Palo Alto Networks NetSec-Pro Prisma SD-WAN Path NAT And Zone-Based Security Practice Test

 

This Palo Alto Networks Network Security Professional practice test focuses on prisma sd-wan path nat and zone-based security through original scenario-based questions aligned to the June 2026 NetSec-Pro blueprint. Use the full ExamSnap NetSec-Pro collection for broader practice across all current blueprint domains. For broader exam preparation, review the Palo Alto Networks NetSec-Pro Exam Dumps page.

Question 1

While validating a deployment for Lucerne Publishing, an architect must ensure the design can steer a latency-sensitive application over the path that best meets performance requirements. What should be done?

  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization

Correct answer: D

Explanation

  1. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  2. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  3. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  4. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This directly satisfies one of the stated requirement(s).
  5. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.

Learning point: NETSEC-T06-Q001: Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path.

 

Question 2

At A. Datum Research, the network security team needs to enforce branch application access between security zones. Which approach best meets the requirement?

  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules

Correct answer: E

Explanation

  1. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  2. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  3. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  4. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  5. Prisma SD-WAN security policies control application access within or across zones at branch sites. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T06-Q002: Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules.

 

Question 3

Coho Winery is reviewing its Palo Alto Networks deployment. What should the administrator do to avoid assuming path policy alone grants application access?

  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Monitor path health and application flow metrics rather than judging performance only from link-up status
  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization

Correct answer: E

Explanation

  1. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  2. A link can be operational yet unsuitable due to latency, jitter, loss, or transaction performance; telemetry provides the needed detail. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  3. Central policy promotes consistency while site scoping allows controlled variation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  4. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  5. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T06-Q003: Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization.

 

Question 4

During a design review for Trey Research, the requirement is to observe why a branch flow selected a particular WAN path. Which choice is most appropriate?

  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path

Correct answer: D

Explanation

  1. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  2. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  3. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  4. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This directly satisfies one of the stated requirement(s).
  5. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.

Learning point: NETSEC-T06-Q004: Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics.

 

Question 5

A change request at Wide World Importers states that the team must prefer one path for normal traffic but fail over when quality degrades. What is the best response?

  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule

Correct answer: D

Explanation

  1. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  2. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  3. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  4. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This directly satisfies one of the stated requirement(s).
  5. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.

Learning point: NETSEC-T06-Q005: Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path.

 

Question 6

An engineer at Contoso Retail is troubleshooting a configuration decision. Which action directly addresses the need to control address translation for branch traffic where translation is required?

  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Monitor path health and application flow metrics rather than judging performance only from link-up status
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ

Correct answer: D

Explanation

  1. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control address translation for branch traffic where translation is required.
  2. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control address translation for branch traffic where translation is required.
  3. A link can be operational yet unsuitable due to latency, jitter, loss, or transaction performance; telemetry provides the needed detail. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control address translation for branch traffic where translation is required.
  4. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This directly satisfies one of the stated requirement(s).
  5. Central policy promotes consistency while site scoping allows controlled variation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control address translation for branch traffic where translation is required.

Learning point: NETSEC-T06-Q006: Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule.

 

Question 7

Which option best supports the goal to limit branch-to-branch access to required applications in Fabrikam Health’s Palo Alto Networks environment?

  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules

Correct answer: D

Explanation

  1. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): limit branch-to-branch access to required applications.
  2. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): limit branch-to-branch access to required applications.
  3. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): limit branch-to-branch access to required applications.
  4. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This directly satisfies one of the stated requirement(s).
  5. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): limit branch-to-branch access to required applications.

Learning point: NETSEC-T06-Q007: Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric.

 

Question 8

A security review at Northwind Traders identifies a gap. The team wants to troubleshoot a flow denied even though a preferred WAN path exists. Which action should it take?

  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed

Correct answer: E

Explanation

  1. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This can be valid in another context, but it does not directly satisfy the stated requirement(s): troubleshoot a flow denied even though a preferred WAN path exists.
  2. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): troubleshoot a flow denied even though a preferred WAN path exists.
  3. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): troubleshoot a flow denied even though a preferred WAN path exists.
  4. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): troubleshoot a flow denied even though a preferred WAN path exists.
  5. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T06-Q008: Check the matching zone-based security policy because security policy can prune paths that are not allowed.

 

Question 9

Wingtip Logistics has two related requirements: it must standardize branch security while preserving local exceptions only where justified, and it must also enforce branch application access between security zones. Which TWO actions best satisfy these requirements? Select two.

  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization

Correct answers: B, C

Explanation

  1. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): standardize branch security while preserving local exceptions only where justified; enforce branch application access between security zones.
  2. Central policy promotes consistency while site scoping allows controlled variation. This directly satisfies one of the stated requirement(s).
  3. Prisma SD-WAN security policies control application access within or across zones at branch sites. This directly satisfies one of the stated requirement(s).
  4. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): standardize branch security while preserving local exceptions only where justified; enforce branch application access between security zones.
  5. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): standardize branch security while preserving local exceptions only where justified; enforce branch application access between security zones.

Learning point: NETSEC-T06-Q009: Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ; Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules.

 

Question 10

At Woodgrove Bank, the network security team needs to verify application experience across multiple circuits. Which approach best meets the requirement?

  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Monitor path health and application flow metrics rather than judging performance only from link-up status
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics

Correct answer: B

Explanation

  1. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify application experience across multiple circuits.
  2. A link can be operational yet unsuitable due to latency, jitter, loss, or transaction performance; telemetry provides the needed detail. This directly satisfies one of the stated requirement(s).
  3. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify application experience across multiple circuits.
  4. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify application experience across multiple circuits.
  5. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify application experience across multiple circuits.

Learning point: NETSEC-T06-Q010: Monitor path health and application flow metrics rather than judging performance only from link-up status.

 

Question 11

Alpine Ski House is reviewing its Palo Alto Networks deployment. What should the administrator do to steer a latency-sensitive application over the path that best meets performance requirements?

  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric

Correct answer: A

Explanation

  1. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This directly satisfies one of the stated requirement(s).
  2. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  3. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  4. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  5. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.

Learning point: NETSEC-T06-Q011: Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path.

 

Question 12

During a design review for Litware Manufacturing, the requirement is to enforce branch application access between security zones. Which choice is most appropriate?

  • Monitor path health and application flow metrics rather than judging performance only from link-up status
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules

Correct answer: E

Explanation

  1. A link can be operational yet unsuitable due to latency, jitter, loss, or transaction performance; telemetry provides the needed detail. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  2. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  3. Central policy promotes consistency while site scoping allows controlled variation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  4. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  5. Prisma SD-WAN security policies control application access within or across zones at branch sites. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T06-Q012: Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules.

 

Question 13

A change request at Adventure Works states that the team must avoid assuming path policy alone grants application access. What is the best response?

  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path

Correct answer: C

Explanation

  1. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  2. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  3. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This directly satisfies one of the stated requirement(s).
  4. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  5. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.

Learning point: NETSEC-T06-Q013: Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization.

 

Question 14

An engineer at Proseware Services is troubleshooting a configuration decision. Which action directly addresses the need to observe why a branch flow selected a particular WAN path?

  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path

Correct answer: C

Explanation

  1. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  2. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  3. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This directly satisfies one of the stated requirement(s).
  4. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  5. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.

Learning point: NETSEC-T06-Q014: Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics.

 

Question 15

Which option best supports the goal to prefer one path for normal traffic but fail over when quality degrades in Wingtip Logistics’s Palo Alto Networks environment?

  • Monitor path health and application flow metrics rather than judging performance only from link-up status
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path

Correct answer: E

Explanation

  1. A link can be operational yet unsuitable due to latency, jitter, loss, or transaction performance; telemetry provides the needed detail. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  2. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  3. Central policy promotes consistency while site scoping allows controlled variation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  4. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  5. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T06-Q015: Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path.

 

Question 16

A security review at Blue Yonder Airlines identifies a gap. The team wants to control address translation for branch traffic where translation is required. Which action should it take?

  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules

Correct answer: C

Explanation

  1. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control address translation for branch traffic where translation is required.
  2. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control address translation for branch traffic where translation is required.
  3. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This directly satisfies one of the stated requirement(s).
  4. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control address translation for branch traffic where translation is required.
  5. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): control address translation for branch traffic where translation is required.

Learning point: NETSEC-T06-Q016: Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule.

 

Question 17

While validating a deployment for Fourth Coffee, an architect must ensure the design can limit branch-to-branch access to required applications. What should be done?

  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric

Correct answer: E

Explanation

  1. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): limit branch-to-branch access to required applications.
  2. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): limit branch-to-branch access to required applications.
  3. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): limit branch-to-branch access to required applications.
  4. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): limit branch-to-branch access to required applications.
  5. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T06-Q017: Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric.

 

Question 18

Contoso Retail has two related requirements: it must troubleshoot a flow denied even though a preferred WAN path exists, and it must also avoid assuming path policy alone grants application access. Which TWO actions best satisfy these requirements? Select two.

  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ
  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric

Correct answers: B, C

Explanation

  1. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): troubleshoot a flow denied even though a preferred WAN path exists; avoid assuming path policy alone grants application access.
  2. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This directly satisfies one of the stated requirement(s).
  3. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This directly satisfies one of the stated requirement(s).
  4. Central policy promotes consistency while site scoping allows controlled variation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): troubleshoot a flow denied even though a preferred WAN path exists; avoid assuming path policy alone grants application access.
  5. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This can be valid in another context, but it does not directly satisfy the stated requirement(s): troubleshoot a flow denied even though a preferred WAN path exists; avoid assuming path policy alone grants application access.

Learning point: NETSEC-T06-Q018: Check the matching zone-based security policy because security policy can prune paths that are not allowed; Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization.

 

Question 19

Lucerne Publishing is reviewing its Palo Alto Networks deployment. What should the administrator do to standardize branch security while preserving local exceptions only where justified?

  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules

Correct answer: C

Explanation

  1. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): standardize branch security while preserving local exceptions only where justified.
  2. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): standardize branch security while preserving local exceptions only where justified.
  3. Central policy promotes consistency while site scoping allows controlled variation. This directly satisfies one of the stated requirement(s).
  4. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): standardize branch security while preserving local exceptions only where justified.
  5. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): standardize branch security while preserving local exceptions only where justified.

Learning point: NETSEC-T06-Q019: Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ.

 

Question 20

During a design review for A. Datum Research, the requirement is to verify application experience across multiple circuits. Which choice is most appropriate?

  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric
  • Monitor path health and application flow metrics rather than judging performance only from link-up status
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path

Correct answer: B

Explanation

  1. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify application experience across multiple circuits.
  2. A link can be operational yet unsuitable due to latency, jitter, loss, or transaction performance; telemetry provides the needed detail. This directly satisfies one of the stated requirement(s).
  3. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify application experience across multiple circuits.
  4. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify application experience across multiple circuits.
  5. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): verify application experience across multiple circuits.

Learning point: NETSEC-T06-Q020: Monitor path health and application flow metrics rather than judging performance only from link-up status.

 

Question 21

A change request at Coho Winery states that the team must steer a latency-sensitive application over the path that best meets performance requirements. What is the best response?

  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Monitor path health and application flow metrics rather than judging performance only from link-up status
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path

Correct answer: E

Explanation

  1. Central policy promotes consistency while site scoping allows controlled variation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  2. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  3. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  4. A link can be operational yet unsuitable due to latency, jitter, loss, or transaction performance; telemetry provides the needed detail. This can be valid in another context, but it does not directly satisfy the stated requirement(s): steer a latency-sensitive application over the path that best meets performance requirements.
  5. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T06-Q021: Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path.

 

Question 22

An engineer at Trey Research is troubleshooting a configuration decision. Which action directly addresses the need to enforce branch application access between security zones?

  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path

Correct answer: D

Explanation

  1. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  2. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  3. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.
  4. Prisma SD-WAN security policies control application access within or across zones at branch sites. This directly satisfies one of the stated requirement(s).
  5. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): enforce branch application access between security zones.

Learning point: NETSEC-T06-Q022: Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules.

 

Question 23

Which option best supports the goal to avoid assuming path policy alone grants application access in Wide World Importers’s Palo Alto Networks environment?

  • Define zones and explicit security-policy rules instead of relying on reachability created by the WAN fabric
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Use supported Prisma SD-WAN NAT policy rather than trying to implement translation only in the security rule
  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization

Correct answer: E

Explanation

  1. Connectivity does not imply authorization; zone-based policy should enforce least privilege between branch segments. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  2. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  3. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  4. NAT and security authorization serve different functions and should be configured with the appropriate policy type. This can be valid in another context, but it does not directly satisfy the stated requirement(s): avoid assuming path policy alone grants application access.
  5. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This directly satisfies one of the stated requirement(s).

Learning point: NETSEC-T06-Q023: Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization.

 

Question 24

A security review at Contoso Retail identifies a gap. The team wants to observe why a branch flow selected a particular WAN path. Which action should it take?

  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path
  • Monitor path health and application flow metrics rather than judging performance only from link-up status
  • Use centrally managed policy sets and site bindings, adding local scope deliberately when business requirements differ
  • Check the matching zone-based security policy because security policy can prune paths that are not allowed

Correct answer: A

Explanation

  1. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This directly satisfies one of the stated requirement(s).
  2. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  3. A link can be operational yet unsuitable due to latency, jitter, loss, or transaction performance; telemetry provides the needed detail. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  4. Central policy promotes consistency while site scoping allows controlled variation. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.
  5. Prisma SD-WAN evaluates security policy as part of flow processing, so an available path may still be unusable for a denied flow. This can be valid in another context, but it does not directly satisfy the stated requirement(s): observe why a branch flow selected a particular WAN path.

Learning point: NETSEC-T06-Q024: Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics.

 

Question 25

While validating a deployment for Fabrikam Health, an architect must ensure the design can prefer one path for normal traffic but fail over when quality degrades. What should be done?

  • Evaluate security policy separately because permitted routing or path selection does not replace zone-based firewall authorization
  • Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path
  • Use flow details and monitoring data such as path policy, latency, loss, and jitter metrics
  • Configure Prisma SD-WAN zone-based firewall security policy with explicit allow or deny rules
  • Use Prisma SD-WAN path policy with application and path-quality criteria to select an appropriate WAN path

Correct answer: B

Explanation

  1. Path selection and security enforcement are distinct decisions; a viable path still must be allowed by security policy. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  2. Application-aware path selection is intended to adapt forwarding when path conditions no longer meet the policy goal. This directly satisfies one of the stated requirement(s).
  3. Operational flow telemetry shows both the selected policy and relevant path-quality data used to explain forwarding behavior. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  4. Prisma SD-WAN security policies control application access within or across zones at branch sites. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.
  5. Path policy can make application-aware forwarding choices based on available paths and performance objectives. This can be valid in another context, but it does not directly satisfy the stated requirement(s): prefer one path for normal traffic but fail over when quality degrades.

Learning point: NETSEC-T06-Q025: Configure path policy and performance thresholds or service-level objectives so the application can use a healthier path.

Popular posts

img