Courseiva

CCNA Managing Troubleshooting and High Availability Questions

39 questions · Managing Troubleshooting and High Availability · All types, answers revealed

1
MCQeasy

An administrator is troubleshooting a Palo Alto Networks firewall and needs to view the current sessions that are active on the firewall. The administrator wants to see details such as source and destination IP addresses, application, and security policy applied. Which CLI command should the administrator use?

A.show running session all
B.show session info
C.show session all
D.show session table
AnswerC

The 'show session all' command displays all active sessions on the firewall, including source and destination IP addresses, application, security policy, and other details. It is the primary command for viewing the session table. This command provides a comprehensive list, which can be filtered further if needed. Therefore, it meets the administrator's requirement to view current sessions with the specified details.

Why this answer

The 'show session all' command is the correct CLI command to display all active sessions on a Palo Alto Networks firewall, including source and destination IP addresses, application, and the security policy applied. It provides the detailed session information the administrator needs to troubleshoot or monitor current traffic.

Exam trap

The trap here is confusing similar-sounding commands like 'show session info' with 'show session all', where the former only provides summary statistics and not detailed session listings.

2
Multi-Selectmedium

An organization has configured an active/passive high availability pair of Palo Alto Networks firewalls. During a maintenance window, the active firewall was rebooted. After the reboot, the passive firewall became active, but the session table on the original active firewall is incomplete. The administrator notices that session synchronization is not working properly. Which two configuration checks should the technician perform to resolve this issue?

Select 2 answers
A.Check that the session synchronization encryption is disabled to reduce latency.
B.Validate that the heartbeat hold timer is set to a value greater than the failover delay.
C.Confirm that the HA1 link is using the correct IP address and is in the same subnet.
D.Verify that the HA2 link is operational and has sufficient bandwidth.
E.Ensure that the HA firewalls have the same software version and that session synchronization is enabled in the HA configuration.
AnswersD, E

The HA2 link is dedicated to session synchronization; if it is down or congested, sync fails.

Why this answer

Session synchronization in an active/passive HA pair uses the HA2 link (or HA2 backup) to replicate session tables between firewalls. If the HA2 link is down, has insufficient bandwidth, or is misconfigured, session synchronization will fail, causing the newly active firewall to have an incomplete session table after a failover. Verifying that the HA2 link is operational and has sufficient bandwidth is therefore a critical first step in troubleshooting this issue.

Exam trap

The trap here is that candidates often confuse the HA1 and HA2 link roles, assuming that checking the HA1 link (used for heartbeats and configuration sync) will resolve session synchronization issues, when in fact session replication relies exclusively on the HA2 link.

3
Multi-Selecteasy

Which TWO statements about active/active HA mode are true compared to active/passive mode? (Choose two.)

Select 2 answers
A.Active/active eliminates the need for failover
B.Active/active requires enabling asymmetric routing support
C.Active/active allows both firewalls to process traffic simultaneously
D.Active/active automatically synchronizes configuration changes
E.Active/active is the default and most commonly deployed mode
AnswersB, C

In active/active HA, both firewalls simultaneously hold sessions and forward traffic, so return packets may traverse a different device than the original flow. Enabling asymmetric routing support lets each peer forward such traffic without dropping it, a requirement absent in active/passive.

Why this answer

In active/active HA mode, both firewalls can process traffic simultaneously, which requires enabling asymmetric routing support to handle traffic that may arrive at either firewall for the same session. This is necessary because active/active mode does not enforce a single path for traffic, unlike active/passive mode where only one firewall actively processes traffic.

Exam trap

The trap here is that candidates often assume active/active mode eliminates the need for failover or is the default mode, but in reality, failover is still required and active/passive is the default; the key differentiator is the need for asymmetric routing support in active/active mode.

4
MCQhard

A medium-sized enterprise has two Palo Alto Networks PA-5250 firewalls configured in an active/passive HA pair with session synchronization and configuration synchronization enabled. The HA1 link is a direct copper cable, and the HA2 link is also a direct copper cable. The firewalls are connected to two upstream routers (R1 and R2) and two downstream switches (S1 and S2). The network uses OSPF for dynamic routing. The active firewall (FW-A) is connected to R1 and S1, while the passive firewall (FW-P) is connected to R2 and S2. The OSPF cost is set symmetrically on both sides. During a maintenance window, the network team shuts down the HA1 and HA2 links on both firewalls to test failover behavior. After the links are brought back up, the firewalls are in a state of 'non-functional' and 'suspended'. The team suspects the HA configuration is broken. What is the most likely cause and the best course of action to restore HA?

A.Upgrade both firewalls to the same software version and then re-initialize HA
B.Change the HA mode to active/active and enable asymmetric routing
C.Reboot both firewalls after verifying the HA configuration and that the links are operationally up
D.Configure a dedicated management interface for HA1 communication and ensure HA2 is on a different subnet
AnswerC

Rebooting recovers from suspended state; links are up now.

Why this answer

When both HA1 and HA2 links are simultaneously shut down on both firewalls, the active/passive pair loses all communication and session synchronization. Upon restoration, the firewalls enter a 'non-functional' and 'suspended' state because the HA control plane cannot re-establish a quorum or verify the peer's state without a full reset of the HA state machine. Rebooting both firewalls after verifying the HA configuration and that the links are operationally up forces a clean initialization of the HA process, clearing the suspended state and allowing the pair to renegotiate roles correctly.

Exam trap

The trap here is that candidates assume re-establishing the HA links alone will automatically restore the HA pair, but PAN-OS requires a full reboot of both firewalls to clear the suspended state after a simultaneous HA link failure, as the state machine does not have a built-in recovery mechanism for this scenario.

How to eliminate wrong answers

Option A is wrong because upgrading software versions is irrelevant to the immediate issue; the firewalls were already running the same version before the test, and the problem is a state machine lockup, not a version mismatch. Option B is wrong because changing to active/active mode does not resolve a suspended state caused by HA link disruption; it would require a different configuration and does not address the core issue of HA state recovery. Option D is wrong because dedicating a management interface for HA1 or changing subnets does not fix the current suspended state; HA1 and HA2 were already on direct copper cables, and the problem is not about subnet overlap but about the HA process needing a full restart after simultaneous link loss.

5
MCQhard

During a network incident, an engineer notices that after an HA failover, some sessions are not active on the new active firewall. The 'show session all' command shows the sessions with state 'half-closed'. What is the most likely cause?

A.The firewall failed to properly synchronize the TCP sessions before the failover
B.The HA2 link failover timer is set too low
C.The ARP timeout on the next-hop router is too short
D.Asymmetric routing is causing the firewall to see only one direction of traffic
AnswerA

Incomplete sync leads to half-closed sessions.

Why this answer

The 'half-closed' session state indicates that the firewall has only one side of the TCP handshake (FIN or RST) recorded, which typically occurs when session synchronization fails during an HA failover. In an active/passive HA pair, TCP session state information is synchronized via the HA2 link; if synchronization is incomplete or interrupted before the failover, the new active firewall will have partial session data, leading to half-closed sessions. This is a common symptom of a synchronization failure, not a timeout or routing issue.

Exam trap

The trap here is that candidates confuse 'half-closed' with 'incomplete' or 'asymmetric routing' symptoms, but 'half-closed' specifically indicates a TCP state where one side has initiated closure, which in an HA context points to incomplete session synchronization rather than a routing or ARP issue.

How to eliminate wrong answers

Option B is wrong because the HA2 link failover timer controls how quickly the passive firewall detects a failure of the active firewall, not the synchronization of session states; a low timer might cause premature failover but does not directly cause half-closed sessions. Option C is wrong because the ARP timeout on the next-hop router affects layer 2 reachability and could cause traffic black-holing after failover, but it does not impact the TCP session state stored on the firewall; half-closed sessions are a session table issue, not an ARP issue. Option D is wrong because asymmetric routing would cause the firewall to see only one direction of traffic, leading to sessions in a 'half-baked' or 'incomplete' state (not 'half-closed'), and it is not directly related to HA failover synchronization; asymmetric routing is a network design problem, not a post-failover session state issue.

6
MCQeasy

A network engineer is troubleshooting an HA pair where both firewalls show as 'active' in the HA state. What is this condition called?

A.Link failure
B.Active/Active
C.Passive/Passive
D.Split brain
AnswerD

Both peers believing they are active defines split brain, caused by loss of the HA heartbeat link while dataplane traffic still flows. Each firewall independently assumes the active role, producing duplicate sessions and conflicting state. The stem's symptom of two simultaneous 'active' states is precisely this condition.

Why this answer

In a Palo Alto Networks active/passive HA configuration, if the heartbeat fails, both firewalls assume the other is down and both transition to 'active' state. This unintended condition is called split brain. It is not a valid configuration like Active/Active, which is intentionally configured and requires separate virtual routers or security zones.

Exam trap

The trap is that candidates may think both firewalls being active indicates Active/Active mode, but in an active/passive pair, this is a split-brain failure condition.

How to eliminate wrong answers

Option A is wrong because a link failure is a potential cause of split brain, not the condition itself. Option C is wrong because passive/passive is not a valid HA state in Palo Alto Networks firewalls; the supported modes are active/passive and active/active (for specific use cases). Option D is wrong because split brain is the correct term for both firewalls being active simultaneously, not a separate option.

7
MCQhard

An engineer is troubleshooting an active/passive HA pair where the passive firewall is not receiving session synchronization updates from the active firewall. The HA2 link is up, and the HA1 link is healthy. The engineer checks the HA configuration and sees that the HA2 interface is configured with an IP address, and session synchronization is enabled. What is the most likely cause of the synchronization failure?

A.Session synchronization is disabled on the active firewall.
B.The HA2 interface is configured in a different subnet on each firewall.
C.The HA2 interface is not assigned to a security zone.
D.The HA2 interface is configured as a Layer 2 interface instead of Layer 3.
AnswerB

For HA2 synchronization to work, the HA2 interfaces on both firewalls must be in the same subnet. If they are in different subnets, they cannot communicate directly, and session synchronization will fail. This is a common misconfiguration that can prevent the passive firewall from receiving session updates.

Why this answer

The HA2 interfaces must be in the same subnet for session synchronization to occur. If they are in different subnets, the firewalls cannot establish a direct connection for synchronization, even if the link is physically up. This is a common configuration error that leads to synchronization failure.

Exam trap

The trap here is overlooking the subnet requirement for HA2; engineers often focus on link status and session sync enablement but forget that IP addressing must be in the same subnet.

8
MCQmedium

An engineer is troubleshooting an active/passive HA pair where the passive firewall is not receiving session synchronization updates. The engineer runs 'show high-availability state' on both firewalls and sees that the HA2 link is down. Which action should the engineer take first to resolve the issue?

A.Restart the HA services on both firewalls.
B.Verify that the HA2 interface is configured with the correct IP address and is in the same subnet as the peer.
C.Ensure that the HA2 link is configured for encryption.
D.Check the physical cabling and switch port configuration for the HA2 link.
AnswerD

If the HA2 link is down, the most common cause is a physical connectivity issue, such as a bad cable, incorrect switch port configuration, or a failed interface. Checking the physical layer first is a logical troubleshooting step to quickly identify and resolve the problem.

Why this answer

When an HA2 link is down, the first step is to check the physical connectivity, including cables, switch ports, and interface status. This is because the most common causes of a down link are physical issues. Once the physical layer is verified, other configuration aspects can be checked.

Exam trap

The trap here is jumping to configuration or software fixes before verifying the physical layer, which is often the simplest cause.

9
MCQhard

A network engineer is configuring HA on a pair of PA-5220 firewalls. The HA1 link is configured over a dedicated interface, and HA1 backup is configured over the management interface. The engineer wants to ensure that HA1 control traffic is encrypted and authenticated. Which action should be taken?

A.Enable SSL/TLS on the HA1 interface.
B.Use SSH to tunnel HA1 traffic.
C.Enable HA1 encryption and authentication in the HA settings.
D.Configure IPsec on the HA1 interface.
AnswerC

HA1 encryption and authentication can be enabled in the HA configuration to secure control traffic. This ensures that HA1 packets are encrypted and authenticated, preventing unauthorized access and tampering. It is a best practice for HA1 links that traverse untrusted networks. The engineer should enable this feature in the HA1 configuration settings, which applies to both HA1 and HA1 backup links.

Why this answer

HA1 encryption and authentication is a built-in feature that secures control traffic between HA peers. It uses a pre-shared key to encrypt and authenticate HA1 packets, protecting against eavesdropping and tampering. This is the recommended method when HA1 traverses untrusted networks, such as when using the management interface as HA1 backup.

Other options like IPsec or SSH are not applicable to HA1.

Exam trap

The trap here is thinking that generic VPN or tunneling technologies are needed, but the firewall has a dedicated HA1 encryption option that is simpler and purpose-built.

10
MCQeasy

Refer to the exhibit. What is the primary cause of the 'non-functional' state?

A.The configuration sync operation has failed
B.One firewall is not running
C.HA1 link failure between 10.1.1.1 and 10.1.1.2
D.The configuration on the two firewalls is not identical
AnswerD

Identical configuration is mandatory for an active/passive HA pair to form and synchronise state. Any divergence in interfaces, zones or policies prevents the peer from reaching a functional state, directly causing the non-functional status shown.

Why this answer

The 'non-functional' state in a Palo Alto Networks HA pair indicates that the configuration synchronization (config sync) has failed because the configurations on the two firewalls are not identical. This is a prerequisite for HA operation; if the configurations differ, the HA pair cannot establish a functional sync state, even if HA1 and HA2 links are up.

Exam trap

The trap here is that candidates often confuse 'non-functional' with a link failure or peer down state, but the 'non-functional' state is uniquely tied to configuration synchronization issues, not connectivity or hardware failures.

How to eliminate wrong answers

Option A is wrong because a configuration sync operation failure is a symptom, not the primary cause; the root cause is the configuration mismatch itself. Option B is wrong because if one firewall were not running, the HA state would show 'down' or 'disconnected', not 'non-functional'. Option C is wrong because an HA1 link failure would result in a 'suspended' or 'down' state for the HA link, not a 'non-functional' state for the HA pair; the HA pair can still be functional with a single HA link if HA2 is available.

11
MCQmedium

Based on the exhibit, what is the impact of the current HA state on the network?

A.Configuration changes are not synchronized
B.The passive firewall will preempt the active when the active fails
C.Sessions will not be preserved during a failover
D.The HA pair cannot perform a failover
AnswerC

HA2 is down, causing session synchronization to fail. Consequently, existing sessions are lost during a failover.

Why this answer

The exhibit shows that the HA pair's session synchronization is not synchronized (for example, the HA2 data link is down or session synchronization is disabled). In active/passive HA, session preservation requires session synchronization. Because sessions are not synchronized between the peers, a failover will drop existing sessions, so sessions will not be preserved.

Exam trap

PCNSE HA questions require reading the exhibit carefully: distinguish between configuration synchronization (HA1 control link) and session synchronization (HA2 data link). A failed HA2 link or disabled session sync means sessions are not preserved on failover, but a failed HA1 link means configuration changes are not synchronized. Candidates must identify which link/state the exhibit actually shows before selecting an answer.

How to eliminate wrong answers

Option A is wrong because configuration changes are typically synchronized in HA regardless of session state, unless there is a synchronization issue. Option B is wrong because preemption is a configured behavior, not an impact of the current state; the passive firewall will only preempt if preemption is enabled and the active fails. Option D is wrong because the HA pair can still perform a failover; the state might affect session preservation but not the ability to failover.

12
MCQmedium

During an HA failover, the new active firewall's session table is empty, causing all existing connections to be dropped. Which configuration change would prevent this?

A.Configure HA3 for stateful inspection.
B.Increase HA1 keepalive timer.
C.Enable config sync on HA1.
D.Enable session sync on HA2.
AnswerD

Session sync replicates the active firewall's session table to the passive peer over the HA2 link, so after failover existing flows are already known and continue without re-establishment. Without HA2 session synchronisation, the newly active device has no state and drops all established connections.

Why this answer

Enabling session sync on the HA2 link ensures that session state information is continuously replicated from the active firewall to the standby firewall. During a failover, the new active firewall already has the session table populated, so existing connections are preserved and not dropped. Without session sync, the standby firewall starts with an empty session table, causing all existing TCP/UDP sessions to be torn down.

Exam trap

The trap here is confusing configuration synchronization (config sync) with session state synchronization (session sync), leading candidates to incorrectly select config sync on HA1 as the solution for preserving active connections during failover.

How to eliminate wrong answers

Option A is wrong because HA3 is the management link used for control-plane traffic like configuration synchronization and keepalives, not for session state synchronization; stateful inspection is a firewall feature unrelated to HA session sync. Option B is wrong because increasing the HA1 keepalive timer only affects how quickly the firewall detects a peer failure, but does not prevent session loss after failover; it may actually delay failover detection. Option C is wrong because config sync on HA1 synchronizes configuration objects (policies, objects) between peers, not dynamic session state; session tables are not part of configuration sync.

13
MCQmedium

A network security engineer is troubleshooting a Palo Alto Networks firewall that is dropping traffic to a critical internal server. The engineer runs 'show session all filter destination 10.1.1.50' and sees sessions in the 'discard' state. The engineer wants to determine why these sessions are being discarded. Which action should the engineer take next?

A.Run 'show session id <session-id>' to view detailed session information including the discard reason.
B.Run 'show running resource-monitor' to check if the firewall is under resource stress.
C.Run 'show counter global filter severity drop' to identify the global counters that are incrementing.
D.Run 'debug dataplane packet-diag set filter match destination 10.1.1.50' to capture packets and analyze them.
AnswerA

The 'show session id' command displays detailed information about a specific session, including the reason it was discarded, such as policy deny, application identified as unknown, or threat detection. This is the correct next step to diagnose why sessions are in the discard state.

Why this answer

The 'show session id' command provides detailed session information, including the discard reason, which is essential for troubleshooting why sessions are in the discard state. The other commands either provide aggregate data or require additional steps to correlate with the specific session, making them less efficient for this scenario.

Exam trap

The trap here is assuming that global counters or packet captures directly reveal the discard reason, when in fact session-specific details are needed.

14
MCQeasy

When configuring High Availability on a Palo Alto Networks firewall, which of the following is a best practice for the HA1 control link?

A.Use the management interface (MGT) for HA1
B.Configure HA1 as a subinterface on the HA2 link
C.Configure HA1 over a VLAN on a data interface to save ports
D.Use a dedicated physical interface for HA1, not shared with data traffic
AnswerD

HA1 carries heartbeat and synchronisation control traffic between peers. Sharing it with data traffic lets a saturated data path delay or drop heartbeats, causing false failover; a dedicated physical interface isolates control-plane traffic and satisfies the HA1 best-practise requirement.

Why this answer

The HA1 control link carries critical heartbeat and synchronization traffic between the two firewalls in an active/passive or active/active HA pair. Using a dedicated physical interface ensures that control traffic is isolated from data traffic, preventing congestion or interference that could cause false failovers or synchronization delays. The management interface (MGT) is not recommended for HA1 because it shares the control plane CPU and can be overwhelmed by management traffic, leading to HA instability.

Exam trap

The trap here is that candidates often assume the MGT interface is acceptable for HA1 because it is a separate interface, but Palo Alto Networks explicitly recommends against it due to control plane resource contention and the risk of HA failure during management spikes.

How to eliminate wrong answers

Option A is wrong because the MGT interface is designed for out-of-band management and should not be used for HA1; it shares the control plane CPU and can cause HA heartbeat failures under heavy management load. Option B is wrong because HA1 cannot be configured as a subinterface on the HA2 link; HA2 is a dedicated data link for session and state synchronization, and subinterfaces are not supported for HA control traffic. Option C is wrong because configuring HA1 over a VLAN on a data interface violates the best practice of isolating control traffic; data interface VLANs carry user traffic and can introduce latency or packet loss that disrupts HA heartbeat timing.

15
MCQeasy

An HA pair is configured with Active/Passive mode. The passive firewall fails to become active after the active firewall's management interface goes down. What is the most likely cause?

A.HA1 keepalive failure is not detected
B.Management interface failure is not a monitored condition by default
C.HA2 link monitoring is not enabled
D.Session synchronization is not complete
AnswerB

Management interface down does not trigger HA failover unless explicitly configured under device HA.

Why this answer

In an Active/Passive HA pair, the passive firewall monitors the active firewall's liveness via the HA1 control link. By default, only the HA1 link failure triggers a failover; the management interface is not monitored for HA state transitions. Therefore, if the management interface goes down but the HA1 link remains up, the passive firewall does not detect a failure and will not become active.

Exam trap

The trap here is that candidates assume any interface failure triggers HA failover, but Palo Alto Networks HA only monitors interfaces explicitly configured as monitored interfaces; the management interface is not monitored by default.

How to eliminate wrong answers

Option A is wrong because HA1 keepalive failure is detected via the HA1 control link; if the management interface goes down but HA1 remains up, keepalives continue, so no failure is detected. Option C is wrong because HA2 link monitoring is used for data link path monitoring and session synchronization, not for triggering failover in Active/Passive mode; failover is based on HA1 keepalive failure or monitored interface failure, not HA2. Option D is wrong because session synchronization completeness does not affect failover triggering; the passive firewall will not become active unless it detects a failure condition, regardless of sync state.

16
MCQmedium

An engineer is deploying a new Palo Alto Networks firewall running PAN-OS 10.1 as a standalone device. The security team requires that the firewall forward syslog messages to an external server. After configuring the Syslog server profile and applying it to a Log Forwarding profile, the engineer notices that no logs are being received on the syslog server. The firewall's management interface can reach the syslog server on UDP port 514. Which action should the engineer take to resolve this issue?

A.Add the syslog server's IP address to the firewall's management interface permitted IP list.
B.Enable logging on the security policy rules that should generate the logs.
C.Configure a security policy rule that allows the management interface to send traffic to the syslog server.
D.Configure a NAT policy to translate the firewall's management IP to an external IP address.
AnswerB

For logs to be forwarded, the originating security policy rules must have logging enabled at session end or at session start. Without logging enabled, no traffic logs are generated, so nothing is sent to the syslog server. Even if the Syslog server profile and Log Forwarding profile are correctly configured, the absence of logs means no forwarding occurs. Enabling logging on the relevant security rules is the necessary step.

Why this answer

Log forwarding requires that the relevant security policy rules have logging enabled. Without logging, no traffic logs are generated, so nothing is sent to the syslog server even if the Syslog server profile and Log Forwarding profile are properly configured. Enabling logging on the security rules that handle the traffic of interest ensures that logs are created and then forwarded according to the Log Forwarding profile.

Exam trap

The trap here is assuming that configuring the Syslog server profile and Log Forwarding profile alone is sufficient, while overlooking that the security policy rules must have logging enabled to generate the logs.

17
MCQhard

In an Active/Passive HA pair, the passive firewall reports 'non-functional' state. The 'show high-availability state' output on the passive shows 'state: non-functional' and 'reason: configuration mismatch'. The active firewall shows 'state: active' and 'reason: no reason'. Which action should be taken to resolve the issue without disrupting traffic?

A.Run 'request high-availability sync-to-remote' from the active firewall
B.Restart the HA process on the passive firewall with 'debug software restart high-availability'
C.Failover the active firewall to force re-sync
D.Upgrade both firewalls to the same PAN-OS version
AnswerA

Running `request high-availability sync-to-remote` from the active firewall pushes the running configuration to the passive peer, resolving the configuration mismatch that forces the passive into non-functional state. Because the passive is already not passing traffic, synchronising it cannot disrupt existing sessions, satisfying the no-disruption constraint.

Why this answer

The 'configuration mismatch' error indicates that the configuration databases on the active and passive firewalls are out of sync. Running 'request high-availability sync-to-remote' from the active firewall pushes the active configuration to the passive firewall without disrupting traffic, as it only updates the passive unit's configuration and does not trigger a failover or restart.

Exam trap

The trap here is that candidates often assume a 'non-functional' state requires a restart or failover, but the specific 'configuration mismatch' reason points to a sync issue that can be resolved non-disruptively with a configuration push from the active firewall.

How to eliminate wrong answers

Option B is wrong because restarting the HA process on the passive firewall does not resolve a configuration mismatch; it only restarts the HA state machine and may temporarily disrupt HA communication without syncing the configuration. Option C is wrong because failing over the active firewall would force a traffic disruption by switching the active role to the passive unit, which is in a non-functional state, potentially causing a full outage. Option D is wrong because the issue is a configuration mismatch, not a PAN-OS version mismatch; upgrading both firewalls would not fix the configuration discrepancy and could introduce unnecessary downtime.

18
Drag & Dropmedium

Arrange the steps to enable and configure GlobalProtect on a Palo Alto Networks firewall.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for enabling and configuring GlobalProtect on a Palo Alto Networks firewall starts with configuring the portal, which handles authentication and client settings. Next, the gateway is configured to manage VPN connections. Then, the GlobalProtect agent (client configuration) is set up to push settings to endpoints.

Finally, security policies are applied to allow GlobalProtect traffic. Following this order ensures dependencies are satisfied and reduces configuration errors.

19
MCQhard

An engineer is troubleshooting an HA pair where the passive firewall is not synchronizing sessions. The HA1 link is up and the HA state is 'passive'. The engineer notices that the HA2 link is up, but session synchronization is still not working. Which action should the engineer take next?

A.Verify that the 'Session Synchronization' option is enabled in the HA configuration.
B.Configure the HA2 link to use the management interface to simplify cabling.
C.Ensure that the HA1 link is encrypted with a pre-shared key.
D.Check that the HA2 link is configured with the same IP addresses on both firewalls.
AnswerA

Session synchronization must be explicitly enabled in the HA configuration for the passive firewall to receive session updates. If disabled, no sessions will sync regardless of HA2 link status. This setting is found under Device > High Availability > General > Session Synchronization. Enabling it allows the active firewall to replicate sessions to the passive peer. Without it, the passive firewall will not have current session information.

Why this answer

Session synchronization requires the 'Session Synchronization' option to be enabled. Even if the HA2 link is up, if this setting is disabled, no sessions will be synchronized. The engineer should verify this setting first.

This is a common oversight when configuring HA. Once enabled, the active firewall will begin replicating sessions to the passive peer.

Exam trap

The trap here is assuming that a functional HA2 link is sufficient for session sync, when the 'Session Synchronization' option must also be enabled.

20
MCQeasy

A security engineer is configuring HA on a pair of Palo Alto Networks firewalls. The engineer wants to ensure that the HA1 control link is highly available. Which configuration should the engineer use for the HA1 link?

A.Use a dedicated physical interface connected to a switch with redundant paths.
B.Use an HA1 backup link in addition to the primary HA1 link.
C.Use an IP-bridged HA1 link over a dedicated physical interface.
D.Use a dedicated physical interface with a direct cable between the firewalls.
AnswerB

Configuring an HA1 backup link provides redundancy for the control link. If the primary HA1 link fails, the backup link takes over, ensuring continuous HA communication. This is the recommended best practice for high availability of the HA1 control link.

Why this answer

The HA1 control link is critical for HA communication. To ensure high availability, a backup HA1 link should be configured. This allows the firewalls to maintain HA state synchronization even if the primary HA1 link fails.

Other options may provide a working link but do not offer redundancy for the link itself.

Exam trap

The trap here is assuming that a direct cable or a switched connection is sufficient for high availability, when in fact a backup link is needed.

21
MCQhard

An HA pair is deployed with Active/Active mode. During a traffic spike, session table utilization reaches 90% on both firewalls. The engineer notices asymmetric routing and drops. What should be configured to optimize session distribution?

A.Change the HA mode to Active/Passive
B.Adjust the session distribution algorithm to match traffic patterns
C.Increase the HA2 link bandwidth using link aggregation
D.Enable session synchronization for all sessions
AnswerB

Proper distribution reduces asymmetric routing.

Why this answer

In an Active/Active HA pair, session distribution is controlled by a hash-based algorithm that determines which firewall handles a given flow. When asymmetric routing and drops occur during high session utilization, the default algorithm may not distribute traffic evenly, causing one firewall to become overloaded. Adjusting the session distribution algorithm (e.g., from IP hash to round-robin or a weighted distribution) can better match the traffic patterns and balance the load, reducing asymmetry and drops.

Exam trap

The trap here is that candidates often assume increasing HA2 bandwidth or enabling session synchronization will fix load imbalance, but these address sync throughput, not the root cause of uneven session distribution.

How to eliminate wrong answers

Option A is wrong because changing to Active/Passive would eliminate the load-sharing benefit of Active/Active, leaving one firewall idle and potentially still causing drops on the active unit during a traffic spike. Option C is wrong because increasing HA2 link bandwidth (used for session synchronization and state propagation) does not affect how sessions are initially distributed; it only improves the throughput of sync traffic, not the load-balancing algorithm. Option D is wrong because session synchronization is already enabled by default in Active/Active mode to maintain state; enabling it for all sessions does not change the distribution algorithm and will not optimize how sessions are assigned to firewalls.

22
Multi-Selecthard

Which TWO troubleshooting steps are most effective when an HA pair is not synchronizing sessions between peers? (Assume HA1 and HA2 are up.)

Select 2 answers
A.Ensure session synchronization is enabled on both firewalls under Device > High Availability > Setup
B.Check HA1 link utilization
C.Increase the packet buffer protection threshold
D.Review the session synchronization configuration for mismatched parameters (e.g., encryption, timeout)
E.Restart the HA process on both firewalls
AnswersA, D

Session synchronisation is a per-firewall setting, so it must be enabled on both peers for sessions to replicate. With HA1 and HA2 confirmed up, checking this toggle under Device > High Availability > Setup rules out the simplest cause of missing synchronisation.

Why this answer

Option A is correct because session synchronization must be explicitly enabled in Device > High Availability > Setup on both peers; if the checkbox is cleared on either firewall, sessions will not replicate even though HA1/HA2 heartbeats are up. Option D is correct because the session synchronization settings (e.g., sync encryption, session timeout, and related parameters) must match on both peers; a mismatch such as encryption enabled on one side but not the other silently prevents session state from being exchanged. Options B, C, and E are not the most effective steps: HA1 utilization affects heartbeat/control traffic rather than session sync (which normally uses HA2), packet buffer protection is unrelated to session replication, and restarting the HA process is a disruptive action that does not address configuration causes of sync failure.

Exam trap

PCNSE often tests the assumption that HA link 'up' status means synchronization is working, when in fact session sync can be disabled or misconfigured independently of link state.

23
MCQhard

The firewall is in passive state. The network team reports that during a recent maintenance window, the active firewall lost its upstream link but the passive firewall did not take over. Based on the exhibit, what is the most likely reason?

A.HA2 heartbeat link is down, preventing the passive from detecting the active's failure.
B.The fail-holdup timer is set to 0, causing immediate failover but not triggered.
C.Link monitoring is enabled but not configured to monitor the specific interface that failed.
D.Path monitoring is disabled so the passive does not monitor connectivity to the upstream router.
AnswerC

Passive firewalls only fail over when the monitored link path fails. If link monitoring watches a different interface than the one that actually went down, the passive device never detects the failure and stays passive, so no takeover occurs despite the active firewall losing its upstream link.

Why this answer

Link monitoring on a Palo Alto Networks firewall is configured to monitor specific interfaces. If the upstream link that failed is not included in the link monitoring group, the passive firewall will not detect the loss of that link and will not trigger a failover. The passive firewall only monitors the interfaces explicitly listed under Device > High Availability > Link Monitoring, so an unmonitored interface failure will be ignored for HA purposes.

Exam trap

The trap here is that candidates confuse link monitoring (local interface state) with path monitoring (remote reachability) or assume the HA2 heartbeat link is responsible for failure detection, when in fact HA1 keepalives handle that and link monitoring is the feature that must explicitly include the failed interface.

How to eliminate wrong answers

Option A is wrong because the HA2 heartbeat link is used for session synchronization and state propagation, not for detecting link failures; the passive detects active failure via HA1 keepalive packets, not HA2. Option B is wrong because the fail-holdup timer (default 0) controls how long the passive waits before taking over after detecting a failure, but it does not prevent detection of the failure itself; the issue here is that the failure was never detected. Option D is wrong because path monitoring is a separate feature that monitors connectivity to specific destination IP addresses (e.g., next-hop routers), not the state of local interfaces; disabling path monitoring would not prevent the passive from detecting a local interface failure, which is the domain of link monitoring.

24
MCQmedium

A firewall in an HA pair is being upgraded. The administrator wants to minimize traffic loss. What is the recommended procedure for upgrading the passive firewall in an active/passive pair?

A.Upgrade the active firewall first, then failover to the passive
B.Upgrade the passive firewall, failover to it, then upgrade the original active
C.Suspend HA, upgrade both, then re-enable HA
D.Upgrade both firewalls simultaneously after disconnecting HA links
AnswerB

Upgrading the passive node first keeps the active firewall forwarding traffic, then a failover promotes the upgraded unit so it carries sessions while the original active is upgraded. This staged approach satisfies the minimise-traffic-loss constraint without taking both nodes offline simultaneously.

Why this answer

In an active/passive HA pair, the passive firewall is upgraded first while the active firewall continues to handle traffic. After the passive firewall is upgraded and rebooted, an administrative failover is performed to make it the new active firewall, minimizing traffic loss. The original active firewall is then upgraded, ensuring there is always a firewall processing traffic during the upgrade process.

Exam trap

The trap here is that candidates often assume upgrading the active firewall first is safer because it is the primary device, but this ignores the fact that the passive firewall must be upgraded and ready to take over before the active firewall is touched to avoid traffic loss.

How to eliminate wrong answers

Option A is wrong because upgrading the active firewall first would cause traffic disruption during its reboot, as the passive firewall is not yet upgraded and may not be able to take over seamlessly. Option C is wrong because suspending HA breaks the synchronization and state sharing, leaving the network unprotected during the upgrade and requiring manual reconfiguration, which increases the risk of traffic loss. Option D is wrong because upgrading both firewalls simultaneously after disconnecting HA links leaves no firewall protecting the network, causing complete traffic loss until at least one firewall is back online.

25
MCQhard

Refer to the exhibit. Based on the log, what triggered the failover?

A.Loss of HA1 heartbeat from the peer
B.A link failure on ethernet1/1
C.An administrator manually triggered a failover
D.A path monitoring group determined that the upstream ISP is unreachable
AnswerD

Path monitoring groups probe specified destination IPs; when probes fail, the firewall treats the monitored path as down and triggers failover. The log records an unreachable upstream ISP, satisfying the path-monitoring failure condition that initiates the failover.

Why this answer

The log entry indicates that the failover was triggered by a path monitoring group, which detected that the upstream ISP became unreachable. Path monitoring actively probes the next-hop gateway or a target IP address; when the probe fails, the firewall considers the path down and initiates a failover to the passive peer. This is distinct from HA1 heartbeat loss or link failure, as the log explicitly references the path monitoring group.

Exam trap

The trap here is that candidates often confuse path monitoring with simple link monitoring or HA1 heartbeat loss, but the log entry's explicit reference to a 'path monitoring group' is the key differentiator that points to upstream unreachability rather than local interface or HA communication issues.

How to eliminate wrong answers

Option A is wrong because loss of HA1 heartbeat would generate a log entry referencing 'HA1 heartbeat timeout' or 'HA1 link down', not a path monitoring group event. Option B is wrong because a link failure on ethernet1/1 would produce a log entry for 'link down' or 'interface down', not a path monitoring group action. Option C is wrong because an administrator manually triggering a failover would show a log entry like 'admin requested failover' or 'manual failover', not a path monitoring group event.

26
MCQmedium

During a failover test, the active firewall in an active/passive HA pair goes down, but the passive firewall remains in passive state and does not take over. The passive firewall shows HA state 'passive' and the HA1 link status is 'down'. What is the most likely cause?

A.The HA2 link is not configured for session synchronization.
B.The HA1 link is not configured with the same subnet on both firewalls.
C.The passive firewall is configured with a lower HA priority.
D.The HA1 link is down, preventing heartbeat communication.
AnswerD

The HA1 link is the control link used for heartbeats and synchronization between HA peers. If it is down, the passive firewall does not receive heartbeats from the active firewall and may not detect a failure, thus remaining passive. The stem explicitly states HA1 link status is 'down', making this the most likely cause for the passive firewall not taking over.

Why this answer

The HA1 link is critical for heartbeats and control communication. When it is down, the passive firewall cannot determine the active firewall's status and will not initiate failover. The stem indicates HA1 link status is 'down', which directly explains why the passive firewall remains passive despite the active firewall going down.

Exam trap

The trap here is assuming that HA2 link issues prevent failover, but HA2 is for session synchronization and not for failover detection.

27
MCQmedium

An engineer notices that the HA pair is not synchronizing configuration changes. The 'show high-availability sync-status' output shows 'sync-failure'. What is the first step to troubleshoot?

A.Verify HA1 link status and IP connectivity between peers
B.Disable preemption on the active firewall
C.Check the HA2 link session synchronization status
D.Reboot both firewalls to clear the failure
AnswerA

A sync-failure indicates the peers cannot exchange configuration data, and that exchange travels over the HA1 link. Verifying HA1 interface status and IP connectivity between peers confirms whether the dedicated synchronisation path is down before investigating deeper causes such as version mismatches or commit failures.

Why this answer

The 'sync-failure' status on the 'show high-availability sync-status' output indicates that configuration synchronization between the HA peers has failed. The first step in troubleshooting is to verify the HA1 link status and IP connectivity between peers because HA1 is the dedicated control link used for heartbeats and configuration sync. Without a functional HA1 link, the firewalls cannot exchange configuration data, making this the most fundamental check before investigating other potential causes.

Exam trap

The trap here is that candidates often jump to checking the HA2 link (session synchronization) because they confuse configuration sync with stateful session sync, but HA1 is the correct link for configuration changes.

How to eliminate wrong answers

Option B is wrong because disabling preemption does not address the underlying connectivity or sync mechanism; preemption controls which firewall becomes active after a failure, not the synchronization of configurations. Option C is wrong because the HA2 link is used for session synchronization (stateful failover), not for configuration synchronization; checking HA2 would be relevant for session sync issues, not config sync failures. Option D is wrong because rebooting both firewalls is a drastic and unnecessary step that could cause service disruption; it should only be considered after verifying basic connectivity and link status, as a reboot will not fix a fundamental HA1 link problem.

28
MCQhard

An engineer is troubleshooting an HA pair where the passive firewall is not receiving session updates. The HA1 link is up and the firewalls are in active/passive mode. The engineer runs 'show high-availability state' and sees 'State: passive' and 'Peer State: active'. Which additional command should the engineer run to verify that session synchronization is enabled and functioning?

A.show high-availability interface ha2
B.show high-availability state-synchronization
C.show session all
D.show high-availability state
AnswerB

This command displays the session synchronization state and statistics, including whether synchronization is enabled and if there are any errors. It directly addresses the engineer's need to verify that session updates are being sent and received. If synchronization is not working, this command will show details such as packet counts and errors, helping to pinpoint the issue.

Why this answer

To verify session synchronization, the engineer should use the command that specifically reports on synchronization state and statistics. 'show high-availability state-synchronization' provides details such as whether synchronization is enabled, the number of synchronized sessions, and any errors. This is the most direct way to confirm if session updates are being sent and received correctly.

Exam trap

The trap here is assuming that HA1 and HA2 link status are sufficient, but session synchronization also depends on configuration and can be disabled or failing even with healthy links.

29
MCQhard

In an HA active/passive setup, the engineer wants to ensure that during a failover, existing FTP data sessions are not interrupted. What additional configuration is required beyond default session synchronization?

A.Use HA3 link for session synchronization
B.Enable asymmetric routing support
C.Enable UDP session synchronization
D.Configure an application layer gateway (ALG) for FTP
AnswerD

FTP data sessions use a separate dynamic data channel, so default session synchronisation alone cannot preserve them across failover. Configuring an application layer gateway makes the firewall inspect and synchronise the FTP control and data channels, keeping existing transfers alive when the passive node takes over.

Why this answer

FTP uses separate control and data channels, and the data channel port is dynamically negotiated via the PORT or PASV command. Without an application layer gateway (ALG) for FTP, the firewall cannot track these dynamic ports, so session synchronization would only replicate the control session, causing data sessions to drop after a failover. Enabling the FTP ALG ensures the firewall inspects FTP commands and creates the necessary pinholes for data sessions, which are then synchronized to the passive peer.

Exam trap

The trap here is that candidates assume session synchronization alone is sufficient for all TCP sessions, overlooking that FTP's dynamic port negotiation requires application-layer inspection to create and sync the data channel sessions.

How to eliminate wrong answers

Option A is wrong because the HA3 link is used for state synchronization and session table updates, but it does not address the protocol-specific issue of FTP's dynamic data ports; session synchronization alone cannot preserve FTP data sessions without ALG support. Option B is wrong because asymmetric routing support handles scenarios where traffic takes different paths inbound and outbound, but it does not solve the problem of FTP data sessions being dynamically negotiated and not tracked by default session sync. Option C is wrong because UDP session synchronization is irrelevant to FTP, which uses TCP for both control and data channels; enabling UDP sync would not help preserve FTP data sessions.

30
MCQhard

Based on the exhibit, what is the most likely cause of the warnings?

A.The HA3 link is misconfigured
B.Configuration synchronization is failing
C.Both the primary and backup HA2 links are down
D.The HA2 keepalive timer is set too low
AnswerC

Warnings for both indicate link failure.

Why this answer

The exhibit shows warnings indicating that both the primary and backup HA2 links are down. HA2 is the control link used for session synchronization and configuration state exchange in an active/passive or active/active firewall pair. When both HA2 links fail, the firewalls cannot synchronize session tables, leading to warnings about potential asymmetric traffic and failover issues.

Option C correctly identifies this as the most likely cause.

Exam trap

The trap here is that candidates often confuse HA2 (control link) with HA3 (data link) or assume that a single link failure is the cause, but the exhibit explicitly shows warnings for both primary and backup HA2 links being down, making C the only correct answer.

How to eliminate wrong answers

Option A is wrong because the HA3 link is the dataplane link used for forwarding traffic in active/active mode or for asymmetric routing; misconfiguration of HA3 would cause traffic forwarding issues, not the specific warnings shown. Option B is wrong because configuration synchronization failing would typically generate a different set of warnings related to config mismatch or sync failure, not the HA2 link down warnings. Option D is wrong because the HA2 keepalive timer being set too low would cause flapping or false failovers, but the exhibit shows persistent warnings indicating the links are down, not intermittent keepalive failures.

31
MCQmedium

An administrator is configuring HA on a pair of PA-5220 firewalls. They want to ensure that the HA1 link is redundant and can survive a single link failure. Which configuration should they use?

A.Configure HA1 on a dedicated interface and enable HA1 backup.
B.Configure HA1 on an aggregate interface (AE) with multiple physical links.
C.Configure HA1 on a loopback interface and enable BFD.
D.Configure HA1 on a VLAN interface and enable LACP.
AnswerA

HA1 backup allows the configuration of a secondary HA1 link on a different interface. If the primary HA1 link fails, the backup takes over, providing redundancy. This is a best practice for HA1 to avoid a single point of failure. The firewall supports HA1 backup on a separate interface, which can be a physical port or an aggregate interface.

Why this answer

HA1 backup allows a secondary HA1 link to be configured on a different interface. If the primary HA1 link fails, the backup link is used, ensuring control link redundancy. This is the recommended configuration for HA1 redundancy.

Exam trap

The trap here is thinking that link aggregation on HA1 provides redundancy, but HA1 backup is the supported and recommended method.

32
MCQmedium

A network engineer is configuring HA on a pair of PA-5220 firewalls. The company requires that the HA1 control link be secured and that the firewalls authenticate each other. Which action should the engineer take?

A.Use the management interface for HA1 traffic and enable SSL/TLS encryption on the management plane.
B.Configure the HA1 link to use IPsec by creating a tunnel between the management interfaces.
C.Enable HA1 encryption by setting a pre-shared key in the HA configuration.
D.Enable HA1 encryption by selecting the 'Encrypt HA1' checkbox and generating a self-signed certificate.
AnswerC

Setting a pre-shared key enables encryption of HA1 control traffic and provides mutual authentication between peers. This satisfies both the security and authentication requirements. The pre-shared key is configured under Device > High Availability > General > Control Link. Without it, HA1 messages are sent in clear text and any device could potentially spoof HA messages.

Why this answer

HA1 control link encryption and authentication are achieved by configuring a pre-shared key. This ensures that only the paired firewalls can exchange HA control messages and that the messages are encrypted. The pre-shared key must match on both peers.

This is the standard method to secure HA1 and is a best practice when the HA1 link traverses untrusted networks.

Exam trap

The trap here is assuming that HA1 encryption requires certificates or IPsec, when it is actually enabled by a simple pre-shared key.

33
Multi-Selecthard

An engineer is configuring HA on a pair of firewalls and wants to ensure that the HA1 link is secure and redundant. Which two actions should the engineer take? (Choose two.)

Select 2 answers
A.Configure HA1 backup on a separate interface.
B.Enable HA1 link aggregation using LACP.
C.Set the HA1 link to use UDP port 29281.
D.Configure HA2 encryption.
E.Configure HA1 encryption.
AnswersA, E

HA1 backup provides redundancy for the control link. If the primary HA1 link fails, the backup link is used. This ensures that the HA pair remains operational and can still exchange heartbeats and synchronize configuration. It is a recommended practice for high availability.

Why this answer

To secure HA1, enable HA1 encryption. To provide redundancy, configure HA1 backup on a separate interface. These two actions ensure that the control link is both protected and resilient.

Exam trap

The trap here is confusing HA1 and HA2 features; HA2 encryption and aggregation are not applicable to HA1 security and redundancy.

34
MCQeasy

A network engineer is troubleshooting an HA pair where the passive firewall is showing a state of 'suspended'. The active firewall is functioning normally. What is the most likely reason for the suspended state?

A.The HA2 link is down.
B.A path monitoring failure has occurred.
C.The passive firewall has a lower HA priority.
D.The HA1 link is down.
AnswerB

Path monitoring is used to monitor critical IP addresses or interfaces. If a monitored path fails on the passive firewall, it can cause the firewall to enter a suspended state to prevent it from becoming active and potentially causing a network outage. This is a safety mechanism. The active firewall is functioning normally, so the passive firewall's path monitoring failure is likely the cause.

Why this answer

A path monitoring failure on the passive firewall can cause it to enter a suspended state. This prevents the firewall from becoming active if the active firewall fails, avoiding a potentially worse network situation. The active firewall is functioning normally, so the passive firewall's suspension is likely due to its own path monitoring.

Exam trap

The trap here is confusing suspended state with non-functional state; suspended is often due to path monitoring, while non-functional is due to HA link or configuration issues.

35
MCQeasy

A company has deployed two PA-3220 firewalls in an active/passive high availability configuration. During normal operation, the active firewall (FW-A) handles all traffic. The network team notices that after a brief power outage, both firewalls report as active in the HA pair, causing network instability. The administrator needs to resolve this issue and prevent it from recurring. Which course of action should the administrator take?

A.Reboot both firewalls simultaneously to reset the HA state.
B.Disable link speed and duplex settings on the HA interfaces to force a failover.
C.Configure the HA mode with the 'preemptive' option and set the device priority higher on the intended active firewall.
D.Set the HA mode to 'active/active' to allow both firewalls to process traffic.
AnswerC

Preemptive ensures the higher-priority device becomes active after recovery, preventing both firewalls from staying active.

Why this answer

Configuring the HA mode with the 'preemptive' option ensures that when both firewalls recover from a power outage, the firewall with the higher device priority (the intended active unit) will automatically preempt the other and become active. Without preemption, both firewalls may come up as active if they lose HA heartbeat synchronization during the outage, leading to a split-brain scenario. Setting the device priority higher on FW-A guarantees it is preferred as the active unit upon recovery.

Exam trap

The trap here is that candidates often assume rebooting or resetting the HA state (Option A) is sufficient, but they overlook the need for preemption to automatically resolve the split-brain condition after a power failure, which is a common cause of HA instability in production environments.

How to eliminate wrong answers

Option A is wrong because rebooting both firewalls simultaneously does not resolve the underlying split-brain condition; it only temporarily resets the HA state and the problem will recur if the root cause (lack of preemption) is not addressed. Option B is wrong because disabling link speed and duplex settings on HA interfaces would disrupt the HA heartbeat link, potentially causing both firewalls to assume active state due to loss of communication, which worsens the issue rather than fixing it. Option D is wrong because setting the HA mode to 'active/active' would allow both firewalls to process traffic simultaneously, which is not the intended design for this active/passive deployment and would cause asymmetric routing and network instability, not resolve the split-brain problem.

36
MCQmedium

A company has deployed two Palo Alto Networks firewalls in an active/passive HA configuration. During a failover test, the engineer notices that the passive firewall did not take over when the active firewall's data plane interface went down. The engineer reviews the HA configuration and sees that the HA1 link is up and the HA2 link is up. What is the most likely reason for the failover not occurring?

A.The HA2 link is not configured for session synchronization.
B.The HA1 link is not configured with a backup path.
C.Link monitoring is not enabled on the data plane interface.
D.The passive firewall is in a suspended state.
AnswerC

For the firewall to trigger a failover when a data plane interface goes down, link monitoring must be enabled on that interface in the HA configuration. Without link monitoring, the firewall does not detect the interface failure and thus does not initiate a failover. This is a common oversight in HA setup.

Why this answer

Failover in an active/passive HA pair is triggered by link monitoring and path monitoring. If link monitoring is not enabled on the data plane interface that went down, the firewall does not detect the failure and therefore does not initiate a failover. The HA1 and HA2 links being up only ensure control and data synchronization, not failure detection.

Exam trap

The trap here is assuming that any interface failure automatically triggers failover; actually, link monitoring must be explicitly enabled on the interface.

37
MCQeasy

An administrator needs to verify the health of HA links. Which CLI command displays the current status of HA1, HA2, and HA3 links?

A.show session info
B.show running np-ips
C.show device-info
D.show high-availability state
AnswerD

Displays HA status including link states.

Why this answer

The 'show high-availability state' command is the correct CLI command to verify the health of HA1, HA2, and HA3 links because it displays the current status, link state, and any failures for each HA link in a Palo Alto Networks firewall. This command provides a comprehensive view of the HA control link (HA1), data link (HA2), and backup link (HA3), including their operational status and packet statistics, which is essential for troubleshooting high-availability configurations.

Exam trap

The trap here is that candidates often confuse 'show high-availability state' with 'show device-info' or 'show session info', assuming general system or session data includes HA link details, but only the dedicated HA command provides the granular link status required for this verification.

How to eliminate wrong answers

Option A is wrong because 'show session info' displays information about active sessions, such as source/destination IPs and ports, not the status of HA links. Option B is wrong because 'show running np-ips' shows the running configuration of network processor IP addresses, which is unrelated to HA link health verification. Option C is wrong because 'show device-info' provides general system information like model, serial number, and uptime, but does not include the specific status of HA1, HA2, or HA3 links.

38
MCQmedium

Based on the exhibit, what caused the last failover?

A.The HA2 link went down.
B.A preemption event occurred.
C.The peer firewall was rebooted.
D.The HA1 keepalive from the peer was lost.
AnswerD

The HA1 keepalive carries the heartbeat between peers; its loss makes the firewall conclude the peer is down, triggering failover. The exhibit shows HA1 link failure, so the peer's keepalive never arrived, which is the direct cause of the last failover.

Why this answer

The exhibit shows 'HA1 keepalive from the peer was lost' as the last failover reason. In an active/passive HA pair, the passive firewall monitors HA1 keepalive messages from the active peer. When these keepalives are not received within the configured hello interval (default 1 second) and hold timer (default 3 seconds), the passive firewall assumes the active peer has failed and initiates a failover to become active.

Exam trap

The trap here is that candidates often confuse the HA1 link (control link for keepalives) with the HA2 link (data link for session sync), leading them to incorrectly select Option A when the actual failover trigger is loss of HA1 keepalive, not HA2 link failure.

How to eliminate wrong answers

Option A is wrong because the HA2 link is used for session synchronization and state propagation, not for keepalive monitoring; a HA2 link failure alone does not trigger a failover unless it also causes HA1 keepalive loss. Option B is wrong because a preemption event would be logged as 'Preempted by local firewall' or 'Preempted by peer firewall', not as a keepalive loss; preemption is a configuration-based event that occurs when the higher-priority firewall comes back online. Option C is wrong because if the peer firewall was rebooted, the failover reason would typically show 'Peer firewall rebooted' or 'HA1 keepalive from the peer was lost' only if the reboot caused keepalive failure, but the direct cause logged is the keepalive loss, not the reboot itself.

39
MCQmedium

Refer to the exhibit. An engineer configures HA with link monitoring and path monitoring. However, failover does not occur when ethernet1/2 goes down. What is the likely reason?

A.The HA group-id is not unique in the network
B.HA2 link is down preventing failover
C.Path monitoring interval is set too high, causing delayed failover
D.'link-monitoring' is configured under the high-availability hierarchy but not explicitly enabled
AnswerD

In PAN-OS, link monitoring must be enabled with 'enable yes' under high-availability; interfaces alone do not enable it.

Why this answer

In Palo Alto Networks HA configuration, link monitoring is not enabled by default even when the 'link-monitoring' block is present under the 'high-availability' hierarchy. The engineer must explicitly set 'enabled yes' within the 'link-monitoring' configuration to activate it. Without this explicit enable, the firewall will not monitor the specified interfaces for link state changes, so a failure on ethernet1/2 will not trigger a failover.

Exam trap

The trap here is that candidates assume that simply adding the 'link-monitoring' configuration stanza under the HA hierarchy automatically enables link monitoring, when in fact the 'enabled yes' parameter is required to activate it.

How to eliminate wrong answers

Option A is wrong because a non-unique HA group-id would cause both peers to attempt to be active or passive simultaneously, leading to split-brain or failover issues, but it would not prevent failover when a monitored link goes down; the failover would still occur if link monitoring were properly enabled. Option B is wrong because the HA2 link is used for session synchronization and heartbeat, not for link monitoring; if the HA2 link were down, the firewalls would lose heartbeat and potentially both become active, but this would not prevent a link-monitoring-based failover from occurring when ethernet1/2 goes down. Option C is wrong because the path monitoring interval controls how often the firewall checks the reachability of monitored paths (e.g., ping to a next-hop IP), not the link state of an interface; link monitoring reacts immediately to link state changes (up/down) and is not affected by the path monitoring interval.

Ready to test yourself?

Try a timed practice session using only Managing Troubleshooting and High Availability questions.