exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 322 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 322
Topic #: 1
[All PCNSE Questions]

Which three use cases are valid reasons for requiring an Active/Active high availability deployment? (Choose three.)

  • A. The environment requires real full-time redundancy from both firewalls at all times.
  • B. The environment requires that traffic be load-balanced across both firewalls to handle peak traffic spikes.
  • C. The environment requires Layer 2 interfaces in the deployment.
  • D. The environment requires that all configuration must be fully synchronized between both members of the HA pair.
  • E. The environment requires that both firewalls maintain their own routing tables for faster dynamic routing protocol convergence.
Show Suggested Answer Hide Answer
Suggested Answer: ADE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alquicerm
Highly Voted 2 years, 6 months ago
I think that it is A,B,E because configuration is fully sinchronized in a A/P too.
upvoted 19 times
443Annny
4 months, 1 week ago
it actually only synchronzid on A/P HA active/active fw don't sync their config
upvoted 1 times
...
...
divi1
Most Recent 2 weeks ago
Selected Answer: ADE
as per https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-modes An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs.
upvoted 1 times
...
m70855712
1 month, 4 weeks ago
Selected Answer: ADE
Going with A,D,E. Based on this docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 1 times
...
NullNull88
2 months, 1 week ago
Selected Answer: ABE
There's a lot left there to unpack with D. It is A, B and E
upvoted 1 times
...
ALCOSTA35
2 months, 1 week ago
Selected Answer: ADE
It is not a good practice to handle peaks using both firewall capacities. This defeats the purpose of Full redundancy, so B can't be right.
upvoted 1 times
m70855712
1 month, 4 weeks ago
Not only that, but it specifically states "An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs. Ways to load share sessions to both firewalls include using ECMP, multiple ISPs, and load balancers." https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 1 times
...
...
corpguy
3 months, 2 weeks ago
Selected Answer: ABE
the other explanations are good.
upvoted 1 times
...
TeachTrooper
3 months, 4 weeks ago
Selected Answer: ABE
Hello, if you look at the palo reference for HA Sync, you see that more things can be synced with A/P (i.e FIB,MFIB, ARP Table, MAC Table) so it is clear in Active/Active deployment full sync is beside the point.... https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization Here the question does not refer to firewall doing the load balancing, but the environment requires load balancing to allow the customer to send traffic through both firewalls.
upvoted 1 times
...
62c930f
5 months, 1 week ago
Selected Answer: ADE
Im guessing ADE, and not choosing B as Palo Alto explicitly dissuades configuring the firewalls to handle more traffic than one firewall is capable of handling. This would defeat the entire purpose of HA in the event of a failover, as the failover would result in network performance degradation from the newly created bottleneck.
upvoted 3 times
...
CarlosDV06
5 months, 1 week ago
Selected Answer: ADE
Bros the A/A does not balance the traffic, you need an external load balancer to do so. So B cannot be an option. ADC sounds accurate.
upvoted 1 times
...
NSO_Blue
6 months ago
Answer B is definetly wrong! The Palo Alto Firewall are not able to load balance traffic.
upvoted 1 times
...
123XYZT
10 months, 2 weeks ago
ABE, C is only possible on Active/Passive, and D is incorrect since the config is sync on Active/Passive too.
upvoted 1 times
...
guy276465281819372
11 months ago
Selected Answer: ABE
configuration is Synced in A/P too, answer is A B E.
upvoted 2 times
...
0d2fdfa
11 months, 1 week ago
Selected Answer: ADE
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/arp-load-sharing Firewall support ARP load sharing but not the load balancing.
upvoted 1 times
...
ThirdLevel
11 months, 4 weeks ago
ADE is correct
upvoted 1 times
...
joquin0020
1 year, 2 months ago
Selected Answer: ABE
ABE. "Active/active mode has faster failover and can handle peak traffic flows better than active/passive mode because both firewalls are actively processing traffic." Source:https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 1 times
...
evilCorpBot7494
1 year, 3 months ago
Selected Answer: ABE
Correct answer is ABE C makes no sense D can also be done with Active-Passive HA A is a little ambiguous since A/A HA doesn't guarantee that both fw will always be working, it just says that if one fails the other is still working, but A/P just guarantees that at least one will always be working so only A/A can achieve what A) describes B. Is the textbook definition of why Active/active HA can be useful E. Is one of the reasons why A/A HA can be faster.
upvoted 3 times
...
Metgatz
1 year, 4 months ago
A,B,E are the correct options
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago