PCNSE Deploy and Configure Firewalls Practice Question
In an Active/Passive HA pair, which statement is true regarding configuration synchronization?
⚠ Common exam trap
Candidates often assume all configuration changes (including uncommitted candidate changes) are synced in real time, but Palo Alto Networks only syncs committed configurations to maintain consistency and prevent partial or broken configurations from being applied to the passive peer.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Only committed changes on the active are synced to the passive.
In an Active/Passive HA pair, configuration synchronization occurs only after changes are committed on the active firewall. The passive peer then receives the committed configuration via the HA control link (using TCP port 2928 by default). This ensures that only validated, committed changes are propagated, preventing the passive from receiving uncommitted or partial configurations that could cause instability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configuration is not synced automatically; the administrator must export and import.
Why it's wrong here
Configuration synchronisation between HA peers is automatic once HA is configured, so manual export and import is unnecessary. It is tempting because manual export/import is the correct method for migrating configuration between standalone firewalls or for backup purposes, but it does not describe the ongoing sync behaviour of an Active/Passive pair.
- ✓
Only committed changes on the active are synced to the passive.
Why this is correct
Committed configuration on the active firewall synchronises automatically to the passive peer, ensuring both devices hold identical running configurations for seamless failover. Uncommitted candidate changes remain local and are never propagated, satisfying the requirement that the passive stays ready to assume traffic without manual intervention.
- ✗
All configuration changes on the active peer are automatically synced to the passive.
Why it's wrong here
Not all configuration changes sync: only settings within the synchronised categories are pushed, while device-specific and HA-specific settings remain local to each peer. It is tempting because most policy and object changes do propagate automatically, but the absolute wording fails the exam's requirement for the precise scope of synchronisation.
- ✗
The passive peer initiates the sync.
Why it's wrong here
Synchronisation is driven by the active peer, which pushes its configuration to the passive device; the passive never initiates the exchange. It is tempting because the passive receives and applies the configuration, which looks like initiating, but that role belongs to the active firewall in a Palo Alto Networks HA pair.
Go deeper
Related to this question
About these practice questions
One of 319 original PCNSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.