exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 322 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 322
Topic #: 1
[All PCNSE Questions]

Which three use cases are valid reasons for requiring an Active/Active high availability deployment? (Choose three.)

  • A. The environment requires real full-time redundancy from both firewalls at all times.
  • B. The environment requires that traffic be load-balanced across both firewalls to handle peak traffic spikes.
  • C. The environment requires Layer 2 interfaces in the deployment.
  • D. The environment requires that all configuration must be fully synchronized between both members of the HA pair.
  • E. The environment requires that both firewalls maintain their own routing tables for faster dynamic routing protocol convergence.
Show Suggested Answer Hide Answer
Suggested Answer: ADE 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 2 years, 3 months ago
I think that it is A,B,E because configuration is fully sinchronized in a A/P too.
upvoted 18 times
1 month, 4 weeks ago
it actually only synchronzid on A/P HA active/active fw don't sync their config
upvoted 1 times
Most Recent 3 days, 11 hours ago
Selected Answer: ABE
There's a lot left there to unpack with D. It is A, B and E
upvoted 1 times
3 days, 15 hours ago
Selected Answer: ADE
It is not a good practice to handle peaks using both firewall capacities. This defeats the purpose of Full redundancy, so B can't be right.
upvoted 1 times
1 month, 1 week ago
Selected Answer: ABE
the other explanations are good.
upvoted 1 times
1 month, 2 weeks ago
Selected Answer: ABE
Hello, if you look at the palo reference for HA Sync, you see that more things can be synced with A/P (i.e FIB,MFIB, ARP Table, MAC Table) so it is clear in Active/Active deployment full sync is beside the point.... https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization Here the question does not refer to firewall doing the load balancing, but the environment requires load balancing to allow the customer to send traffic through both firewalls.
upvoted 1 times
3 months ago
Selected Answer: ADE
Im guessing ADE, and not choosing B as Palo Alto explicitly dissuades configuring the firewalls to handle more traffic than one firewall is capable of handling. This would defeat the entire purpose of HA in the event of a failover, as the failover would result in network performance degradation from the newly created bottleneck.
upvoted 3 times
3 months ago
Selected Answer: ADE
Bros the A/A does not balance the traffic, you need an external load balancer to do so. So B cannot be an option. ADC sounds accurate.
upvoted 1 times
3 months, 3 weeks ago
Answer B is definetly wrong! The Palo Alto Firewall are not able to load balance traffic.
upvoted 1 times
8 months, 1 week ago
ABE, C is only possible on Active/Passive, and D is incorrect since the config is sync on Active/Passive too.
upvoted 1 times
8 months, 3 weeks ago
Selected Answer: ABE
configuration is Synced in A/P too, answer is A B E.
upvoted 2 times
9 months ago
Selected Answer: ADE
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/arp-load-sharing Firewall support ARP load sharing but not the load balancing.
upvoted 1 times
9 months, 3 weeks ago
ADE is correct
upvoted 1 times
1 year ago
Selected Answer: ABE
ABE. "Active/active mode has faster failover and can handle peak traffic flows better than active/passive mode because both firewalls are actively processing traffic." Source:https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 1 times
1 year ago
Selected Answer: ABE
Correct answer is ABE C makes no sense D can also be done with Active-Passive HA A is a little ambiguous since A/A HA doesn't guarantee that both fw will always be working, it just says that if one fails the other is still working, but A/P just guarantees that at least one will always be working so only A/A can achieve what A) describes B. Is the textbook definition of why Active/active HA can be useful E. Is one of the reasons why A/A HA can be faster.
upvoted 3 times
1 year, 2 months ago
A,B,E are the correct options
upvoted 1 times
1 year, 5 months ago
Selected Answer: ADE
worth noting that A/A does not load balance traffic... it can load-share "An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs. Ways to load share sessions to both firewalls include using ECMP, multiple ISPs, and load balancers."
upvoted 4 times
1 year, 5 months ago
Selected Answer: ABE
Voted ABE (D is applicable for both a/a and a/p)
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago