PCNSE Exam QuestionsBrowse all questions from this exam

PCNSE Exam - Question 322


Which three use cases are valid reasons for requiring an Active/Active high availability deployment? (Choose three.)

Show Answer
Correct Answer: ABE

Active/Active high availability deployments are used in environments requiring real full-time redundancy from both firewalls, ensuring continuous operation even if one fails. This deployment is also necessary when traffic needs to be load-shared across both firewalls to handle peak traffic spikes, allowing better traffic management and reduced latency. Additionally, Active/Active HA ensures that both firewalls maintain their own routing tables, enabling faster dynamic routing protocol convergence and improving overall network resilience and performance.

Discussion

17 comments
Sign in to comment
AlquicermOptions: ABE
Oct 25, 2022

I think that it is A,B,E because configuration is fully sinchronized in a A/P too.

sov4Options: ABE
Jul 30, 2023

Active/Active— Both firewalls in the pair are active and processing traffic and work synchronously to handle session setup and session ownership. Both firewalls individually maintain session tables and routing tables and synchronize to each other. ctive/active mode is recommended if each firewall needs its own routing instances and you require full, real-time redundancy out of both firewalls all the time. Active/active mode has faster failover and can handle peak traffic flows better than active/passive mode because both firewalls are actively processing traffic. https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/ha-concepts/ha-modes

[Removed]Options: ABE
Apr 5, 2023

full synchronization is also available in active /passive

dgonzOptions: ADE
Sep 6, 2023

worth noting that A/A does not load balance traffic... it can load-share "An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs. Ways to load share sessions to both firewalls include using ECMP, multiple ISPs, and load balancers."

evilCorpBot7494Options: ABE
Jan 25, 2024

Correct answer is ABE C makes no sense D can also be done with Active-Passive HA A is a little ambiguous since A/A HA doesn't guarantee that both fw will always be working, it just says that if one fails the other is still working, but A/P just guarantees that at least one will always be working so only A/A can achieve what A) describes B. Is the textbook definition of why Active/active HA can be useful E. Is one of the reasons why A/A HA can be faster.

Merlin0oOptions: ABE
Sep 5, 2023

Voted ABE (D is applicable for both a/a and a/p)

guy276465281819372Options: ABE
Jun 2, 2024

configuration is Synced in A/P too, answer is A B E.

Frightened_AcrobatOptions: ABE
Mar 17, 2023

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/high-availability/ha-concepts/ha-modes A. Yes. "you require full, real-time redundancy out of both firewalls all the time." B. Yes. "you can load-share by sending traffic to the peer" and "the HA pair can be used to temporarily process more traffic than what one firewall can normally handle." C. No. "Active/active HA is supported in virtual wire and Layer 3 deployments." D. No. "Active/Passive— share the same configuration settings" This is not unique to active/active. E. Yes. "Both firewalls individually maintain session tables and routing tables" Though I don't like that B contradics "no load balancing occurs," it's still the only viable third answer here.

sujss
Apr 29, 2023

D. But still it doenst mean that D fullfills that requirement ? As CertboxExam correctly pointed out, Active/Active doesnt do load-balance.

sujss
Apr 29, 2023

Apologies, D. But still it doesn't mean that D cannot fullfills that requirement ?

Creep099Options: ABE
May 19, 2023

b is for active/active

dgonzOptions: ABE
Jul 6, 2023

I vote ABE.

GiorgioLDNOptions: ABE
Jul 14, 2023

1. configuration is fully synchronised in a A/P too. 2. C doesn't make any sense at all.

Betty2022Options: ADE
Jul 30, 2023

A,D,E Yes A:Active/active mode is recommended ..if you require full, real-time redundancy out of both firewalls all the time. Not B:An active/active configuration does not load-balance traffic. Although you can load-share by sending traffic to the peer, no load balancing occurs. Not C: active/active mode does support Layer 2 deployment, Only L3 and Vwire Yes E:Active/Active firewalls individually maintain session tables and routing tables and synchronize to each other. Leaves D, left as 3rd answer

MetgatzOptions: ABE
Dec 11, 2023

A,B,E are the correct options

joquin0020Options: ABE
Feb 4, 2024

ABE. "Active/active mode has faster failover and can handle peak traffic flows better than active/passive mode because both firewalls are actively processing traffic." Source:https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/ha-modes

ThirdLevelOptions: ADE
May 7, 2024

ADE is correct

0d2fdfaOptions: ADE
May 23, 2024

https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/high-availability/ha-concepts/arp-load-sharing Firewall support ARP load sharing but not the load balancing.

123XYZTOptions: ABE
Jun 17, 2024

ABE, C is only possible on Active/Passive, and D is incorrect since the config is sync on Active/Passive too.