Courseiva

PCNSE Practice Question: Managing Troubleshooting and High Availability

In an HA active/passive setup, the engineer wants to ensure that during a failover, existing FTP data sessions are not interrupted. What additional configuration is required beyond default session synchronization?

⚠ Common exam trap

A common mix-up: candidates assume session synchronization alone is sufficient for all TCP sessions, overlooking that FTP's dynamic port negotiation requires application-layer inspection to create and sync the data channel sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an application layer gateway (ALG) for FTP

FTP uses separate control and data channels, and the data channel port is dynamically negotiated via the PORT or PASV command. Without an application layer gateway (ALG) for FTP, the firewall cannot track these dynamic ports, so session synchronization would only replicate the control session, causing data sessions to drop after a failover. Enabling the FTP ALG ensures the firewall inspects FTP commands and creates the necessary pinholes for data sessions, which are then synchronized to the passive peer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use HA3 link for session synchronization

    Why it's wrong here

    The HA3 link carries HA control and synchronisation traffic between peers; it does not extend session synchronisation to FTP's separate data channel. HA3 is the correct transport choice when you need dedicated high-availability heartbeat and state links between firewalls, not for preserving FTP data sessions.

  • ✗

    Enable asymmetric routing support

    Why it's wrong here

    Asymmetric routing support lets return traffic traverse a different path than the forward flow; it does not replicate FTP data-channel state to the passive peer. It is the right setting when traffic paths are intentionally asymmetric, not for maintaining existing FTP data sessions across a failover.

  • ✗

    Enable UDP session synchronization

    Why it's wrong here

    FTP data sessions run over TCP, so synchronising UDP session state does nothing for them; the FTP data channel's TCP state is what must survive failover. UDP synchronisation is intended for UDP-based protocols such as SIP or DNS, where session state must also be replicated across the HA pair.

  • ✓

    Configure an application layer gateway (ALG) for FTP

    Why this is correct

    FTP data sessions use a separate dynamic data channel, so default session synchronisation alone cannot preserve them across failover. Configuring an application layer gateway makes the firewall inspect and synchronise the FTP control and data channels, keeping existing transfers alive when the passive node takes over.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.