exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 7 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 7
Topic #: 1
[All PCNSE Questions]

An administrator pushes a new configuration from Panorama to a pair of firewalls that are configured as an active/passive HA pair.
Which NGFW receives the configuration from Panorama?

  • A. The passive firewall, which then synchronizes to the active firewall
  • B. The active firewall, which then synchronizes to the passive firewall
  • C. Both the active and passive firewalls, which then synchronize with each other
  • D. Both the active and passive firewalls independently, with no synchronization afterward
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
Community vote distribution
D (80%)
10%
10%

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mohammed
Highly Voted 4 years, 5 months ago
I thisnk answer is D https://live.paloaltonetworks.com/t5/General-Topics/config-push-from-panorama-to-HA-PA/td-p/236297
upvoted 14 times
...
oo7
Highly Voted 4 years, 5 months ago
D https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleOCAS
upvoted 10 times
...
Nico1973
Most Recent 3 weeks ago
Selected Answer: B
The correct answer is: B. The active firewall, which then synchronizes to the passive firewall Explanation: When pushing a configuration from Panorama to a pair of firewalls configured in an active/passive High Availability (HA) pair, the following process occurs: Panorama sends the configuration to the active firewall: Panorama communicates directly with the active firewall in the HA pair and pushes the new configuration to it. The active firewall synchronizes the configuration to the passive firewall: After receiving the configuration, the active firewall automatically synchronizes the configuration to the passive firewall to ensure both devices have the same settings. This approach ensures consistency between the active and passive firewalls and avoids configuration mismatches that could cause issues during failover.
upvoted 1 times
...
scanossa
8 months ago
Selected Answer: D
I set up a lab with an HA pair, both devices received the configuration in their respective template stack and then, performed a commit. Because the values are the same, no synchronization is needed.
upvoted 1 times
...
Marshpillowz
8 months, 2 weeks ago
Selected Answer: D
D is the correct answer. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleOCAS
upvoted 2 times
...
evdw
1 year, 9 months ago
Correct Answer is D Policies and templates from Panorama must be committed to both active and passive HA devices! They are not getting synched!
upvoted 2 times
...
myname_1
1 year, 9 months ago
Selected Answer: D
This has some info for migrating HA into Panorama: https://docs.paloaltonetworks.com/panorama/10-1/panorama-admin/manage-firewalls/transition-a-firewall-to-panorama-management/migrate-a-firewall-ha-pair-to-panorama-management Basically, Panorama configuration is not synced regardless of if the config sync box is checked. Only local configuration will be synchronized if the config sync box is checked.
upvoted 2 times
...
lol12
1 year, 11 months ago
Selected Answer: D
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleOCAS
upvoted 1 times
...
ashmeow
2 years, 1 month ago
Selected Answer: D
Sync only happens if you commit locally and enable config sync is ticked under the HA section
upvoted 1 times
...
melek18
2 years, 2 months ago
Selected Answer: C
In my opinion C
upvoted 1 times
...
ThatIT
2 years, 4 months ago
The Correct answer here is C , both firewalls will receive the configuration and will need to sync what the configuration it is, may be an application , objects ,security policy . On panorama you will also see on the devices it will show they are in-sync or out of sync
upvoted 1 times
...
king04
2 years, 7 months ago
Selected Answer: D
D is correct
upvoted 1 times
...
r0ze
2 years, 12 months ago
Answer: D
upvoted 2 times
...
uNburNed
3 years, 3 months ago
Should be C
upvoted 2 times
Breyarg
2 years, 9 months ago
no its D. although we always set up HA with sync enabled, its not a requirement for HA. so just HA without the "additional and optional" sync, will not sync.
upvoted 1 times
...
...
theroghert
3 years, 7 months ago
only D
upvoted 1 times
...
Sarbi
3 years, 10 months ago
Ths answer is D
upvoted 1 times
...
lol1000
3 years, 11 months ago
Answer: D sk suggests that Panorama policy is pushed to both units and no sync is performed per se. This means that any local policy would need to be synced separately https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleOCAS
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
VMCE v12
Santiago, 1 minute ago