Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks SD-WAN-Engineer Exam - Topic 2 Question 14 Discussion

Which statement is valid when integrating Prisma SD-WAN with Prisma Access remote networks?
D) Bandwidth must be allocated to each Prisma Access remote network compute location, and this bandwidth is shared between all branches that terminate on this remote network node.
A) Security policies for remote networks are configured in Prisma Access and pushed to Prisma SD-WAN for enforcement on the branch ION devices.
B) Easy onboarding automatically recommends the closest preconfigured remote network security processing nodes and can be overridden manually.
C) A branch with multiple internet circuits will automatically connect to Prisma Access on each circuit and will be used in an active/standby manner for internet-bound traffic.

Palo Alto Networks SD-WAN-Engineer Exam - Topic 2 Question 14 Discussion

Actual exam question for Palo Alto Networks's SD-WAN-Engineer exam
Question #: 14
Topic #: 2
[All SD-WAN-Engineer Questions]

Which statement is valid when integrating Prisma SD-WAN with Prisma Access remote networks?

Show Suggested Answer Hide Answer
Suggested Answer: D

Comprehensive and Detailed Explanation

When deploying Prisma Access for Remote Networks (connecting branch offices), the licensing and throughput model is based on aggregate bandwidth allocated to specific compute locations (regions).

Bandwidth Allocation (Option D): Administrators must purchase and allocate a specific amount of bandwidth (e.g., 500 Mbps, 1 Gbps) to a Prisma Access 'Compute Location' (e.g., US West, Europe Central). This allocated bandwidth is then shared as a pool among all the branch sites (Remote Networks) that onboard and terminate their IPSec tunnels at that specific location. The system does not allocate bandwidth on a strict per-site basis but rather enforces the limit on the aggregate throughput of the compute node itself.

Policy Enforcement (Option A): Security policies for Prisma Access are enforced in the cloud (at the Prisma Access Service Processing Node), not pushed down to the branch ION devices for local enforcement. The ION device handles local segmentation (ZBFW) and traffic steering, but the 'Remote Network' security stack resides in the cloud.

Path Usage (Option C): Prisma SD-WAN is designed to utilize Active/Active paths. When a branch has multiple internet circuits connected to Prisma Access, the CloudBlade and ION automatically build tunnels on all compatible paths and can load-balance traffic across them based on application performance (SLA), rather than defaulting to a strict Active/Standby model for internet traffic.


Contribute your Thoughts:

0/2000 characters
Tyra
6 days ago
C seems valid too. Active/standby for circuits is a smart way to manage traffic.
upvoted 0 times
...
Carmelina
11 days ago
I’m leaning towards B. Easy onboarding sounds really helpful for setups.
upvoted 0 times
...
Vicki
16 days ago
I think A is the right choice. It makes sense for security policies to be pushed from Prisma Access.
upvoted 0 times
...
Samuel
21 days ago
Wait, are we really sharing bandwidth across branches? That seems risky!
upvoted 0 times
...
Elroy
26 days ago
D) makes sense, but sharing bandwidth could be a problem.
upvoted 0 times
...
Reena
1 month ago
C) is interesting, but does it really work that way?
upvoted 0 times
...
Galen
1 month ago
I disagree, B) sounds more accurate for onboarding.
upvoted 0 times
...
Layla
1 month ago
A) is correct, security policies are pushed from Prisma Access.
upvoted 0 times
...
Ocie
2 months ago
D is tricky. I remember bandwidth allocation being a topic, but I can't recall if it's shared across branches or dedicated to each one.
upvoted 0 times
...
Shenika
2 months ago
C seems a bit off to me. I recall something about active/standby setups, but I thought they were more about load balancing rather than automatic connections.
upvoted 0 times
...
Diane
2 months ago
I'm not entirely sure about B, but I remember something about onboarding and how it can suggest nodes. It might be right?
upvoted 0 times
...
Celeste
2 months ago
I think option A sounds familiar since we discussed how security policies are managed in Prisma Access during our study sessions.
upvoted 0 times
...

Save Cancel