exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 322 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 322
Topic #: 1
[All PCNSE Questions]

Which three use cases are valid reasons for requiring an Active/Active high availability deployment? (Choose three.)

  • A. The environment requires real full-time redundancy from both firewalls at all times.
  • B. The environment requires that traffic be load-balanced across both firewalls to handle peak traffic spikes.
  • C. The environment requires Layer 2 interfaces in the deployment.
  • D. The environment requires that all configuration must be fully synchronized between both members of the HA pair.
  • E. The environment requires that both firewalls maintain their own routing tables for faster dynamic routing protocol convergence.
Show Suggested Answer Hide Answer
Suggested Answer: ADE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Alquicerm
Highly Voted 2 years, 9 months ago
I think that it is A,B,E because configuration is fully sinchronized in a A/P too.
upvoted 19 times
443Annny
7 months, 1 week ago
it actually only synchronzid on A/P HA active/active fw don't sync their config
upvoted 1 times
...
...
network_enthusiast
Most Recent 2 weeks, 4 days ago
Selected Answer: ABE
Active/active mode requires advanced design concepts that can result in more complex networks. Depending on how you implement active/active HA, it might require additional configuration such as activating networking protocols on both firewalls, replicating NAT pools, and deploying floating IP addresses to provide proper failover. Because both firewalls are actively processing traffic, the firewalls use additional concepts of session owner and session setup to perform Layer 7 content inspection. Active/active mode is recommended if each firewall needs its own routing instances and you require full, real-time redundancy out of both firewalls all the time. Active/active mode has faster failover and can handle peak traffic flows better than active/passive mode because both firewalls are actively processing traffic.
upvoted 1 times
...
divi1
3 months, 2 weeks ago
Selected Answer: ADE
as per https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-modes An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs.
upvoted 1 times
...
m70855712
5 months ago
Selected Answer: ADE
Going with A,D,E. Based on this docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 1 times
...
NullNull88
5 months, 2 weeks ago
Selected Answer: ABE
There's a lot left there to unpack with D. It is A, B and E
upvoted 1 times
...
ALCOSTA35
5 months, 2 weeks ago
Selected Answer: ADE
It is not a good practice to handle peaks using both firewall capacities. This defeats the purpose of Full redundancy, so B can't be right.
upvoted 1 times
m70855712
5 months ago
Not only that, but it specifically states "An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs. Ways to load share sessions to both firewalls include using ECMP, multiple ISPs, and load balancers." https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 1 times
...
...
corpguy
6 months, 2 weeks ago
Selected Answer: ABE
the other explanations are good.
upvoted 1 times
...
TeachTrooper
7 months ago
Selected Answer: ABE
Hello, if you look at the palo reference for HA Sync, you see that more things can be synced with A/P (i.e FIB,MFIB, ARP Table, MAC Table) so it is clear in Active/Active deployment full sync is beside the point.... https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization Here the question does not refer to firewall doing the load balancing, but the environment requires load balancing to allow the customer to send traffic through both firewalls.
upvoted 1 times
...
62c930f
8 months, 2 weeks ago
Selected Answer: ADE
Im guessing ADE, and not choosing B as Palo Alto explicitly dissuades configuring the firewalls to handle more traffic than one firewall is capable of handling. This would defeat the entire purpose of HA in the event of a failover, as the failover would result in network performance degradation from the newly created bottleneck.
upvoted 3 times
...
CarlosDV06
8 months, 2 weeks ago
Selected Answer: ADE
Bros the A/A does not balance the traffic, you need an external load balancer to do so. So B cannot be an option. ADC sounds accurate.
upvoted 1 times
...
NSO_Blue
9 months ago
Answer B is definetly wrong! The Palo Alto Firewall are not able to load balance traffic.
upvoted 1 times
...
123XYZT
1 year, 1 month ago
ABE, C is only possible on Active/Passive, and D is incorrect since the config is sync on Active/Passive too.
upvoted 1 times
...
guy276465281819372
1 year, 2 months ago
Selected Answer: ABE
configuration is Synced in A/P too, answer is A B E.
upvoted 2 times
...
0d2fdfa
1 year, 2 months ago
Selected Answer: ADE
https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/arp-load-sharing Firewall support ARP load sharing but not the load balancing.
upvoted 1 times
...
ThirdLevel
1 year, 2 months ago
ADE is correct
upvoted 1 times
...
joquin0020
1 year, 5 months ago
Selected Answer: ABE
ABE. "Active/active mode has faster failover and can handle peak traffic flows better than active/passive mode because both firewalls are actively processing traffic." Source:https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/ha-modes
upvoted 1 times
...
evilCorpBot7494
1 year, 6 months ago
Selected Answer: ABE
Correct answer is ABE C makes no sense D can also be done with Active-Passive HA A is a little ambiguous since A/A HA doesn't guarantee that both fw will always be working, it just says that if one fails the other is still working, but A/P just guarantees that at least one will always be working so only A/A can achieve what A) describes B. Is the textbook definition of why Active/active HA can be useful E. Is one of the reasons why A/A HA can be faster.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...