mediumMultiple ChoiceObjective-mapped
PCNSA Practice Question: A medium-sized enterprise recently deployed a…
A medium-sized enterprise recently deployed a pair of PA-5250 firewalls in an active/passive high-availability configuration. The network team notices that after a failover event, the new active firewall does not pass any traffic for about 30 seconds, even though the session table is synchronized. Users report that existing connections break and need to be re-established. The firewall is configured to use session state synchronization and failover triggers based on link state and ping to the next-hop gateway. Which action should the administrator take to minimize traffic disruption during failover?
⚠ Common exam trap
Many candidates confuse the cause of traffic disruption after failover with detection speed (path monitoring timers) or resource exhaustion (buffer size), rather than recognizing it as a session lookup issue that asymmetric path bypass directly addresses.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure asymmetric path bypass on the high-availability settings.
Asymmetric path bypass allows the new active firewall to accept and forward packets for existing sessions even before the session table is fully synchronized or the routing converges. In an active/passive HA pair, after failover, the new active firewall may receive packets for flows that were originally processed by the previous active unit; without asymmetric path bypass, these packets are dropped because the firewall does not recognize them as part of an existing session. Enabling this feature ensures that the firewall temporarily bypasses session lookup for such packets, reducing the 30-second traffic blackout.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure asymmetric path bypass on the high-availability settings.
Why this is correct
Asymmetric path bypass allows the new active firewall to forward packets even if the return path is not synchronized immediately, reducing the window of traffic loss.
- ✗
Increase the packet buffer size on the firewall to handle burst traffic.
Why it's wrong here
Increasing packet buffer size does not address the delay in traffic forwarding after failover.
- ✗
Reduce the hold timer for path monitoring to the next-hop gateway.
Why it's wrong here
Reducing the hold timer may cause false positive failovers and does not address the initial 30-second delay after failover.
- ✗
Enable preemptive mode for the active/passive HA pair.
Why it's wrong here
Preemptive mode causes the original active firewall to resume control when it recovers, leading to another failover and additional disruption.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSA question from scratch — 516 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.