Courseiva

PCNSA Device Management and Services Practice Question

An organization is deploying a firewall in a high-availability (HA) pair. The administrator wants to ensure that session state is synchronized between the firewalls so that active sessions are not dropped during failover. Which configuration is required?

⚠ Common exam trap

Test-takers frequently confuse Config Sync (which synchronizes configuration files) with Session State Synchronization (which synchronizes active session data), leading them to select Option B instead of C.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Session Setup and State Synchronization under HA configuration

Session state synchronization (also known as stateful failover) requires enabling both Session Setup and State Synchronization under the HA configuration. This ensures that the active firewall's session table is continuously replicated to the passive firewall, so when a failover occurs, existing sessions are not dropped and can continue without interruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure HA1 and HA2 interfaces with appropriate IPs

    Why it's wrong here

    Interfaces are required for HA communication, but they don't enable session sync.

  • ✗

    Enable Config Sync on the HA General tab

    Why it's wrong here

    Config Sync replicates configuration and objects between peers, not runtime session state. It is tempting because it keeps both firewalls consistent, and it would be correct for ensuring identical policy across the pair, but preserving active sessions requires HA2 session synchronisation instead.

  • ✓

    Enable Session Setup and State Synchronization under HA configuration

    Why this is correct

    Enabling Session Setup and State Synchronization under HA configuration replicates session tables and state between peers, so established flows survive failover without re-establishment. Without it, the passive firewall lacks session context and drops active connections during transition.

  • ✗

    Configure Path Monitoring to detect link failures

    Why it's wrong here

    Path Monitoring tracks link and destination reachability to trigger failover; it does not transfer session tables between peers. It is tempting because it improves failover responsiveness, and it would be correct for detecting upstream outages, but session synchronisation requires HA2 configured for state transfer.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.