Courseiva
Manage, Monitor and OperatehardMultiple ChoiceObjective-mapped

PCNSE Manage, Monitor and Operate Practice Question

A firewall is configured with two virtual routers in an active/passive HA pair. The active firewall fails over, and after failover, traffic is not passing through the new active firewall. The interface IP addresses are configured as virtual IPs. What is the most likely cause?

⚠ Common exam trap

Many exam-takers assume routing table synchronization is the issue because traffic stops, but PAN-OS automatically syncs routing tables via HA2, while session synchronization is a separate, optional feature that must be explicitly enabled and is frequently overlooked.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The session table is not synchronized between HA peers.

In an active/passive HA pair with virtual IPs, session table synchronization is required for the passive firewall to take over active sessions seamlessly after a failover. If session synchronization is not enabled or fails, the new active firewall will not have the session state for existing traffic, causing it to drop packets that belong to those sessions. This is the most likely cause because the interface IPs are virtual, so the routing and interface configuration are already in place, but the session state is missing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The session table is not synchronized between HA peers.

    Why this is correct

    Without session synchronization, the new active firewall does not have existing sessions, causing traffic drops.

  • The passive firewall's routing table is not synchronized.

    Why it's wrong here

    HA synchronizes routing tables, so this should not be an issue.

  • The virtual router is not configured to use the virtual IPs.

    Why it's wrong here

    Virtual IPs are automatically assigned to the virtual router in HA.

  • The HA configuration does not include the virtual router.

    Why it's wrong here

    HA synchronizes virtual router configuration between peers.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 504 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.