Where do you check the status of active control connections in vManage?
This is the correct path to view active control plane sessions.
Why this answer
Monitor > Network > Select Device > Control > Connections.
175 questions total · 3pages · All types, answers revealed
Page 1 of 3
Page 2Where do you check the status of active control connections in vManage?
This is the correct path to view active control plane sessions.
Why this answer
Monitor > Network > Select Device > Control > Connections.
You need to allow direct internet access for SaaS applications from the branch site. What is the correct term for this configuration?
DIA is the standard term for local internet egress.
Why this answer
Local Internet Breakout (LIB) is the feature that allows traffic to bypass the hub and go directly to the internet.
If an ION device is not receiving DHCP addresses from an upstream provider, where should you look first?
This is where DHCP client settings are configured.
Why this answer
The WAN interface configuration and status are the first places to verify DHCP settings.
You need to ensure that traffic from a specific subnet is placed into a unique VRF. How is this achieved?
Interface-level mapping dictates VRF membership.
Why this answer
VRF assignment is mapped to local segments or subnets at the interface configuration level.
What is the purpose of the 'Zone' configuration on an ION device in a Unified SASE context?
Segmentation via zones allows granular policy application.
Why this answer
Zones are used to segment traffic logically, allowing for different policies to be applied to different traffic types or users.
What is the purpose of 'Bandwidth Groups' in Prisma SD-WAN?
This simplifies policy application across grouped links.
Why this answer
Bandwidth groups aggregate multiple WAN links to manage total capacity and policy-based steering as a single logical pipe.
Which TWO visibility tools help monitor the Unified SASE traffic flow?
Centralized logs provide end-to-end flow visibility.
Why this answer
Visibility is provided by the SD-WAN controller dashboards and the unified logging service.
Which TWO actions can be performed by the SD-WAN controller to manage SASE security policy?
Linking applications to policies is a core controller function.
Why this answer
The controller acts as the single point for defining and pushing security policies to the edges.
When integrating Prisma SD-WAN with Prisma Access, how does the system ensure that the security policy is applied to the traffic correctly based on the user's identity?
CIE integration allows the user identity to be associated with the traffic flow.
Why this answer
The ION device retrieves user identity context, which is passed through the tunnel to Prisma Access, where the security policy is applied.
Which menu path is used to view the real-time tunnel statistics for a specific vEdge router?
This path leads directly to tunnel-specific performance statistics.
Why this answer
Monitor > Network allows you to select a specific device and view its tunnel performance.
A branch office requires local breakout for SaaS traffic. How do you configure the policy to ensure this traffic does not traverse the data center?
Local breakout action directs traffic to the local WAN interface.
Why this answer
The destination-based policy for direct internet access (DIA) ensures local traffic exits locally.
If a user is incorrectly identified in a SASE security log, which part of the Unified SASE architecture should be investigated first?
CIE is the source of user identity information.
Why this answer
CIE is responsible for mapping IP addresses to users; an incorrect mapping suggests an issue with the CIE-to-SASE synchronization.
You need to restrict administrative access to the ION device. Where is this configured?
This is the correct location for restricting management access.
Why this answer
Management access policies are defined under the device configuration settings in the Controller.
What are the primary benefits of implementing a hub-and-spoke design with Prisma SD-WAN? (Choose THREE)
Easier to manage at the hub.
Why this answer
Centralized security, easier management, and traffic grooming are benefits of hub-and-spoke.
Where do you go in vManage to generate a report on historical bandwidth utilization for a specific site?
This is the central location for generating historical usage reports.
Why this answer
vManage provides a Reporting section specifically for historical analysis of interface and application metrics.
During pre-deployment planning for a high-security site, you must implement an identity-aware firewall policy. Where is this configuration mapped in the Prisma SD-WAN Controller?
This is the specific location for identity-driven firewall rules.
Why this answer
The Security Policy allows for user-identity mapping and service enforcement.
What does the 'Flow Monitor' tool primarily track?
It tracks flow-level metrics including source, destination, and app.
Why this answer
The Flow Monitor provides granular details on active traffic sessions.
How does Prisma SD-WAN handle DNS queries for branch users?
DNS proxying is a standard feature to optimize performance.
Why this answer
Prisma SD-WAN can act as a DNS proxy or forwarder to improve efficiency.
Which dashboard component in vManage provides an 'at-a-glance' health score for the entire SD-WAN fabric?
This dashboard provides the high-level health score for the overlay.
Why this answer
The Network Health dashboard provides an aggregated score based on various site and device metrics.
When DCI is implemented via an L3VPN overlay, which OMP attribute is most critical to ensure traffic prefers the direct link over the DCI link for reaching local subnets?
Higher TLOC preference ensures the fabric prefers a specific path.
Why this answer
OMP TLOC preference is used to influence path selection across different transports and links.
Which Prisma SD-WAN component is responsible for orchestrating the overall security policy across the entire fabric?
The Controller is the central management authority.
Why this answer
The Controller manages global policies, including security policies, pushed to ION devices.
When configuring an ION device as a gateway for a cloud environment, what is the primary role of a 'Service' interface?
Service interfaces handle internal traffic segments.
Why this answer
Service interfaces are designated for specific traffic flows or service chains within the SD-WAN fabric.
Which Prisma SD-WAN tool is used to monitor real-time health and performance of the SD-WAN fabric during the deployment phase?
The Controller Dashboard is the primary tool for monitoring fabric health.
Why this answer
The Prisma SD-WAN Controller provides the dashboard and analytics tools for monitoring.
You notice an ION device is showing as 'Disconnected' in the Controller UI. What is the first step you should take?
Verifying physical and link layer connectivity is the standard starting point.
Why this answer
Verifying WAN connectivity and local interface status is the logical first step in troubleshooting connectivity.
To ensure high availability, you are implementing Active-Active gateway deployment at a large branch. What is required for this to work correctly?
Heartbeat ensures the gateways know each other's status and fail over correctly.
Why this answer
Active-Active deployment requires synchronization between the gateways, typically via a heartbeat link.
Which TWO of the following are benefits of using Prisma SD-WAN?
Centralization is a key benefit.
Why this answer
The solution aims to simplify management and optimize performance.
In a multi-homed DCI scenario, you are seeing asymmetric routing. What is the most likely cause within the OMP domain?
Inconsistent TLOC preference is a common source of asymmetry in DCI.
Why this answer
Asymmetry occurs when the return path preference differs from the forward path due to OMP path attribute configurations.
What is the effect of changing the 'Path Selection' strategy from 'Latency' to 'Lowest Cost' in a policy?
Cost is the primary factor in this algorithm.
Why this answer
'Lowest Cost' prioritizes links with lower administrative or service costs rather than performance metrics.
When planning for a large-scale deployment, which items are required for the initial site information gather? (Choose THREE)
Required for QoS and optimization.
Why this answer
Knowing local WAN IPs, LAN subnets, and bandwidth requirements is essential for design.
If a user at a branch site reports that they cannot access a specific internal server, which diagnostic tool should you use first?
This allows you to see the traffic path and drop points.
Why this answer
Flow monitoring allows you to see if traffic is hitting the expected policy and where it is being dropped or steered.
In a Unified SASE architecture, an administrator needs to ensure that branch offices prioritize voice traffic while using Prisma Access. Where should the Quality of Service (QoS) policy be defined to ensure consistent application performance?
The SD-WAN controller manages the traffic shaping and prioritization before it hits the WAN.
Why this answer
QoS policies must be defined on the Prisma SD-WAN side to ensure traffic is queued correctly before being encapsulated into the Service Connection tunnel.
Which THREE pieces of information are critical when opening a support ticket for a suspected SD-WAN bug?
Provides the engineering data required for analysis.
Why this answer
Technical support requires device logs, packet captures, and a clear description of the issue.
What is the purpose of the 'site-id' in the Prisma SD-WAN branch configuration?
The site-id is essential for fabric addressing and policy scoping.
Why this answer
The site-id is a unique identifier used to manage and reference the site within the SD-WAN fabric.
A specific branch is failing to steer traffic via the preferred ISP despite a defined Path Policy. What is the most likely cause?
If the app is misidentified, the policy engine will not apply the intended path rule.
Why this answer
Application definitions often rely on IP ranges or DSCP tags that may not match if traffic is incorrectly identified.
A customer wants to deploy a Hub-and-Spoke model with redundant hubs. What must be configured to ensure seamless transition if the primary hub fails?
Setting priorities ensures the system knows which hub to prefer.
Why this answer
Configuring redundant hubs in the controller allows the spokes to fail over to the secondary hub automatically.
Which component manages the configuration and policy definition for a fleet of Prisma SD-WAN ION devices?
The controller is the centralized management platform.
Why this answer
The Prisma SD-WAN Controller is the single pane of glass for managing all ION devices and policies.
You are verifying the status of a Service Connection between a branch ION and Prisma Access. Which command or dashboard view provides the most accurate status of the tunnel reachability?
This dashboard is designed to monitor the health of connections to Prisma Access.
Why this answer
The Prisma SD-WAN Controller dashboard provides a clear Service Connection status widget that shows tunnel up/down state.
Which of the following is a benefit of a Unified SASE architecture?
This is the primary benefit of the integration.
Why this answer
Unified SASE combines networking (SD-WAN) and security (SASE) into a single management plane, simplifying operations.
In a scenario where a branch office loses its internet connection, what happens to the Unified SASE connection?
SD-WAN is designed to maintain connectivity via alternative paths if available.
Why this answer
The Service Connection is lost, and if configured, the SD-WAN will failover to a backup WAN path or enter a local-only state depending on the policy.
Which mechanism would explain why traffic is taking a sub-optimal path despite a policy favoring a different link?
Failover occurs automatically when the preferred path is deemed unhealthy.
Why this answer
If the preferred path fails the path-health check, the ION will automatically fail over to a sub-optimal path.
Which TWO factors contribute to the 'Path Health' score?
Directly impacts the health score.
Why this answer
The path health score is calculated based on packet loss and latency.
A user reports that a specific SaaS application is being blocked, but no security policy matches are seen. What is the most likely cause?
If no explicit allow rule matches, traffic is dropped by the implicit deny.
Why this answer
If no policy match is found, the traffic may be hitting the default implicit deny or is being blocked by a local device policy.
Which TWO metrics are displayed in the Path Quality dashboard?
Key indicator of path delay.
Why this answer
The dashboard displays jitter and latency as key performance indicators.
Which protocol is utilized for the auto-discovery of Prisma SD-WAN Gateways during site provisioning?
ZTP allows for the automated registration and configuration of new gateways.
Why this answer
The Zero-Touch Provisioning (ZTP) process uses the controller to push configurations after the gateway registers via the secure cloud portal.
When designing a multi-tenant environment, how does the Prisma SD-WAN Controller ensure that management traffic is separated for each entity?
The controller architecture natively supports tenant-based logical isolation.
Why this answer
The Controller uses multi-tenancy constructs where each tenant is logically partitioned.
Which Prisma SD-WAN interface is used to connect to the local LAN?
LAN interfaces are used for internal network connectivity.
Why this answer
The LAN-side interface connects to switches, servers, and internal users.
Which command or interface path is used to verify the status of the SD-WAN tunnel between two branch sites?
The monitoring section of the controller provides the status and health of all tunnels.
Why this answer
The Dashboard or the 'show' commands in the CLI allow for tunnel status verification.
Which Prisma SD-WAN feature enables the automatic configuration of security parameters for a new gateway?
Security templates simplify the deployment by pushing standardized policies to gateways.
Why this answer
The security template is a container that holds policies, which are applied to gateways during provisioning.
When defining an Application Steering Policy in a Unified SASE environment, what is the advantage of using 'Application Groups'?
This simplifies management and ensures consistency.
Why this answer
Application groups allow for policy abstraction, so multiple apps can be steered using a single policy definition.
You have a DCI configuration where two data centers are connected via a dedicated link. You want to ensure the DCI link is only used if the primary WAN transport fails. How do you achieve this?
Lower preference ensures that traffic prefers other paths unless the DCI path is the only one remaining.
Why this answer
OMP TLOC preference can be used to steer traffic to specific paths based on preference values.
A branch office uses both MPLS and Broadband. The design requires that business-critical traffic prefers MPLS, failing over to Broadband only if the MPLS path experiences packet loss exceeding 1%. Which metric should the PFR policy utilize?
This is the specific metric to trigger the failover based on the 1% threshold.
Why this answer
Performance Routing policies rely on path metrics like loss, latency, and jitter to make routing decisions.
Which TWO features are included in the vManage 'Monitor' menu?
Essential for daily monitoring of the fabric.
Why this answer
The Monitor menu is the central hub for observing the SD-WAN fabric performance.
Which THREE factors can cause a site to go into 'Disconnected' state in the orchestrator?
Prevents secure tunnel establishment.
Why this answer
Loss of internet, controller reachability issues, and incorrect time settings are common causes.
You need to ensure that branch office voice traffic always has the lowest latency. Which QoS classification strategy is recommended?
DSCP-based classification and strict priority queuing are best for voice.
Why this answer
Prioritizing voice (EF class) in the QoS policy ensures it gets priority access to the transport queue.
A customer is experiencing intermittent connectivity to internal applications after enabling Unified SASE. Traffic is being routed through Prisma Access. What is the most likely cause?
IPSec encapsulation adds overhead, requiring MSS adjustment to prevent fragmentation.
Why this answer
MTU/MSS mismatches are a common issue when encapsulating traffic through tunnels, especially in SASE environments.
Which TWO factors are used by Prisma SD-WAN to determine the health of a WAN path?
Loss is a primary performance metric.
Why this answer
The SD-WAN engine monitors latency and loss to calculate path quality.
Which of the following are valid transport types that can be defined in a Prisma SD-WAN site configuration? (Choose TWO)
Valid transport type.
Why this answer
Public Internet and MPLS are standard transport categories in the SD-WAN policy engine.
What is the primary function of the 'Controller' dashboard in the Prisma SD-WAN UI?
The dashboard is for monitoring.
Why this answer
The dashboard provides a high-level view of health, status, and traffic analytics.
Which criteria can be used to steer traffic in a Performance Routing policy? (Choose TWO)
Key performance metric.
Why this answer
Latency and packet loss are key metrics used to determine the best path in PFR.
Which command or interface action is used to verify the current status of the SD-WAN overlay tunnels?
This interface specifically tracks SD-WAN overlay status.
Why this answer
The Controller dashboard or the ION CLI provides real-time tunnel status.
What is the impact of assigning a site to a specific 'Site Group' in a Prisma SD-WAN policy?
This is the core purpose of logical grouping.
Why this answer
Site Groups allow for scalable policy application across multiple sites with similar requirements.
Which of these tasks are part of the pre-deployment planning phase for Prisma SD-WAN? (Choose TWO)
Ensures the underlying transport is ready.
Why this answer
Assessing current bandwidth usage and identifying critical applications are vital first steps.
You need to ensure that specific branch traffic is encrypted over a public internet link. Which configuration step is mandatory?
Auto-VPN is the primary mechanism for secure site-to-site connectivity.
Why this answer
VPN tunnels are established automatically between ION devices when policies are defined, but the path must be categorized to allow tunnel formation.
Which TWO actions can resolve persistent high latency on a path?
Reduces congestion-related latency.
Why this answer
Configuring path selection policies to avoid the path or adjusting QoS settings can mitigate the impact of high latency.
You need to see the exact DSCP markings on packets exiting the ION. Which tool should you use?
Capturing packets reveals header information including DSCP.
Why this answer
A Packet Capture allows for deep packet inspection of headers like DSCP.
Which THREE types of information are displayed in the Prisma SD-WAN 'Flow Monitoring' view?
Identifies the endpoints.
Why this answer
Flow monitoring provides details on path, performance, and application statistics.
What is the role of the 'Service Connection' in the Prisma SD-WAN interface?
It specifies the destination and connectivity settings for the SASE edge.
Why this answer
A Service Connection is a logical construct that maps traffic from the SD-WAN fabric to external services like Prisma Access.
When configuring Data Center Interconnect (DCI) between two sites, you notice that routing loops are occurring. What is the most effective way to prevent this in a dual-homed DCI scenario?
SoO tags are specifically designed to prevent loops in multi-homed BGP/OMP environments.
Why this answer
Setting appropriate OMP administrative distances or using site-of-origin tags prevents routing loops in DCI.
A site has two ISPs. Traffic is only using one. What is the best way to verify if both paths are available?
This dashboard shows current latency/loss for all paths.
Why this answer
The Path Quality dashboard displays the health status of all defined paths.
Which dashboard provides the most detailed information regarding the health of individual tunnels within an SD-WAN fabric?
This dashboard focuses on tunnel-specific performance indicators.
Why this answer
The Tunnel Health dashboard is designed specifically to aggregate and report on tunnel performance metrics.
An organization is migrating to Unified SASE. When configuring the 'Direct to App' policy for branch offices, what is the primary benefit of leveraging the Prisma SD-WAN integration with Prisma Access?
This is the core value proposition of the Unified SASE integration.
Why this answer
The integration allows for dynamic path selection and security enforcement, ensuring that traffic is sent directly to the app when possible, or via Prisma Access when security inspection is required.
If a device is stuck in 'In-Progress' during a template push, what is the first troubleshooting step?
Device Tasks provide the most accurate status of a deployment operation.
Why this answer
The device task view provides specific error messages explaining why a push is stalling.
What information is provided by the 'Controller Status' widget on the dashboard?
It indicates if the management tunnel is active.
Why this answer
It confirms the connectivity status between the ION and the controller.
Which THREE factors must be considered when designing a high-availability (HA) Service Connection to Prisma Access?
The policy must know how to fail over.
Why this answer
HA relies on path diversity, multiple tunnels, and proper failover configuration.
You are implementing a QoS policy. Why would you configure a 'Shaping' rate on a WAN interface?
Shaping aligns egress traffic with the ISP's bandwidth contract.
Why this answer
Shaping limits the outbound rate of traffic to match the committed information rate (CIR) of the circuit.
Page 1 of 3
Page 2Practice SD-WAN-Engineer by domain
Target a specific domain to shore up weak areas.
See all domains with question counts →