Courseiva
Deploy and Configure FirewallsmediumMultiple ChoiceObjective-mapped

PCNSE Deploy and Configure Firewalls Practice Question

A company is deploying a new firewall in active/passive high availability. The two firewalls are connected directly via the HA1 and HA2 interfaces. After configuration, the passive firewall shows 'HA state: passive' but the active firewall shows 'HA state: non-functional'. What is the most likely cause?

⚠ Common exam trap

It's easy for candidates to assume the HA1 link is the critical path for all HA functionality, but in active/passive mode, the HA2 link is essential for session state synchronization, and its failure causes the active firewall to report 'non-functional' even if HA1 is operational.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The HA2 link is down or misconfigured.

In active/passive HA, the HA2 link is used for session synchronization and state propagation. If the HA2 link is down or misconfigured, the active firewall cannot synchronize session state to the passive unit, causing it to report 'non-functional' even though the passive unit sees itself as 'passive'. The HA1 link handles heartbeats and configuration sync, which may still be operational, but without a functional HA2 link, the HA pair cannot maintain proper state synchronization, leading to the active firewall's non-functional state.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The HA1 link is down or misconfigured.

    Why it's wrong here

    HA1 is for heartbeat; if down, the firewalls would not form a pair.

  • The HA2 link is being used for management traffic.

    Why it's wrong here

    HA2 should be dedicated for synchronization; management traffic should not be sent over it.

  • The preemptive setting is enabled on both firewalls.

    Why it's wrong here

    Preemption determines which firewall becomes active; it does not cause a non-functional state.

  • The HA2 link is down or misconfigured.

    Why this is correct

    HA2 is required for session synchronization; if it fails, the active firewall reports non-functional.

About these practice questions

This PCNSE question is part of Courseiva's 504-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.