizing that PAN-OS enforces strict version matching for HA synchronization, even if the passive firewall is upgraded correctly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The PAN-OS versions are different between the HA peers

PAN-OS requires both HA peers to run the same major version to synchronize configuration and state. The active firewall at PAN-OS 10.0 and the passive at 10.1 are incompatible, preventing HA synchronization. Even though the passive firewall was upgraded, the active firewall remains on the older version, breaking the HA session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The HA2 link is down or misconfigured

    Why it's wrong here

    HA2 link failure would break state synchronisation, but the passive firewall was upgraded to 10.1 while the active remains on 10.0; PAN-OS requires matching versions for HA synchronisation. HA2 misconfiguration tempts because it commonly causes sync failures, yet here the version mismatch is the direct cause.

  • ✗

    The HA keepalive timer is misconfigured

    Why it's wrong here

    Keepalive timers govern heartbeat failure detection, not configuration synchronisation between peers. The passive firewall runs PAN-OS 10.1 while the active runs 10.0, and mismatched versions prevent HA sync. Timer misconfiguration tempts because it causes HA problems, but it would not produce this version-specific failure.

  • ✗

    The passive firewall has preemption enabled

    Why it's wrong here

    PAN-OS requires matching major versions for HA configuration synchronisation, so a 10.0 active peer cannot sync with a 10.1 passive peer regardless of preemption. Preemption only governs which firewall assumes the active role after failover, making it the right setting to tune when controlling failback order, not version compatibility.

  • ✓

    The PAN-OS versions are different between the HA peers

    Why this is correct

    PAN-OS HA peers must run identical software versions; configuration synchronisation and HA state negotiation fail when one peer runs 10.1 and the other 10.0. The passive device cannot sync until it is downgraded or the active peer is upgraded to match.

About these practice questions

This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.