New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the Paloalto Networks Network Security Administrator SD-WAN-Engineer Questions and answers with Dumpstech

Exam SD-WAN-Engineer Premium Access

View all detail and faqs for the SD-WAN-Engineer exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.

 Both sites must disable NAT and use public IPs on the ION interface.

C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.

 Dynamic VPNs are not supported if both sides are behind NAT.

Questions # 2:

A network installer is at a remote branch site to deploy a new ION 3000 device. The device has been racked, cabled to the internet, and powered on. The installer has the "Claim Code" displayed on the email sent by the administrator.

When the administrator enters this Claim Code into the Prisma SD-WAN portal, what is the immediate status of the device before the configuration is fully pushed?

Options:

A.

Online

B.

Claimed

C.

Provisioned

D.

Active

Questions # 3:

During the Zero Touch Provisioning (ZTP) process of a new ION device at a branch site, which interface ports are supported by default to request an IP address via DHCP and reach the Prisma SD-WAN controller for claiming?

Options:

A.

 Only the dedicated Controller port (if available)

B.

 Any LAN or WAN port on the device

C.

 The dedicated Controller port, or Port 1 / Internet 1 if a dedicated port is absent

D.

 Only the USB port via a cellular modem

Questions # 4:

A network operator receives a critical SITE_CONNECTIVITY_DOWN alarm for a branch site in the Prisma SD-WAN portal.

What specific condition triggers this alarm type?

Options:

A.

 The device has lost power and rebooted.

B.

 One of the two internet circuits at the site has gone down.

C.

 All Secure Fabric Links (VPNs) to all remote peers are down, isolating the site from the overlay.

D.

 The site has exceeded its licensed bandwidth capacity.

Questions # 5:

What is the default action for real-time media applications if link performance is poor?

Options:

A.

Drop the flow.

B.

Move flows.

C.

Apply Forward Error Correction (FEC).1

D.

Raise an alarm.

Questions # 6:

An organization has created a custom internal application definition for "Inventory_App" on the Prisma SD-WAN controller based on its destination IP address and port (L3/L4 rule). The application server IP has just changed.

After updating the custom application definition on the controller, how is this change propagated to the branch ION devices?

Options:

A.

 The administrator must manually "Push" the policy to all sites.

B.

 The administrator must reboot the ION devices for the new object to load.

C.

 The controller automatically pushes the updated Application Definition (App-Def) to all ION devices immediately.

D.

 The change will only take effect after the daily "App-ID" scheduled update.

Questions # 7:

What are two potential causes when a secondary public circuit has been added to the branch site, but the Prisma SD-WAN tunnel is not forming to the data center? (Choose two.)

Options:

A.

Interface role is not selected as “internet.”

B.

Circuit label is missing from interface type.

C.

DNS is not configured.

D.

Interface scope is set to “local.”

Questions # 8:

In a data center (DC) with two ION devices, all of the remote branch Prisma SD-WAN VPNs are active only on DC ION-1.

Why are no VPNs active on DC ION-2?

Options:

A.

The BGP core peer is down.

B.

The static route to core as a next hop is missing.

C.

The ION device is behind a NAT.

D.

The DC and branches are in a different domain.

Questions # 9:

By default, how many days will Prisma SD-WAN VPNs stay operational before the keys expire when an ION device loses connection with the controller?

Options:

A.

1

B.

3

C.

5

D.

7

Questions # 10:

An administrator is configuring a High Availability (HA) pair of ION 3000 devices at a Data Center.

Which statement accurately describes the requirement for the HA Control Interface connection between the two devices?

Options:

A.

 The HA Control interface must be connected via a Layer 3 routed network to ensure reachability across different subnets.

B.

 The HA Control interface must be a direct physical connection or a Layer 2 adjacent connection on a dedicated VLAN, with no routing between them.

C.

 The HA Control connection is optional if both devices are managed by the same Cloud Controller.

D.

 The HA Control interface uses the management port and must be connected to the internet.

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions