Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Paloalto Networks SD-WAN-Engineer - Palo Alto Networks SD-WAN Engineer

User-ID integration is configured for a Prisma SD-WAN deployment. Branch-1 has the user-to-IP mappings available, and User-1 is mapped to IP-1.

To which two use cases can User-ID based zone-based firewall policies be applied? (Choose two.)

A.

User-1 accessing a SaaS application on direct internet and source User-ID based zone-based firewall rules on Branch-1 ION

B.

User-1 accessing a private application within Branch-1, and source User-ID based zone-based firewall rules on Branch-1 ION

C.

User-1 accessing a private application in data center via SD-WAN overlay, and destination User-ID based zone-based firewall rules on DC ION

D.

User-1 accessing a private application in Branch-2 via SD-WAN overlay, and destination User-ID based zone-based firewall rules on Branch-2 ION

What is the default behavior of the Zone-Based Firewall (ZBFW) for traffic originating from the ION device itself (e.g., DNS queries, NTP sync, or Controller connectivity) destined for the "Internet" zone?

A.

 It is denied by the default "Deny All" rule unless explicitly allowed.

B.

 It is allowed by the implicit "Self-Zone" allow rule.

C.

 It is allowed only if the "Management" interface is used.

D.

 It is inspected by the "Global" security stack but bypasses local rules.

The UI triggers incident DEVICESW_CONCURRENT_FLOWLIMIT_EXCEEDED for a branch site. Based in the image below, which tool can be used to identify the host?

A.

Run tcpdump under the LAN interface

B.

Monitor → Activity → Flows

C.

Monitor → Activity → New flows

D.

Monitor → Activity → Transaction Stats

In a data center (DC) with two ION devices, all of the remote branch Prisma SD-WAN VPNs are active only on DC ION-1.

Why are no VPNs active on DC ION-2?

A.

The BGP core peer is down.

B.

The static route to core as a next hop is missing.

C.

The ION device is behind a NAT.

D.

The DC and branches are in a different domain.

While designing a greenfield Prisma SD-WAN solution for a retailer, the risk management group requires segmentation of the retail network to avoid one large fault domain.

The following data points are provided:

    Two data centers and all sites need to access applications in both data centers

    1000 retail branches with stores concentrated in multiple metropolitan areas

    Data Center 1 and Data Center 2 have different sets of applications that are not replicated

    Maintaining application availability is the primary goal

Which action will segment the retail network and reduce regional outages?

A.

Implement a single, large data center cluster spanning both data centers to centralize management and optimize resource use.

B.

Create more than one data center cluster for a larger pool of resources and resiliency.

C.

Create more than one data center cluster in each data center and assign sites to clusters so nearby retail locations can be spread on separate clusters.

D.

Add more data center aggregation devices within the same cluster to enhance the scalability and resilience.