New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Network Security Administrator SD-WAN-Engineer Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

When configuring a Path Policy rule for a "Real-Time Video" application, the administrator wants to ensure the traffic uses the path with the lowest packet loss.

How does the Prisma SD-WAN ION determine the "Packet Loss" metric for a given path when there is no active user traffic flowing on that link?

Options:

A.

 It sends Active Probes (synthetic UDP packets) across the Secure Fabric to measure path quality continuously.


B.

 It relies solely on Passive Monitoring of TCP retransmissions from other user traffic on that link.


C.

 It queries the ISP's router via SNMP to retrieve interface error counters.


D.

 It defaults to a static value of 0% loss until user traffic begins.


Expert Solution
Questions # 2:

What are two potential causes when a secondary public circuit has been added to the branch site, but the Prisma SD-WAN tunnel is not forming to the data center? (Choose two.)

Options:

A.

Interface role is not selected as “internet.”


B.

Circuit label is missing from interface type.


C.

DNS is not configured.


D.

Interface scope is set to “local.”


Expert Solution
Questions # 3:

Which specialized hardware feature is available on the ION 9000 series but NOT on the ION 3000 series, making it suitable for high-throughput Data Center deployments?

Options:

A.

 Support for LTE/5G SIM cards


B.

 Fail-to-Wire Bypass Pairs


C.

 10 Gigabit Ethernet (SFP+) ports


D.

 PoE+ (Power over Ethernet) output ports


Expert Solution
Questions # 4:

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.


B.

 Both sites must disable NAT and use public IPs on the ION interface.


C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.


D.

 Dynamic VPNs are not supported if both sides are behind NAT.


Expert Solution
Questions # 5:

Which component of the Prisma SD-WAN solution is responsible for the deep application identification (App-ID) and the generation of flow metrics (Network Transfer Time, Server Response Time) at the branch?

Options:

A.

 The CloudBlade container


B.

 The Prisma SD-WAN Controller


C.

 The ION Device Data Plane


D.

 The API Gateway


Expert Solution
Questions # 6:

During the Zero Touch Provisioning (ZTP) process of a new ION device at a branch site, which interface ports are supported by default to request an IP address via DHCP and reach the Prisma SD-WAN controller for claiming?

Options:

A.

 Only the dedicated Controller port (if available)


B.

 Any LAN or WAN port on the device


C.

 The dedicated Controller port, or Port 1 / Internet 1 if a dedicated port is absent


D.

 Only the USB port via a cellular modem


Expert Solution
Questions # 7:

Which configuration requirement must be met to allow two branch ION devices to automatically establish a direct Dynamic VPN (branch-to-branch) connection for traffic flow, bypassing the Data Center?

Options:

A.

Both ION devices must be members of the same VPN Cluster.


B.

A static "Gre Tunnel" must be manually configured between the two sites.


C.

The Data Center ION must be offline to trigger the dynamic failover.


D.

The "Standard VPN" path policy must be selected.


Expert Solution
Questions # 8:

A network engineer is troubleshooting a "Voice Quality" issue. They suspect that the DSCP markings are being stripped or altered by the ISP.

Which tool in the Prisma SD-WAN portal allows the engineer to capture live packets on the WAN interface and inspect the IP header ToS/DSCP field?

Options:

A.

 Flow Browser


B.

 Packet Capture (PCAP)


C.

 Path Quality Monitor


D.

 Event Logs


Expert Solution
Questions # 9:

A network operator receives a critical SITE_CONNECTIVITY_DOWN alarm for a branch site in the Prisma SD-WAN portal.

What specific condition triggers this alarm type?

Options:

A.

 The device has lost power and rebooted.


B.

 One of the two internet circuits at the site has gone down.


C.

 All Secure Fabric Links (VPNs) to all remote peers are down, isolating the site from the overlay.


D.

 The site has exceeded its licensed bandwidth capacity.


Expert Solution
Questions # 10:

A network installer is attempting to claim a new ION device using the "Claim Code" method. The device is connected to the internet, but the status in the portal remains stuck at "Claimed" and does not transition to "Online". The installer connects a laptop to the LAN port of the ION and can successfully browse the internet, confirming the uplink is active.

What is the most likely cause of the device failing to reach the "Online" state?

Options:

A.

 The device is missing the "Site" assignment in the portal.


B.

 The upstream firewall is blocking outbound TCP port 443 or UDP port 123 (NTP).


C.

 The device has not yet downloaded the latest software image.


D.

 The "Circuit Label" has not been applied to the WAN interface.


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions