Winter Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

Passed Exam Today SD-WAN-Engineer

Palo Alto Networks SD-WAN Engineer Questions and Answers

Question 13

What is the purpose of Secure Group Tag (SGT) propagation in Prisma SD-WAN?

Options:

A.

To integrate with external identity-based security solutions

B.

To manage QoS policies for traffic based on user and application type

C.

To clarify the intent of rules or configuration objects and improve rule organization

D.

To enable or disable SGT settings at the interface level and initiate services like NTP, DHCP, and App Probes

Question 14

A network administrator notices that a branch ION device is experiencing high CPU utilization due to a suspected TCP SYN Flood attack originating from a compromised host on the local LAN.

Which specific security feature should be configured and applied to the "LAN" zone to mitigate this Denial of Service (DoS) attack?

Options:

A.

 Zone-Based Firewall (ZBFW) Rule with a "Deny" action

B.

 Zone Protection Profile

C.

 Application Quality Profile (AQP)

D.

 Access Control List (ACL) on the WAN interface

Question 15

When configuring a Path Policy rule for a "Real-Time Video" application, the administrator wants to ensure the traffic uses the path with the lowest packet loss.

How does the Prisma SD-WAN ION determine the "Packet Loss" metric for a given path when there is no active user traffic flowing on that link?

Options:

A.

 It sends Active Probes (synthetic UDP packets) across the Secure Fabric to measure path quality continuously.

B.

 It relies solely on Passive Monitoring of TCP retransmissions from other user traffic on that link.

C.

 It queries the ISP's router via SNMP to retrieve interface error counters.

D.

 It defaults to a static value of 0% loss until user traffic begins.

Question 16

An administrator needs to ensure that critical VoIP traffic is not dropped even when the branch's primary internet link is fully saturated with bulk file transfers.

Which QoS mechanism does Prisma SD-WAN automatically apply to the "Platinum" priority class to prevent starvation by lower-priority classes?

Options:

A.

 Strict Priority Queuing (SPQ)

B.

 Weighted Round Robin (WRR)

C.

 Hierarchical Token Bucket (HTB) with guaranteed bandwidth

D.

 First-In, First-Out (FIFO)