nerdexam
Palo_Alto_Networks

PCNSE · Question #286

An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing, and preemption is disabled. What must be verified to upgrade…

The correct answer is B. Applications and Threats update package. Before you upgrade, make sure the firewall is running a version of app + threat (content version) that meets the minimum requirement of the new PAN-OS (see release notes). We recommend always running the latest version of content to ensure the most accurate and effective…

Submitted by paula_co· Apr 18, 2026Operate

Question

An administrator deploys PA-500 NGFWs as an active/passive high availability pair. The devices are not participating in dynamic routing, and preemption is disabled. What must be verified to upgrade the firewalls to the most recent version of PAN-OSֲ® software?

Options

  • AAntivirus update package.
  • BApplications and Threats update package.
  • CUser-ID agent.
  • DWildFire update package.

How the community answered

(46 responses)
  • A
    7% (3)
  • B
    76% (35)
  • C
    4% (2)
  • D
    13% (6)

Explanation

Before you upgrade, make sure the firewall is running a version of app + threat (content version) that meets the minimum requirement of the new PAN-OS (see release notes). We recommend always running the latest version of content to ensure the most accurate and effective protections are being applied. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRrCAK https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-upgrade/upgrade-pan-os/upgrade-the- firewall-pan-os/upgrade-an-ha-firewall-pair

Topics

#PAN-OS Upgrade#High Availability#Content Updates#Upgrade Pre-requisites

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice