PCNSA Device Management and Services Practice Question
An organization is deploying a firewall in a high-availability (HA) pair. The administrator wants to ensure that session state is synchronized between the firewalls so that active sessions are not dropped during failover. Which configuration is required?
⚠ Common exam trap
Test-takers frequently confuse Config Sync (which synchronizes configuration files) with Session State Synchronization (which synchronizes active session data), leading them to select Option B instead of C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Session Setup and State Synchronization under HA configuration
Session state synchronization (also known as stateful failover) requires enabling both Session Setup and State Synchronization under the HA configuration. This ensures that the active firewall's session table is continuously replicated to the passive firewall, so when a failover occurs, existing sessions are not dropped and can continue without interruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure HA1 and HA2 interfaces with appropriate IPs
Why it's wrong here
Interfaces are required for HA communication, but they don't enable session sync.
- ✗
Enable Config Sync on the HA General tab
Why it's wrong here
Config Sync replicates configuration and objects between peers, not runtime session state. It is tempting because it keeps both firewalls consistent, and it would be correct for ensuring identical policy across the pair, but preserving active sessions requires HA2 session synchronisation instead.
- ✓
Enable Session Setup and State Synchronization under HA configuration
Why this is correct
Enabling Session Setup and State Synchronization under HA configuration replicates session tables and state between peers, so established flows survive failover without re-establishment. Without it, the passive firewall lacks session context and drops active connections during transition.
- ✗
Configure Path Monitoring to detect link failures
Why it's wrong here
Path Monitoring tracks link and destination reachability to trigger failover; it does not transfer session tables between peers. It is tempting because it improves failover responsiveness, and it would be correct for detecting upstream outages, but session synchronisation requires HA2 configured for state transfer.
Go deeper
Related to this question
About these practice questions
One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.