Courseiva
Device Management and ServiceshardMultiple ChoiceObjective-mapped

PCNSA Device Management and Services Practice Question

A company has a PA-5250 firewall in an active/passive HA pair. During a maintenance window, the administrator upgrades the passive firewall from PAN-OS 10.0 to 10.1. After the upgrade, the passive firewall fails to synchronize with the active firewall. The active firewall remains at 10.0. What is the most likely cause?

⚠ Common exam trap

The trap here is that candidates may focus on connectivity or timer issues (options A or B) rather than recognizing that PAN-OS enforces strict version matching for HA synchronization, even if the passive firewall is upgraded correctly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The PAN-OS versions are different between the HA peers

PAN-OS requires both HA peers to run the same major version to synchronize configuration and state. The active firewall at PAN-OS 10.0 and the passive at 10.1 are incompatible, preventing HA synchronization. Even though the passive firewall was upgraded, the active firewall remains on the older version, breaking the HA session.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The HA2 link is down or misconfigured

    Why it's wrong here

    HA2 link failure would prevent sync, but version mismatch is more likely.

  • The HA keepalive timer is misconfigured

    Why it's wrong here

    Keepalive failure leads to split-brain, not sync failure.

  • The passive firewall has preemption enabled

    Why it's wrong here

    Preemption affects failback, not synchronization.

  • The PAN-OS versions are different between the HA peers

    Why this is correct

    HA peers must run the same PAN-OS version for sync.

About these practice questions

This PCNSA question is part of Courseiva's 516-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.