Courseiva

PCNSE Practice Question: Managing Troubleshooting and High Availability

Exhibit

Refer to the exhibit.

admin@PA-5050> show high-availability state

HA state: active
peer HA state: passive
link status: up
HA1 link status: up
HA2 link status: up
last failure reason: peer HA1 keepalive lost

Based on the exhibit, what caused the last failover?

⚠ Common exam trap

Candidates often confuse the HA1 link (control link for keepalives) with the HA2 link (data link for session sync), leading them to incorrectly select Option A when the actual failover trigger is loss of HA1 keepalive, not HA2 link failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The HA1 keepalive from the peer was lost.

The exhibit shows 'HA1 keepalive from the peer was lost' as the last failover reason. In an active/passive HA pair, the passive firewall monitors HA1 keepalive messages from the active peer. When these keepalives are not received within the configured hello interval (default 1 second) and hold timer (default 3 seconds), the passive firewall assumes the active peer has failed and initiates a failover to become active.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The HA2 link went down.

    Why it's wrong here

    Failover is triggered by HA1 heartbeats and path monitoring, not HA2; HA2 carries session synchronisation between peers, so its failure leaves the active firewall forwarding traffic. It is tempting because HA2 is a physical HA link, and its loss is correct when the question asks why session state is not replicated.

  • ✗

    A preemption event occurred.

    Why it's wrong here

    Preemption only returns an active role to a higher-priority device after it recovers; it does not cause the initial failover itself. Preemption would be correct if the exhibit showed the original active device coming back online and reclaiming the active role from a lower-priority peer.

  • ✗

    The peer firewall was rebooted.

    Why it's wrong here

    A peer reboot is detected through HA1 hello messages and path monitoring, producing a failover only if the peer was active; the exhibit's cause differs. Peer reboot would be the correct answer when logs show HA1 hello timeouts followed by the peer re-establishing as passive.

  • ✓

    The HA1 keepalive from the peer was lost.

    Why this is correct

    The HA1 keepalive carries the heartbeat between peers; its loss makes the firewall conclude the peer is down, triggering failover. The exhibit shows HA1 link failure, so the peer's keepalive never arrived, which is the direct cause of the last failover.

About these practice questions

Courseiva writes every PCNSE question from scratch — 319 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.