PCNSE Practice Question: Managing Troubleshooting and High Availability
An engineer is troubleshooting an HA pair where the passive firewall is not receiving session updates. The HA1 link is up and the firewalls are in active/passive mode. The engineer runs 'show high-availability state' and sees 'State: passive' and 'Peer State: active'. Which additional command should the engineer run to verify that session synchronization is enabled and functioning?
⚠ Common exam trap
The trap here is assuming that HA1 and HA2 link status are sufficient, but session synchronization also depends on configuration and can be disabled or failing even with healthy links.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
show high-availability state-synchronization
To verify session synchronization, the engineer should use the command that specifically reports on synchronization state and statistics. 'show high-availability state-synchronization' provides details such as whether synchronization is enabled, the number of synchronized sessions, and any errors. This is the most direct way to confirm if session updates are being sent and received correctly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
show high-availability interface ha2
Why it's wrong here
While this command shows HA2 interface status, it does not confirm whether session synchronization is enabled or functioning at the application level. It is useful for checking link health, but the engineer already knows HA1 is up and the state is correct. The issue may be with synchronization configuration, so a more specific command is needed.
- ✓
show high-availability state-synchronization
Why this is correct
This command displays the session synchronization state and statistics, including whether synchronization is enabled and if there are any errors. It directly addresses the engineer's need to verify that session updates are being sent and received. If synchronization is not working, this command will show details such as packet counts and errors, helping to pinpoint the issue.
- ✗
show session all
Why it's wrong here
This command lists all sessions on the firewall, but it does not indicate whether those sessions are being synchronized to the passive peer. It would show active sessions on the active firewall, but without synchronization, the passive firewall would not have them. However, it does not provide direct insight into the synchronization process itself.
- ✗
show high-availability state
Why it's wrong here
The engineer has already run this command and it only shows the HA state and peer state. It does not provide details about session synchronization. Running it again would not yield additional information. The engineer needs a command that specifically reports on synchronization status and statistics.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.