Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Network Security Administrator SD-WAN-Engineer Questions and answers with CertsForce

Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which component of the Prisma SD-WAN solution is responsible for the deep application identification (App-ID) and the generation of flow metrics (Network Transfer Time, Server Response Time) at the branch?

Options:

A.

 The CloudBlade container


B.

 The Prisma SD-WAN Controller


C.

 The ION Device Data Plane


D.

 The API Gateway


Expert Solution
Questions # 12:

Which configuration requirement must be met to allow two branch ION devices to automatically establish a direct Dynamic VPN (branch-to-branch) connection for traffic flow, bypassing the Data Center?

Options:

A.

Both ION devices must be members of the same VPN Cluster.


B.

A static "Gre Tunnel" must be manually configured between the two sites.


C.

The Data Center ION must be offline to trigger the dynamic failover.


D.

The "Standard VPN" path policy must be selected.


Expert Solution
Questions # 13:

A network engineer is troubleshooting a user complaint regarding "slow application performance" for an internal web application. While viewing the Flow Browser in the Prisma SD-WAN portal, the engineer notices that the Server Response Time (SRT) is consistently high (over 500ms), while the Network Transfer Time (NTT) and Round Trip Time (RTT) are low (under 50ms).

What does this data indicate about the root cause of the issue?

Options:

A.

The issue is likely caused by congestion on the WAN circuit, requiring a QoS policy adjustment.


B.

The issue is likely on the application server itself (e.g., high CPU, slow database query), not the network.


C.

The issue is caused by a high packet loss rate on the internet path.


D.

The issue is due to a misconfigured DNS server at the branch.


Expert Solution
Questions # 14:

When an ION device has been claimed, the cloud-based controller generates and communicates with the device by which method?

Options:

A.

Manufacturer Installed Certificate (MIC)


B.

Existing customer public key infrastructure (KPI)


C.

Self-signed certificate


D.

Customer Installed Certificate (CIC)


Expert Solution
Questions # 15:

A network installer is at a remote branch site to deploy a new ION 3000 device. The device has been racked, cabled to the internet, and powered on. The installer has the "Claim Code" displayed on the email sent by the administrator.

When the administrator enters this Claim Code into the Prisma SD-WAN portal, what is the immediate status of the device before the configuration is fully pushed?

Options:

A.

Online


B.

Claimed


C.

Provisioned


D.

Active


Expert Solution
Questions # 16:

A network operator receives a critical SITE_CONNECTIVITY_DOWN alarm for a branch site in the Prisma SD-WAN portal.

What specific condition triggers this alarm type?

Options:

A.

 The device has lost power and rebooted.


B.

 One of the two internet circuits at the site has gone down.


C.

 All Secure Fabric Links (VPNs) to all remote peers are down, isolating the site from the overlay.


D.

 The site has exceeded its licensed bandwidth capacity.


Expert Solution
Questions # 17:

A network installer is attempting to claim a new ION device using the "Claim Code" method. The device is connected to the internet, but the status in the portal remains stuck at "Claimed" and does not transition to "Online". The installer connects a laptop to the LAN port of the ION and can successfully browse the internet, confirming the uplink is active.

What is the most likely cause of the device failing to reach the "Online" state?

Options:

A.

 The device is missing the "Site" assignment in the portal.


B.

 The upstream firewall is blocking outbound TCP port 443 or UDP port 123 (NTP).


C.

 The device has not yet downloaded the latest software image.


D.

 The "Circuit Label" has not been applied to the WAN interface.


Expert Solution
Questions # 18:

BGP core peers on data center IONs are learning only a default route from the core router. Which action will protect the SD-WAN network from getting isolated in the event of BGP misconfiguration on the core routers?

Options:

A.

Enable BGP Bidirectional Forwarding Detection (BFD) on the core peer sessions to rapidly detect BGP neighbor failures.


B.

Configure BGP max-prefix limits on the ION devices to prevent them from accepting too many routes from the core routers.


C.

Add a static default route with higher admin distance pointing to the core peer IPs.


D.

Implement BGP route filtering using prefix lists and route maps on the ION devices to only accept specific, known prefixes from the core.1


Expert Solution
Questions # 19:

The UI triggers incident DEVICESW_CONCURRENT_FLOWLIMIT_EXCEEDED for a branch site. Based in the image below, which tool can be used to identify the host?

Question # 19

Options:

A.

Run tcpdump under the LAN interface


B.

Monitor → Activity → Flows


C.

Monitor → Activity → New flows


D.

Monitor → Activity → Transaction Stats


Expert Solution
Questions # 20:

A network engineer is able to ping and traceroute from SD-WAN branch IP 192.168.1.123 to servers in primary data center – DC1, but is unable to ping or traceroute to a server 10.2.2.22 in the newly configured secondary data center, DC2.

The DC2 ION device is advertising the branch IP subnet 192.168.1.0/24 to the DC2 core via eBGP Core Peer. The DC2 data center site has site prefix 10.2.2.0/23 configured.

Which configuration will resolve the issue in this scenario?

Options:

A.

The default 0.0.0.0/0 static route to the DC2 ION pointing to the DC2 next hop.


B.

Reconfigure eBGP Core Peer to iBGP Core Peer.


C.

Reconfigure eBGP Core Peer as Edge Peer type.


D.

Remove site prefix 10.2.2.0/23 from DC2 site configuration.


Expert Solution
Viewing page 2 out of 3 pages
Viewing questions 11-20 out of questions