Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers

Questions 4

While designing a greenfield Prisma SD-WAN solution for a retailer, the risk management group requires segmentation of the retail network to avoid one large fault domain.

The following data points are provided:

    Two data centers and all sites need to access applications in both data centers

    1000 retail branches with stores concentrated in multiple metropolitan areas

    Data Center 1 and Data Center 2 have different sets of applications that are not replicated

    Maintaining application availability is the primary goal

Which action will segment the retail network and reduce regional outages?

Options:

A.

Implement a single, large data center cluster spanning both data centers to centralize management and optimize resource use.

B.

Create more than one data center cluster for a larger pool of resources and resiliency.

C.

Create more than one data center cluster in each data center and assign sites to clusters so nearby retail locations can be spread on separate clusters.

D.

Add more data center aggregation devices within the same cluster to enhance the scalability and resilience.

Buy Now
Questions 5

1000 branches are to be deployed on Prisma SD-WAN with the following constraints:

    Devices will be shipped in batches directly to the site

    Configuration Management Database (CMDB) has all the necessary details for a site deployment

    Field tech will be responsible for rack, stack, and cabling of the IONs at each site

    Field tech will need to spend minimum amount of time at each branch site to reduce the cost

    The NOC operates in shifts and is responsible for remote cutover support

Which method will achieve the mass deployment in shortest possible time?

Options:

A.

Connect the ION to the LAN switch to bring it online, configure the device using the legacy network, connect the ISP modem or cellular, and cutover the site once the ION is configured.

B.

Connect the device to the ISP modem or use cellular, use device shell to pre-create the configuration for a site, assign the device to the template when device is online, and connect the LAN switch to the ION.

C.

Use site templates and device shells to pre-create the configuration using CSV bulk upload, connect the device to the ISP modem or using cellular, assign the device to the template when device is online, and connect the LAN switch to the ION.

D.

Connect the device to the ISP modem or use cellular, use Prisma SD-WAN Software Development Kit (SDK) using API method for site deployment once the device is online, connect the LAN switch to the ION.

Buy Now
Questions 6

When integrating Prisma SD-WAN with Prisma Access, what is the specific role of the Service Connection (SC)?

Options:

A.

 It connects the Prisma Access cloud infrastructure back to the customer's Headquarters or Data Center for access to internal private resources (e.g., AD, DNS, Intranet).

B.

 It is the IPSec tunnel that connects a Branch site to the Prisma Access gateway for internet access.

C.

 It is the SSL VPN portal used by mobile users to connect to the network.

D.

 It is the peering link between different Prisma Access regions to optimize global traffic.

Buy Now
Questions 7

In the Prisma SD-WAN portal, an administrator is viewing the "Media" analytics for a branch site to troubleshoot complaints about poor voice quality.

When calculating the Mean Opinion Score (MOS) for voice traffic, which two metrics does the system prioritize active monitoring for, even when no user voice traffic is present on the link? (Choose two.)

Options:

A.

 Latency (One-Way)

B.

 Jitter

C.

 Throughput

D.

 Packet Loss

Buy Now
Questions 8

What is the primary function of the "CloudBlade" platform in a Prisma SD-WAN deployment when integrating with third-party services or Prisma Access?

Options:

A.

It acts as a physical line card on the ION device to provide additional 10Gbps interfaces.

B.

It is a containerized application running on the ION device that performs Deep Packet Inspection (DPI).

C.

It is a cloud-based API integration layer that automates the configuration of the ION devices and the remote service.

D.

It is a monitoring dashboard used exclusively for viewing flow records.

Buy Now
Questions 9

What is the number and structure of Prisma SD-WAN QoS queues supported per WAN interface?

Options:

A.

12 queues

4 classes1

3 application criteria within each class

B.

16 queues

4 classes

4 application criteria with each class

C.

8 queues

1 priority queue

7 non-priority queues

D.

8 queues

2 classes

4 application criteria within each class

Buy Now
Questions 10

An administrator has configured a Zone-Based Firewall (ZBFW) policy on a branch ION. They created a rule to "Allow" traffic from the "Guest" zone to the "Internet" zone. However, users in the "Guest" zone are reporting they cannot reach a specific public website, and the Flow Browser shows the flow state as "REJECT".

What is the most likely reason for this specific rejection, assuming the "Allow" rule is correctly placed at the top of the list?

Options:

A.

 The implicit default action at the bottom of the security policy is "Deny All".

B.

 The "Allow" rule does not have the specific "Application" defined (it is set to Any), causing a mismatch.

C.

 There is a "Deny" rule in the "Global" policy stack that is taking precedence over the "Local" site rule.

D.

 The ION device does not support firewalling for HTTP traffic.

Buy Now
Questions 11

An organization has provided the following technical requirements and details:

    High availability (HA) at all data center and branch locations

    Two geographically separate main data center locations

    One small data center location that contains local users and applications requiring policies

    50 branch locations

    ISP capacities for all branch locations but no accurate measurement of the actual bandwidth consumption

Based on Palo Alto Networks best practices and recommendations, which two licensing options will meet the customer objectives? (Choose two.)

Options:

A.

Six data center subscriptions

B.

Aggregate bandwidth subscription

C.

Four data center subscriptions

D.

Branch subscription per site

Buy Now
Questions 12

Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

SD-WAN-Engineer Question 12

Options:

A.

Both the connection to ISP A and the connection to LTE/5G will be usable.

B.

The VRRP Virtual IP address assigned to any SVIs will be moved to the newly active ION.

C.

The newly active ION will send a gratuitous ARP to the LAN for the IP address of any SVIs.

D.

The connection to ISP A will be usable, but the connection to LTE/5G will not.

Buy Now
Questions 13

Site templates are to be used for the large-scale deployment of 100 Prisma SD-WAN branch sites across different regions.

Which two statements align with the capabilities and best practices for Prisma SD-WAN site templates? (Choose two.)

Options:

A.

The use of Jinja conditional statements within a site template is not supported, thereby limiting dynamic customization options.

B.

Mandatory variables for any site template include the site name, ION software version, and at least one ION serial number /device name pair.

C.

Site templates offer the capability to pre-stage device configurations by creating a device shell.

D.

Once a site has been deployed using a template, its configuration can be updated or modified by applying an updated version of the template.

Buy Now
Questions 14

A network engineer is able to ping and traceroute from SD-WAN branch IP 192.168.1.123 to servers in primary data center – DC1, but is unable to ping or traceroute to a server 10.2.2.22 in the newly configured secondary data center, DC2.

The DC2 ION device is advertising the branch IP subnet 192.168.1.0/24 to the DC2 core via eBGP Core Peer. The DC2 data center site has site prefix 10.2.2.0/23 configured.

Which configuration will resolve the issue in this scenario?

Options:

A.

The default 0.0.0.0/0 static route to the DC2 ION pointing to the DC2 next hop.

B.

Reconfigure eBGP Core Peer to iBGP Core Peer.

C.

Reconfigure eBGP Core Peer as Edge Peer type.

D.

Remove site prefix 10.2.2.0/23 from DC2 site configuration.

Buy Now
Questions 15

Where is route leaking configured between VRFs?

Options:

A.

VRF definition

B.

BGP peer

C.

Site configuration

D.

VRF profile

Buy Now
Questions 16

There are periodic complaints about the poor performance of a real-time application.

SD-WAN-Engineer Question 16

What can be inferred about the performance issue, based on the Network Transfer Time (NTT) and Server Response Time (SRT) image below?

Options:

A.

The NTT value increases periodically resulting in higher SRT.

B.

The NTT value drops periodically due to network related issues.

C.

The SRT value increases periodically due to Application Server side issues.

D.

The SRT value drops periodically due to Application Server side issues.

Buy Now
Questions 17

When allocating Aggregate Bandwidth for a Prisma Access "Remote Network" deployment (connecting 50 branch sites), how is the bandwidth license enforced?

Options:

A.

 Each branch site is hard-capped at the specific bandwidth limit defined in its individual IPSec tunnel configuration.

B.

 The bandwidth is shared as a pool across all sites in a specific Compute Location (Region); individual sites can burst up to the available pool capacity.

C.

 The bandwidth is allocated per device serial number and cannot be shared.

D.

 The bandwidth license is only checked once during the initial onboarding; there is no ongoing enforcement.

Buy Now
Questions 18

An administrator is configuring a High Availability (HA) pair of ION 3000 devices at a Data Center.

Which statement accurately describes the requirement for the HA Control Interface connection between the two devices?

Options:

A.

 The HA Control interface must be connected via a Layer 3 routed network to ensure reachability across different subnets.

B.

 The HA Control interface must be a direct physical connection or a Layer 2 adjacent connection on a dedicated VLAN, with no routing between them.

C.

 The HA Control connection is optional if both devices are managed by the same Cloud Controller.

D.

 The HA Control interface uses the management port and must be connected to the internet.

Buy Now
Questions 19

Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

SD-WAN-Engineer Question 19

Options:

A.

Both the connection to ISP A and the connection to LTE/5G will be usable.

B.

The VRRP Virtual IP address assigned to any SVIs will be moved to the newly active ION.

C.

The newly active ION will send a gratuitous ARP to the LAN for the IP address of any SVIs.

D.

The connection to ISP A will be usable, but the connection to LTE/5G will not.

Buy Now
Questions 20

An ION 3000 device at a remote branch has suffered a critical hardware failure and must be replaced via the RMA process. The administrator has received the replacement unit.

What is the correct procedure to transfer the configuration and license from the defective unit to the replacement unit to ensure minimal downtime and retention of historical data?

Options:

A.

 Manually configure the new device from scratch, then open a support ticket to transfer the license.

B.

 Use the "Replace Device" workflow in the Prisma SD-WAN portal, which automatically transfers the configuration (Device Shell) and re-associates the site to the new serial number.

C.

 Backup the configuration of the old device to a USB drive and restore it to the new device using the local console.

D.

 Delete the old device from the portal, create a new site for the replacement device, and rebuild the policies manually.

Buy Now
Questions 21

A network installer is at a remote branch site to deploy a new ION 3000 device. The device has been racked, cabled to the internet, and powered on. The installer has the "Claim Code" displayed on the email sent by the administrator.

When the administrator enters this Claim Code into the Prisma SD-WAN portal, what is the immediate status of the device before the configuration is fully pushed?

Options:

A.

Online

B.

Claimed

C.

Provisioned

D.

Active

Buy Now
Questions 22

A remote branch site is reporting intermittent connectivity to the Data Center. The administrator checks the System > Alarms page and sees a "VPN_DOWN" alarm for the tunnel to the DC. However, the internet circuit status is "Up".

Which specific log file or diagnostic tool in the Prisma SD-WAN portal would provide the IKE (Internet Key Exchange) error codes (e.g., "NO_PROPOSAL_CHOSEN" or "AUTH_FAILED") to pinpoint the cause of the tunnel failure?

Options:

A.

 Flow Browser

B.

 Event Logs > System

C.

 Site Summary > Topology

D.

 Link Quality Graphs

Buy Now
Questions 23

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

Options:

A.

The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.

B.

The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.

C.

The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

D.

The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.

Buy Now
Questions 24

Which specialized hardware feature is available on the ION 9000 series but NOT on the ION 3000 series, making it suitable for high-throughput Data Center deployments?

Options:

A.

 Support for LTE/5G SIM cards

B.

 Fail-to-Wire Bypass Pairs

C.

 10 Gigabit Ethernet (SFP+) ports

D.

 PoE+ (Power over Ethernet) output ports

Buy Now
Questions 25

When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:

SD-WAN-Engineer Question 25

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)

Options:

A.

Using Carrier-1 as the WAN path may have experienced some performance degradation.

B.

Using Carrier-2 as the WAN path may have experienced some performance degradation.

C.

Using Carrier-2 as the WAN path may have switched over to Carrier-1.

D.

Using Carrier-1 as the WAN path may have switched over to Carrier-2.

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Feb 25, 2026
Questions: 86

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99