exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 322 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 322
Topic #: 1
[All PCNSE Questions]

Which three use cases are valid reasons for requiring an Active/Active high availability deployment? (Choose three.)

  • A. The environment requires real full-time redundancy from both firewalls at all times.
  • B. The environment requires that traffic be load-balanced across both firewalls to handle peak traffic spikes.
  • C. The environment requires Layer 2 interfaces in the deployment.
  • D. The environment requires that all configuration must be fully synchronized between both members of the HA pair.
  • E. The environment requires that both firewalls maintain their own routing tables for faster dynamic routing protocol convergence.
Show Suggested Answer Hide Answer
Suggested Answer: ADE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alquicerm
Highly Voted 2 years, 2 months ago
I think that it is A,B,E because configuration is fully sinchronized in a A/P too.
upvoted 18 times
443Annny
2 weeks, 6 days ago
it actually only synchronzid on A/P HA active/active fw don't sync their config
upvoted 1 times
...
...
corpguy
Most Recent 1 day, 11 hours ago
Selected Answer: ABE
the other explanations are good.
upvoted 1 times
...
TeachTrooper
1 week, 6 days ago
Selected Answer: ABE
Hello, if you look at the palo reference for HA Sync, you see that more things can be synced with A/P (i.e FIB,MFIB, ARP Table, MAC Table) so it is clear in Active/Active deployment full sync is beside the point.... https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization Here the question does not refer to firewall doing the load balancing, but the environment requires load balancing to allow the customer to send traffic through both firewalls.
upvoted 1 times
...
62c930f
1 month, 3 weeks ago
Selected Answer: ADE
Im guessing ADE, and not choosing B as Palo Alto explicitly dissuades configuring the firewalls to handle more traffic than one firewall is capable of handling. This would defeat the entire purpose of HA in the event of a failover, as the failover would result in network performance degradation from the newly created bottleneck.
upvoted 3 times
...
CarlosDV06
1 month, 3 weeks ago
Selected Answer: ADE
Bros the A/A does not balance the traffic, you need an external load balancer to do so. So B cannot be an option. ADC sounds accurate.
upvoted 1 times
...
NSO_Blue
2 months, 1 week ago
Answer B is definetly wrong! The Palo Alto Firewall are not able to load balance traffic.
upvoted 1 times
...
123XYZT
7 months ago
ABE, C is only possible on Active/Passive, and D is incorrect since the config is sync on Active/Passive too.
upvoted 1 times
...
guy276465281819372
7 months, 2 weeks ago
Selected Answer: ABE
configuration is Synced in A/P too, answer is A B E.
upvoted 2 times
...
0d2fdfa
7 months, 3 weeks ago
Selected Answer: ADE
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/arp-load-sharing Firewall support ARP load sharing but not the load balancing.
upvoted 1 times
...
ThirdLevel
8 months, 1 week ago
ADE is correct
upvoted 1 times
...
joquin0020
11 months, 2 weeks ago
Selected Answer: ABE
ABE. "Active/active mode has faster failover and can handle peak traffic flows better than active/passive mode because both firewalls are actively processing traffic." Source:https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 1 times
...
evilCorpBot7494
11 months, 3 weeks ago
Selected Answer: ABE
Correct answer is ABE C makes no sense D can also be done with Active-Passive HA A is a little ambiguous since A/A HA doesn't guarantee that both fw will always be working, it just says that if one fails the other is still working, but A/P just guarantees that at least one will always be working so only A/A can achieve what A) describes B. Is the textbook definition of why Active/active HA can be useful E. Is one of the reasons why A/A HA can be faster.
upvoted 3 times
...
Metgatz
1 year, 1 month ago
A,B,E are the correct options
upvoted 1 times
...
dgonz
1 year, 4 months ago
Selected Answer: ADE
worth noting that A/A does not load balance traffic... it can load-share "An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs. Ways to load share sessions to both firewalls include using ECMP, multiple ISPs, and load balancers."
upvoted 4 times
...
Merlin0o
1 year, 4 months ago
Selected Answer: ABE
Voted ABE (D is applicable for both a/a and a/p)
upvoted 2 times
...
sov4
1 year, 5 months ago
Selected Answer: ABE
Active/Active— Both firewalls in the pair are active and processing traffic and work synchronously to handle session setup and session ownership. Both firewalls individually maintain session tables and routing tables and synchronize to each other. ctive/active mode is recommended if each firewall needs its own routing instances and you require full, real-time redundancy out of both firewalls all the time. Active/active mode has faster failover and can handle peak traffic flows better than active/passive mode because both firewalls are actively processing traffic. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 4 times
...
Betty2022
1 year, 5 months ago
Selected Answer: ADE
A,D,E Yes A:Active/active mode is recommended ..if you require full, real-time redundancy out of both firewalls all the time. Not B:An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs. Not C: active/active mode does support Layer 2 deployment, Only L3 and Vwire Yes E:Active/Active firewalls individually maintain session tables and routing tables and synchronize to each other. Leaves D, left as 3rd answer
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago