Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Paloalto Networks Network Security Administrator SD-WAN-Engineer Questions and answers with CertsForce

Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions
Questions # 21:

What is the primary function of the "CloudBlade" platform in a Prisma SD-WAN deployment when integrating with third-party services or Prisma Access?

Options:

A.

It acts as a physical line card on the ION device to provide additional 10Gbps interfaces.


B.

It is a containerized application running on the ION device that performs Deep Packet Inspection (DPI).


C.

It is a cloud-based API integration layer that automates the configuration of the ION devices and the remote service.


D.

It is a monitoring dashboard used exclusively for viewing flow records.


Expert Solution
Questions # 22:

In the Prisma SD-WAN portal, an administrator is viewing the "Media" analytics for a branch site to troubleshoot complaints about poor voice quality.

When calculating the Mean Opinion Score (MOS) for voice traffic, which two metrics does the system prioritize active monitoring for, even when no user voice traffic is present on the link? (Choose two.)

Options:

A.

 Latency (One-Way)


B.

 Jitter


C.

 Throughput


D.

 Packet Loss


Expert Solution
Questions # 23:

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.


B.

 Both sites must disable NAT and use public IPs on the ION interface.


C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.


D.

 Dynamic VPNs are not supported if both sides are behind NAT.


Expert Solution
Questions # 24:

An administrator is configuring a BGP peer on a Data Center ION to learn routes from the core switch. The goal is to have the ION learn these prefixes and then advertise them to all remote branch sites across the SD-WAN overlay.

Which setting must be configured on the BGP Peer to ensure these learned routes are redistributed into the SD-WAN fabric?

Options:

A.

 Set the "Admin Distance" to 20.


B.

 Enable "Graceful Restart".


C.

 Set the "Scope" to "Global".


D.

 Configure a "Prefix List" to deny all.


Expert Solution
Questions # 25:

A network design mandates segmentation at the routing level and traffic isolation across various services, such as teller cash registers, ATM traffic, guest Wi-Fi, and corporate applications. Which command can be used to validate and display the Virtual Routing and Forwarding (VRF) route leak rules?

Options:

A.

show interface vrf route_leak_rule all


B.

dump vrf route_leak_rule


C.

inspect flow_browser vrf all


D.

inspect vrf route_leak_rule all


Expert Solution
Viewing page 3 out of 3 pages
Viewing questions 21-30 out of questions