PCNSE Practice Question: Managing Troubleshooting and High Availability
An administrator runs 'show high-availability state' and sees that the local firewall is in 'passive' state, but the remote firewall shows 'active'. However, the HA1 link is up and the configuration is synchronized. What could cause the passive firewall to not take over after the active fails?
⚠ Common exam trap
Candidates often assume that a functional HA1 link and synchronized configuration guarantee automatic failover, but they overlook the dependency on the HA2 link for state synchronization and failover readiness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The HA2 link is down
If the HA2 link is down, the passive firewall cannot synchronize session state from the active firewall. In Palo Alto Networks HA implementations, the passive firewall requires a functional HA2 link to be considered fully operational and ready to take over; without it, the passive will not assume the active role even if the active fails. The HA1 link ensures heartbeats and configuration synchronization, but state synchronization over HA2 is critical for failover eligibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The configuration is not synchronized
Why it's wrong here
Config sync is separate; state transition does not require it.
- ✗
Session synchronization is not fully complete
Why it's wrong here
Session sync does not affect state transition.
- ✓
The HA2 link is down
Why this is correct
HA2 link is for session sync, not state.
- ✗
Preemptive mode is disabled and the passive firewall has a lower priority
Why it's wrong here
Without preemptive, the passive stays passive unless priority is higher.
Go deeper
Related to this question
About these practice questions
This PCNSE question is part of Courseiva's 504-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.