PCNSE Practice Question: Managing Troubleshooting and High Availability
After a failover event, some user sessions are reset. The HA pair is configured for Active/Active with session distribution using a hash algorithm. What is the most likely reason for session resets?
⚠ Common exam trap
Test-takers frequently confuse session synchronization with routing redistribution or assume that Active/Active inherently shares session state, when in fact session synchronization must be explicitly configured and is not automatic even in Active/Active mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session synchronization is not configured between the HA peers
In an Active/Active HA pair with session distribution based on a hash algorithm, each firewall handles a subset of traffic flows. Without session synchronization between the peers, the backup firewall has no session table entries for flows hashed to the primary. After a failover, the backup firewall sees these packets as new connections and resets them because it lacks the state information required to continue the existing sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Session offload is not enabled on the passive firewall
Why it's wrong here
No such feature.
- ✗
Packet Buffer Protection threshold was exceeded
Why it's wrong here
Buffer protection affects packets, not session state.
- ✓
Session synchronization is not configured between the HA peers
Why this is correct
Without session sync, active firewall's sessions are unknown to the other.
- ✗
The routing table is not redistributed after failover
Why it's wrong here
Routing convergence is separate.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 504 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.