PCNSE Practice Question: Managing Troubleshooting and High Availability
A company has deployed two Palo Alto Networks firewalls in an active/passive HA configuration. During a failover test, the engineer notices that the passive firewall did not take over when the active firewall's data plane interface went down. The engineer reviews the HA configuration and sees that the HA1 link is up and the HA2 link is up. What is the most likely reason for the failover not occurring?
⚠ Common exam trap
The trap here is assuming that any interface failure automatically triggers failover; actually, link monitoring must be explicitly enabled on the interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Link monitoring is not enabled on the data plane interface.
Failover in an active/passive HA pair is triggered by link monitoring and path monitoring. If link monitoring is not enabled on the data plane interface that went down, the firewall does not detect the failure and therefore does not initiate a failover. The HA1 and HA2 links being up only ensure control and data synchronization, not failure detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The HA2 link is not configured for session synchronization.
Why it's wrong here
Even if session synchronization were not configured, the firewall should still fail over when a monitored interface fails; however, sessions might not be synchronized, leading to dropped connections. But the question asks why failover did not occur at all. The absence of session sync would not prevent the failover itself, only affect session continuity.
- ✗
The HA1 link is not configured with a backup path.
Why it's wrong here
While a backup HA1 path is recommended for redundancy, its absence does not prevent failover when a data plane interface fails. Failover is triggered by link monitoring and path monitoring, not by the HA1 backup configuration. The HA1 link being up is sufficient for control plane communication; the issue lies elsewhere.
- ✓
Link monitoring is not enabled on the data plane interface.
Why this is correct
For the firewall to trigger a failover when a data plane interface goes down, link monitoring must be enabled on that interface in the HA configuration. Without link monitoring, the firewall does not detect the interface failure and thus does not initiate a failover. This is a common oversight in HA setup.
- ✗
The passive firewall is in a suspended state.
Why it's wrong here
If the passive firewall were suspended, it would not be ready to take over, but the scenario states that the HA1 and HA2 links are up and the passive firewall is otherwise functional. Suspended state usually results from configuration mismatches or licensing issues, which are not indicated here. The more likely cause is missing link monitoring.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.