SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers
While designing a greenfield Prisma SD-WAN solution for a retailer, the risk management group requires segmentation of the retail network to avoid one large fault domain.
The following data points are provided:
Two data centers and all sites need to access applications in both data centers
1000 retail branches with stores concentrated in multiple metropolitan areas
Data Center 1 and Data Center 2 have different sets of applications that are not replicated
Maintaining application availability is the primary goal
Which action will segment the retail network and reduce regional outages?
1000 branches are to be deployed on Prisma SD-WAN with the following constraints:
Devices will be shipped in batches directly to the site
Configuration Management Database (CMDB) has all the necessary details for a site deployment
Field tech will be responsible for rack, stack, and cabling of the IONs at each site
Field tech will need to spend minimum amount of time at each branch site to reduce the cost
The NOC operates in shifts and is responsible for remote cutover support
Which method will achieve the mass deployment in shortest possible time?
When integrating Prisma SD-WAN with Prisma Access, what is the specific role of the Service Connection (SC)?
In the Prisma SD-WAN portal, an administrator is viewing the "Media" analytics for a branch site to troubleshoot complaints about poor voice quality.
When calculating the Mean Opinion Score (MOS) for voice traffic, which two metrics does the system prioritize active monitoring for, even when no user voice traffic is present on the link? (Choose two.)
What is the primary function of the "CloudBlade" platform in a Prisma SD-WAN deployment when integrating with third-party services or Prisma Access?
What is the number and structure of Prisma SD-WAN QoS queues supported per WAN interface?
An administrator has configured a Zone-Based Firewall (ZBFW) policy on a branch ION. They created a rule to "Allow" traffic from the "Guest" zone to the "Internet" zone. However, users in the "Guest" zone are reporting they cannot reach a specific public website, and the Flow Browser shows the flow state as "REJECT".
What is the most likely reason for this specific rejection, assuming the "Allow" rule is correctly placed at the top of the list?
An organization has provided the following technical requirements and details:
High availability (HA) at all data center and branch locations
Two geographically separate main data center locations
One small data center location that contains local users and applications requiring policies
50 branch locations
ISP capacities for all branch locations but no accurate measurement of the actual bandwidth consumption
Based on Palo Alto Networks best practices and recommendations, which two licensing options will meet the customer objectives? (Choose two.)
Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

Site templates are to be used for the large-scale deployment of 100 Prisma SD-WAN branch sites across different regions.
Which two statements align with the capabilities and best practices for Prisma SD-WAN site templates? (Choose two.)
A network engineer is able to ping and traceroute from SD-WAN branch IP 192.168.1.123 to servers in primary data center – DC1, but is unable to ping or traceroute to a server 10.2.2.22 in the newly configured secondary data center, DC2.
The DC2 ION device is advertising the branch IP subnet 192.168.1.0/24 to the DC2 core via eBGP Core Peer. The DC2 data center site has site prefix 10.2.2.0/23 configured.
Which configuration will resolve the issue in this scenario?
There are periodic complaints about the poor performance of a real-time application.

What can be inferred about the performance issue, based on the Network Transfer Time (NTT) and Server Response Time (SRT) image below?
When allocating Aggregate Bandwidth for a Prisma Access "Remote Network" deployment (connecting 50 branch sites), how is the bandwidth license enforced?
An administrator is configuring a High Availability (HA) pair of ION 3000 devices at a Data Center.
Which statement accurately describes the requirement for the HA Control Interface connection between the two devices?
Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

An ION 3000 device at a remote branch has suffered a critical hardware failure and must be replaced via the RMA process. The administrator has received the replacement unit.
What is the correct procedure to transfer the configuration and license from the defective unit to the replacement unit to ensure minimal downtime and retention of historical data?
A network installer is at a remote branch site to deploy a new ION 3000 device. The device has been racked, cabled to the internet, and powered on. The installer has the "Claim Code" displayed on the email sent by the administrator.
When the administrator enters this Claim Code into the Prisma SD-WAN portal, what is the immediate status of the device before the configuration is fully pushed?
A remote branch site is reporting intermittent connectivity to the Data Center. The administrator checks the System > Alarms page and sees a "VPN_DOWN" alarm for the tunnel to the DC. However, the internet circuit status is "Up".
Which specific log file or diagnostic tool in the Prisma SD-WAN portal would provide the IKE (Internet Key Exchange) error codes (e.g., "NO_PROPOSAL_CHOSEN" or "AUTH_FAILED") to pinpoint the cause of the tunnel failure?
A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.
However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.
What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?
Which specialized hardware feature is available on the ION 9000 series but NOT on the ION 3000 series, making it suitable for high-throughput Data Center deployments?
When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)