New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers

Questions 4

What is the primary function of the "CloudBlade" platform in a Prisma SD-WAN deployment when integrating with third-party services or Prisma Access?

Options:

A.

It acts as a physical line card on the ION device to provide additional 10Gbps interfaces.

B.

It is a containerized application running on the ION device that performs Deep Packet Inspection (DPI).

C.

It is a cloud-based API integration layer that automates the configuration of the ION devices and the remote service.

D.

It is a monitoring dashboard used exclusively for viewing flow records.

Buy Now
Questions 5

What are two potential causes when a secondary public circuit has been added to the branch site, but the Prisma SD-WAN tunnel is not forming to the data center? (Choose two.)

Options:

A.

Interface role is not selected as “internet.”

B.

Circuit label is missing from interface type.

C.

DNS is not configured.

D.

Interface scope is set to “local.”

Buy Now
Questions 6

An administrator is configuring a High Availability (HA) pair of ION 3000 devices at a Data Center.

Which statement accurately describes the requirement for the HA Control Interface connection between the two devices?

Options:

A.

 The HA Control interface must be connected via a Layer 3 routed network to ensure reachability across different subnets.

B.

 The HA Control interface must be a direct physical connection or a Layer 2 adjacent connection on a dedicated VLAN, with no routing between them.

C.

 The HA Control connection is optional if both devices are managed by the same Cloud Controller.

D.

 The HA Control interface uses the management port and must be connected to the internet.

Buy Now
Questions 7

Site templates are to be used for the large-scale deployment of 100 Prisma SD-WAN branch sites across different regions.

Which two statements align with the capabilities and best practices for Prisma SD-WAN site templates? (Choose two.)

Options:

A.

The use of Jinja conditional statements within a site template is not supported, thereby limiting dynamic customization options.

B.

Mandatory variables for any site template include the site name, ION software version, and at least one ION serial number /device name pair.

C.

Site templates offer the capability to pre-stage device configurations by creating a device shell.

D.

Once a site has been deployed using a template, its configuration can be updated or modified by applying an updated version of the template.

Buy Now
Questions 8

A network engineer is able to ping and traceroute from SD-WAN branch IP 192.168.1.123 to servers in primary data center – DC1, but is unable to ping or traceroute to a server 10.2.2.22 in the newly configured secondary data center, DC2.

The DC2 ION device is advertising the branch IP subnet 192.168.1.0/24 to the DC2 core via eBGP Core Peer. The DC2 data center site has site prefix 10.2.2.0/23 configured.

Which configuration will resolve the issue in this scenario?

Options:

A.

The default 0.0.0.0/0 static route to the DC2 ION pointing to the DC2 next hop.

B.

Reconfigure eBGP Core Peer to iBGP Core Peer.

C.

Reconfigure eBGP Core Peer as Edge Peer type.

D.

Remove site prefix 10.2.2.0/23 from DC2 site configuration.

Buy Now
Questions 9

A network administrator notices that a branch ION device is experiencing high CPU utilization due to a suspected TCP SYN Flood attack originating from a compromised host on the local LAN.

Which specific security feature should be configured and applied to the "LAN" zone to mitigate this Denial of Service (DoS) attack?

Options:

A.

 Zone-Based Firewall (ZBFW) Rule with a "Deny" action

B.

 Zone Protection Profile

C.

 Application Quality Profile (AQP)

D.

 Access Control List (ACL) on the WAN interface

Buy Now
Questions 10

Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

SD-WAN-Engineer Question 10

Options:

A.

Both the connection to ISP A and the connection to LTE/5G will be usable.

B.

The VRRP Virtual IP address assigned to any SVIs will be moved to the newly active ION.

C.

The newly active ION will send a gratuitous ARP to the LAN for the IP address of any SVIs.

D.

The connection to ISP A will be usable, but the connection to LTE/5G will not.

Buy Now
Questions 11

Which statement is valid when integrating Prisma SD-WAN with Prisma Access remote networks?

Options:

A.

Security policies for remote networks are configured in Prisma Access and pushed to Prisma SD-WAN for enforcement on the branch ION devices.

B.

Easy onboarding automatically recommends the closest preconfigured remote network security processing nodes and can be overridden manually.

C.

A branch with multiple internet circuits will automatically connect to Prisma Access on each circuit and will be used in an active/standby manner for internet-bound traffic.

D.

Bandwidth must be allocated to each Prisma Access remote network compute location, and this bandwidth is shared between all branches that terminate on this remote network node.

Buy Now
Questions 12

A network installer is at a remote branch site to deploy a new ION 3000 device. The device has been racked, cabled to the internet, and powered on. The installer has the "Claim Code" displayed on the email sent by the administrator.

When the administrator enters this Claim Code into the Prisma SD-WAN portal, what is the immediate status of the device before the configuration is fully pushed?

Options:

A.

Online

B.

Claimed

C.

Provisioned

D.

Active

Buy Now
Questions 13

An administrator is configuring a BGP peer on a Data Center ION to learn routes from the core switch. The goal is to have the ION learn these prefixes and then advertise them to all remote branch sites across the SD-WAN overlay.

Which setting must be configured on the BGP Peer to ensure these learned routes are redistributed into the SD-WAN fabric?

Options:

A.

 Set the "Admin Distance" to 20.

B.

 Enable "Graceful Restart".

C.

 Set the "Scope" to "Global".

D.

 Configure a "Prefix List" to deny all.

Buy Now
Questions 14

What is the number and structure of Prisma SD-WAN QoS queues supported per WAN interface?

Options:

A.

12 queues

4 classes1

3 application criteria within each class

B.

16 queues

4 classes

4 application criteria with each class

C.

8 queues

1 priority queue

7 non-priority queues

D.

8 queues

2 classes

4 application criteria within each class

Buy Now
Questions 15

A network administrator is viewing the Flow Browser to investigate a report that a specific user cannot access an internal web server. The flow entry for this traffic shows the "Flow State" as "INIT" and it remains in that state until it times out.

What does the "INIT" state indicate about the traffic flow?

Options:

A.

 The TCP 3-way handshake was completed successfully, and data is being transferred.

B.

 The ION device received the SYN packet from the client but never saw a SYN-ACK response from the server.

C.

 The flow was denied by a Zone-Based Firewall policy on the ION.

D.

 The traffic is being buffered while the ION waits for a dynamic VPN tunnel to establish.

Buy Now
Questions 16

When allocating Aggregate Bandwidth for a Prisma Access "Remote Network" deployment (connecting 50 branch sites), how is the bandwidth license enforced?

Options:

A.

 Each branch site is hard-capped at the specific bandwidth limit defined in its individual IPSec tunnel configuration.

B.

 The bandwidth is shared as a pool across all sites in a specific Compute Location (Region); individual sites can burst up to the available pool capacity.

C.

 The bandwidth is allocated per device serial number and cannot be shared.

D.

 The bandwidth license is only checked once during the initial onboarding; there is no ongoing enforcement.

Buy Now
Questions 17

A network installer is attempting to claim a new ION device using the "Claim Code" method. The device is connected to the internet, but the status in the portal remains stuck at "Claimed" and does not transition to "Online". The installer connects a laptop to the LAN port of the ION and can successfully browse the internet, confirming the uplink is active.

What is the most likely cause of the device failing to reach the "Online" state?

Options:

A.

 The device is missing the "Site" assignment in the portal.

B.

 The upstream firewall is blocking outbound TCP port 443 or UDP port 123 (NTP).

C.

 The device has not yet downloaded the latest software image.

D.

 The "Circuit Label" has not been applied to the WAN interface.

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Jan 8, 2026
Questions: 57

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99