Courseiva

PCNSE Deploy and Configure Firewalls Practice Question

Which THREE are valid methods to provide redundancy for outbound internet traffic in a Palo Alto Networks firewall?

⚠ Common exam trap

Watch out — candidates often confuse virtual router synchronization (which only replicates routing tables) with actual failover mechanisms like floating IPs or path monitoring, assuming that synchronized routing alone provides redundancy for outbound traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Active/Passive HA with floating IP

Active/Passive HA with floating IP (Option A) is valid because the passive firewall assumes the active firewall's IP address upon failover, ensuring outbound traffic continues via the same default gateway. ECMP with equal cost routes (Option B) distributes outbound traffic across multiple paths and provides redundancy by automatically failing over if one path is lost. Policy Based Forwarding combined with path monitoring (Option C) allows you to define forwarding policies based on traffic attributes and monitor path health, redirecting traffic if a monitored path fails.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Active/Passive HA with floating IP

    Why this is correct

    Active/passive HA keeps the standby firewall ready, and the floating IP moves to the passive device on failover, so outbound traffic continues through the surviving peer. This satisfies redundancy at the device level rather than the path level.

  • ✓

    ECMP with equal cost routes

    Why this is correct

    ECMP load-balances outbound flows across multiple equal-cost next hops, so losing one ISP path leaves the remaining routes carrying traffic without manual failover. This satisfies the stem's redundancy requirement by removing the single-path dependency, provided the firewall's virtual router has two or more equal-cost default routes installed.

  • ✓

    Policy Based Forwarding combined with path monitoring

    Why this is correct

    PBF forwards specified traffic out a chosen egress interface, and path monitoring withdraws that rule when the monitored next hop fails, so traffic fails over to the alternate path. This satisfies the redundancy requirement without relying on routing protocol convergence.

  • ✗

    Active/Passive HA with virtual router synchronization

    Why it's wrong here

    Active/Passive HA with virtual router synchronisation protects against device failure, not WAN link failure; both peers still share the same upstream path. It is tempting because HA is the standard resilience mechanism, but it is the correct choice when the requirement is firewall hardware redundancy rather than outbound internet circuit diversity.

  • ✗

    Use of multiple public IPs with NAT rules

    Why it's wrong here

    Multiple public IPs with NAT rules provide address translation and source-port diversity, not path redundancy; if the single ISP link or interface fails, traffic still stops. It is tempting because multiple addresses suggest resilience, but this method suits scenarios needing address flexibility, not failover across independent connections.

About these practice questions

This PCNSE question is part of Courseiva's 319-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.