Courseiva
hardMultiple Select

PCNSA Practice Question: Which THREE of the following are valid features…

Which THREE of the following are valid features of Palo Alto Networks active/passive HA?

⚠ Common exam trap

A common mix-up: candidates confuse active/passive with active/active HA, assuming that both devices share traffic or that the passive device does not participate in monitoring, when in fact active/passive strictly uses one device for forwarding and the other for standby with full monitoring capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session synchronization from active to passive.

In Palo Alto Networks active/passive HA, session synchronization from the active firewall to the passive firewall is a core valid feature, so option A is correct because it keeps the passive device ready to take over established sessions. Option C is correct because active/passive HA provides stateful failover of sessions, meaning the passive device can continue existing flows after failover using synchronized session state. Option D is correct because configuration changes made on the active device are automatically synchronized to the passive device, keeping both peers consistent. Option B is not a valid feature because link monitoring is not prevented on the passive device; HA link and path monitoring behavior is part of the HA configuration and does not simply disable monitoring on the passive peer. Option E is not valid for active/passive HA because load sharing of traffic between both devices describes active/active HA, not active/passive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Session synchronization from active to passive.

    Why this is correct

    Active/passive HA synchronises session tables so the passive device holds matching flow state, enabling seamless takeover. This satisfies the stem's requirement for valid active/passive HA features, since session sync runs continuously from the active peer to the passive peer over the HA links.

  • ✗

    Prevention of link monitoring on passive device.

    Why it's wrong here

    Link monitoring is configured and active on both HA peers, including the passive device, so its prevention is not a feature; disabling it on the passive unit would mask interface failures and prevent failover. It is tempting because passive devices do not forward traffic, yet monitoring still runs there.

  • ✓

    Stateful failover of sessions.

    Why this is correct

    Stateful failover means established sessions survive a failover because their state was synchronised beforehand, so traffic continues without re-establishing connections. This directly satisfies the stem's requirement for a valid active/passive HA feature, distinguishing it from stateless load-balancing alternatives.

  • ✓

    Automatic synchronization of configuration changes.

    Why this is correct

    Configuration changes made on the active device are automatically pushed to the passive peer, keeping both configurations identical. This satisfies the stem's requirement for a valid active/passive HA feature, ensuring the passive firewall can assume the active role immediately without manual configuration reconciliation.

  • ✗

    Load sharing of traffic between both devices.

    Why it's wrong here

    Active/passive HA keeps one firewall handling all traffic while the peer stays on standby, so load sharing does not occur; that behaviour belongs to active/active HA, where both devices forward sessions simultaneously. The naming invites the assumption that both members share traffic.

About these practice questions

One of 385 original PCNSA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.