SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers
A network operator receives a critical SITE_CONNECTIVITY_DOWN alarm for a branch site in the Prisma SD-WAN portal.
What specific condition triggers this alarm type?
When deploying a branch gateway, secure fabric VPN tunnels are automatically established between which two site types? (Choose two.)
A multinational company is deploying Prisma SD-WAN across North America, Europe, and Asia. The data centers in the North America region have served all regions, but regional policies are now being enforced that mandate each of the regions to build their own data centers and branch sites to only connect to their respective regional data centers.
How can this regionalization be achieved so that new or existing branch sites only build tunnels to the regional DC IONs?
What does Prisma SD-WAN use for monitoring and operations to deliver flow data and application visibility?
A network engineer is troubleshooting a user complaint regarding " slow application performance " for an internal web application. While viewing the Flow Browser in the Prisma SD-WAN portal, the engineer notices that the Server Response Time (SRT) is consistently high (over 500ms), while the Network Transfer Time (NTT) and Round Trip Time (RTT) are low (under 50ms).
What does this data indicate about the root cause of the issue?
Which action meets the needs of an organization that requires elevated incident notifications for its headquarters location?
An administrator is configuring a High Availability (HA) pair of ION 3000 devices at a Data Center.
Which statement accurately describes the requirement for the HA Control Interface connection between the two devices?
A network engineer is troubleshooting an ION device that is showing as " Offline " in the Prisma SD-WAN portal, despite the site reporting that local internet access is working. The engineer has console access to the device.
Which CLI command should be used to specifically validate the device ' s ability to resolve the controller ' s hostname and establish a secure connection to it over a specific interface?
When integrating Prisma SD-WAN with Prisma Access, what is the specific role of the Service Connection (SC)?
What are two potential causes when a secondary public circuit has been added to the branch site, but the Prisma SD-WAN tunnel is not forming to the data center? (Choose two.)
A network design mandates segmentation at the routing level and traffic isolation across various services, such as teller cash registers, ATM traffic, guest Wi-Fi, and corporate applications. Which command can be used to validate and display the Virtual Routing and Forwarding (VRF) route leak rules?
When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)
How can a network administrator detect a site outage or a service-level agreement (SLA) violation using controller-generated incidents?
When configuring SASE connectivity with easy onboarding at a branch, which two options must be selected? (Choose two.)
When an ION device has been claimed, the cloud-based controller generates and communicates with the device by which method?
A network installer is attempting to claim a new ION device using the " Claim Code " method. The device is connected to the internet, but the status in the portal remains stuck at " Claimed " and does not transition to " Online " . The installer connects a laptop to the LAN port of the ION and can successfully browse the internet, confirming the uplink is active.
What is the most likely cause of the device failing to reach the " Online " state?
When configuring a Path Policy rule for a " Real-Time Video " application, the administrator wants to ensure the traffic uses the path with the lowest packet loss.
How does the Prisma SD-WAN ION determine the " Packet Loss " metric for a given path when there is no active user traffic flowing on that link?
A network engineer is able to ping and traceroute from SD-WAN branch IP 192.168.1.123 to servers in primary data center – DC1, but is unable to ping or traceroute to a server 10.2.2.22 in the newly configured secondary data center, DC2.
The DC2 ION device is advertising the branch IP subnet 192.168.1.0/24 to the DC2 core via eBGP Core Peer. The DC2 data center site has site prefix 10.2.2.0/23 configured.
Which configuration will resolve the issue in this scenario?
Which statements accurately describes how the Prisma SD-WAN zone-based firewall functions within a branch network?
Which metrics can be monitored at the individual Prisma SD-WAN ION device level to assess its health and operational performance?
There are periodic complaints about the poor performance of a real-time application.

What can be inferred about the performance issue, based on the Network Transfer Time (NTT) and Server Response Time (SRT) image below?
Which condition, when configured within a performance policy, is a trigger for generating an incident related to application performance or path degradation?
