Courseiva

PCNSE Practice Question: Managing Troubleshooting and High Availability

Exhibit

Refer to the exhibit.
```
admin@PA-5050> show high-availability state

Local:
  mode: active-passive
  state: passive
  link monitoring: enabled
  path monitoring: disabled
  monitor fail-holdup: 0
  HA1 link status: up
  HA2 link status: down

Peer:
  mode: active-passive
  state: active
  link monitoring: enabled
  path monitoring: disabled
  monitor fail-holdup: 0

Group state: complete
```

The firewall is in passive state. The network team reports that during a recent maintenance window, the active firewall lost its upstream link but the passive firewall did not take over. Based on the exhibit, what is the most likely reason?

⚠ Common exam trap

Many candidates confuse link monitoring (local interface state) with path monitoring (remote reachability) or assume the HA2 heartbeat link is responsible for failure detection, when in fact HA1 keepalives handle that and link monitoring is the feature that must explicitly include the failed interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Link monitoring is enabled but not configured to monitor the specific interface that failed.

Link monitoring on a Palo Alto Networks firewall is configured to monitor specific interfaces. If the upstream link that failed is not included in the link monitoring group, the passive firewall will not detect the loss of that link and will not trigger a failover. The passive firewall only monitors the interfaces explicitly listed under Device > High Availability > Link Monitoring, so an unmonitored interface failure will be ignored for HA purposes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    HA2 heartbeat link is down, preventing the passive from detecting the active's failure.

    Why it's wrong here

    The HA2 link carries synchronisation traffic, not heartbeats; a failed HA2 causes configuration drift between peers rather than preventing the passive from learning the active has gone away. It is tempting because HA2 outages are a common HA fault, but heartbeat and failover detection run over HA1.

  • ✗

    The fail-holdup timer is set to 0, causing immediate failover but not triggered.

    Why it's wrong here

    A zero fail-holdup timer shortens how long the passive waits before promoting itself, so it cannot explain a failover that never occurred. It is tempting because tuning this timer is a legitimate way to speed up HA transitions in an active/passive pair, but it addresses failover timing, not the trigger condition the stem describes.

  • ✓

    Link monitoring is enabled but not configured to monitor the specific interface that failed.

    Why this is correct

    Passive firewalls only fail over when the monitored link path fails. If link monitoring watches a different interface than the one that actually went down, the passive device never detects the failure and stays passive, so no takeover occurs despite the active firewall losing its upstream link.

  • ✗

    Path monitoring is disabled so the passive does not monitor connectivity to the upstream router.

    Why it's wrong here

    Path monitoring runs on the active firewall to watch upstream reachability; disabling it affects the active's own link-failure detection, not the passive's behaviour. It is tempting because path monitoring is genuinely the feature used to fail over on upstream link loss, but the stem's exhibit points to a different cause.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.