New Year Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > Paloalto Networks > Network Security Administrator > SD-WAN-Engineer

SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Question and Answers

Question # 4

Which component of the Prisma SD-WAN solution is responsible for the deep application identification (App-ID) and the generation of flow metrics (Network Transfer Time, Server Response Time) at the branch?

A.

 The CloudBlade container

B.

 The Prisma SD-WAN Controller

C.

 The ION Device Data Plane

D.

 The API Gateway

Full Access
Question # 5

What is the primary function of the "CloudBlade" platform in a Prisma SD-WAN deployment when integrating with third-party services or Prisma Access?

A.

It acts as a physical line card on the ION device to provide additional 10Gbps interfaces.

B.

It is a containerized application running on the ION device that performs Deep Packet Inspection (DPI).

C.

It is a cloud-based API integration layer that automates the configuration of the ION devices and the remote service.

D.

It is a monitoring dashboard used exclusively for viewing flow records.

Full Access
Question # 6

In a Prisma SD-WAN deployment, what is the defining characteristic of a "Standard VPN" compared to a "Secure Fabric Link"?

A.

 Standard VPNs use GRE encapsulation, while Secure Fabric Links use VXLAN.

B.

 Standard VPNs are automatically built between ION devices, while Secure Fabric Links require manual configuration.

C.

 Standard VPNs are manually configured IPSec tunnels to non-ION endpoints, while Secure Fabric Links are automated tunnels between ION devices.

D.

 Standard VPNs support BGP, whereas Secure Fabric Links only support static routing.

Full Access
Question # 7

Site templates are to be used for the large-scale deployment of 100 Prisma SD-WAN branch sites across different regions.

Which two statements align with the capabilities and best practices for Prisma SD-WAN site templates? (Choose two.)

A.

The use of Jinja conditional statements within a site template is not supported, thereby limiting dynamic customization options.

B.

Mandatory variables for any site template include the site name, ION software version, and at least one ION serial number /device name pair.

C.

Site templates offer the capability to pre-stage device configurations by creating a device shell.

D.

Once a site has been deployed using a template, its configuration can be updated or modified by applying an updated version of the template.

Full Access
Question # 8

An ION 3000 device at a remote branch has suffered a critical hardware failure and must be replaced via the RMA process. The administrator has received the replacement unit.

What is the correct procedure to transfer the configuration and license from the defective unit to the replacement unit to ensure minimal downtime and retention of historical data?

A.

 Manually configure the new device from scratch, then open a support ticket to transfer the license.

B.

 Use the "Replace Device" workflow in the Prisma SD-WAN portal, which automatically transfers the configuration (Device Shell) and re-associates the site to the new serial number.

C.

 Backup the configuration of the old device to a USB drive and restore it to the new device using the local console.

D.

 Delete the old device from the portal, create a new site for the replacement device, and rebuild the policies manually.

Full Access
Question # 9

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

A.

The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.

B.

The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.

C.

The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

D.

The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.

Full Access
Question # 10

A remote branch site is reporting intermittent connectivity to the Data Center. The administrator checks the System > Alarms page and sees a "VPN_DOWN" alarm for the tunnel to the DC. However, the internet circuit status is "Up".

Which specific log file or diagnostic tool in the Prisma SD-WAN portal would provide the IKE (Internet Key Exchange) error codes (e.g., "NO_PROPOSAL_CHOSEN" or "AUTH_FAILED") to pinpoint the cause of the tunnel failure?

A.

 Flow Browser

B.

 Event Logs > System

C.

 Site Summary > Topology

D.

 Link Quality Graphs

Full Access
Question # 11

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.

 Both sites must disable NAT and use public IPs on the ION interface.

C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.

 Dynamic VPNs are not supported if both sides are behind NAT.

Full Access
Question # 12

A multinational company is deploying Prisma SD-WAN across North America, Europe, and Asia. The data centers in the North America region have served all regions, but regional policies are now being enforced that mandate each of the regions to build their own data centers and branch sites to only connect to their respective regional data centers.

How can this regionalization be achieved so that new or existing branch sites only build tunnels to the regional DC IONs?

A.

Create a new cluster for each regional DC ION and move the sites from the existing cluster to the new cluster.

B.

Disable the auto-tunnel feature globally on the Prisma SD-WAN portal and manually create all necessary tunnels exclusively between IONs within their designated regions.

C.

Remove the circuit labels and apply new circuit labels for in-region circuits only.

D.

Assign WAN interfaces to distinct Virtual Routing and Forwarding (VRF) instances for each region on the DC IONs, ensuring that branches only connect to the WAN interfaces/VRFs designated for their region.

Full Access
Question # 13

Which statement is valid when integrating Prisma SD-WAN with Prisma Access remote networks?

A.

Security policies for remote networks are configured in Prisma Access and pushed to Prisma SD-WAN for enforcement on the branch ION devices.

B.

Easy onboarding automatically recommends the closest preconfigured remote network security processing nodes and can be overridden manually.

C.

A branch with multiple internet circuits will automatically connect to Prisma Access on each circuit and will be used in an active/standby manner for internet-bound traffic.

D.

Bandwidth must be allocated to each Prisma Access remote network compute location, and this bandwidth is shared between all branches that terminate on this remote network node.

Full Access
Question # 14

A network engineer is troubleshooting an ION device that is showing as "Offline" in the Prisma SD-WAN portal, despite the site reporting that local internet access is working. The engineer has console access to the device.

Which CLI command should be used to specifically validate the device's ability to resolve the controller's hostname and establish a secure connection to it over a specific interface?

A.

 ping

B.

 debug controller reachability

C.

 show system connectivity

D.

 dump vpn summary

Full Access
Question # 15

When identifying devices for IoT classification purposes, which two methods does Prisma SD-WAN use to discover devices that are not directly connected to the branch ION? (Choose two.)

A.

LLDP

B.

CDP

C.

SNMP

D.

Syslog

Full Access