Two nodes plus a quorum device is not high availability, it is convenience. You get shared management and easy migration, not survival of an arbitrary failure.
If a guest must stay up during a node failure, plan for three voting members from the start.
A backup job that reports success proves the job ran. It does not prove the archive restores. Restore one guest to a scratch VM every month and the difference stops being theoretical.
Keep at least one copy off the cluster. A storage failure that takes the guests usually takes the backups stored beside them.
Passthrough fails for a short list of reasons: IOMMU disabled in firmware, the device sharing a group with something the host needs, or the host driver holding the device.
Check the group membership before buying a second card to solve the problem.