Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers

Questions 4

Which component of the Prisma SD-WAN solution is responsible for the deep application identification (App-ID) and the generation of flow metrics (Network Transfer Time, Server Response Time) at the branch?

Options:

A.

 The CloudBlade container

B.

 The Prisma SD-WAN Controller

C.

 The ION Device Data Plane

D.

 The API Gateway

Buy Now
Questions 5

Which statement is valid when integrating Prisma SD-WAN with Prisma Access remote networks?

Options:

A.

Security policies for remote networks are configured in Prisma Access and pushed to Prisma SD-WAN for enforcement on the branch ION devices.

B.

Easy onboarding automatically recommends the closest preconfigured remote network security processing nodes and can be overridden manually.

C.

A branch with multiple internet circuits will automatically connect to Prisma Access on each circuit and will be used in an active/standby manner for internet-bound traffic.

D.

Bandwidth must be allocated to each Prisma Access remote network compute location, and this bandwidth is shared between all branches that terminate on this remote network node.

Buy Now
Questions 6

Site templates are to be used for the large-scale deployment of 100 Prisma SD-WAN branch sites across different regions.

Which two statements align with the capabilities and best practices for Prisma SD-WAN site templates? (Choose two.)

Options:

A.

The use of Jinja conditional statements within a site template is not supported, thereby limiting dynamic customization options.

B.

Mandatory variables for any site template include the site name, ION software version, and at least one ION serial number /device name pair.

C.

Site templates offer the capability to pre-stage device configurations by creating a device shell.

D.

Once a site has been deployed using a template, its configuration can be updated or modified by applying an updated version of the template.

Buy Now
Questions 7

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

Options:

A.

The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.

B.

The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.

C.

The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

D.

The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.

Buy Now
Questions 8

An administrator has configured a Path Policy for "ERP_Traffic". The policy allows two public internet links, "ISP-A" and "ISP-B", both marked as "Active". The Path Quality Profile (SLA) requires a latency of less than 150ms. Currently, both ISP-A and ISP-B have a latency of 40ms, well within the SLA.

How does the Prisma SD-WAN ION determine which link to use for a new flow of "ERP_Traffic" when both active paths meet the SLA requirements?

Options:

A.

It selects the path with the lowest numerical latency (e.g., if ISP-A drops to 39ms).

B.

It selects the path with the highest available bandwidth capacity.

C.

It duplicates the packets across both paths (Packet Duplication) to ensure delivery.

D.

It selects the path that appears first in the interface configuration list.

Buy Now
Questions 9

When defining a Path Quality Profile (SLA) for a "Transactional" application group (e.g., Citrix, Oracle), the administrator sets the "Packet Loss" threshold to 1%.

What happens to the traffic for this application if all active paths currently exceed this 1% loss threshold?

Options:

A.

 The traffic is dropped to prevent data corruption.

B.

 The system selects the best available path (lowest loss) among the active paths, even if it violates the profile.

C.

 The traffic is queued indefinitely until a path recovers.

D.

 The system automatically enables a Backup path, even if the Active paths are technically "Up" but degraded.

Buy Now
Questions 10

Which statements accurately describes how the Prisma SD-WAN zone-based firewall functions within a branch network?

Options:

A.

North-south traffic (internet/WAN egress) is handled by zone-based firewall and relies on external firewalls for east-west segmentation.1

B.

East-west traffic between the zones can be explicitly blocked, but traditional Access Control List (ACLs) are required to block north-south traffic.

C.

North-south traffic is handled by application-aware policies, while east-west traffic requires traditional Access Control List (ACLs).

D.

Security zones enable granular control over both WAN-to-LAN and LAN-to-WAN as well as east-west (LAN-to-LAN) traffic flows within the branch.

Buy Now
Questions 11

A network installer is attempting to claim a new ION device using the "Claim Code" method. The device is connected to the internet, but the status in the portal remains stuck at "Claimed" and does not transition to "Online". The installer connects a laptop to the LAN port of the ION and can successfully browse the internet, confirming the uplink is active.

What is the most likely cause of the device failing to reach the "Online" state?

Options:

A.

 The device is missing the "Site" assignment in the portal.

B.

 The upstream firewall is blocking outbound TCP port 443 or UDP port 123 (NTP).

C.

 The device has not yet downloaded the latest software image.

D.

 The "Circuit Label" has not been applied to the WAN interface.

Buy Now
Questions 12

An engineer at a managed services provider is updating an application that allows its customers to request firewall changes to also manage SD-WAN. The application will be able to make any approved changes directly to devices via API.

What is a requirement for the application to create SD-WAN interfaces?

Options:

A.

REST API’s “sdwanInterfaceprofiles” parameter on a Panorama device

B.

REST API’s “sdwanInterfaces” parameter on a firewall device

C.

XML API’s “sdwanprofiles/interfaces” parameter on a Panorama device

D.

XML API’s “InterfaceProfiles/sdwan” parameter on a firewall device

Buy Now
Questions 13

BGP core peers on data center IONs are learning only a default route from the core router. Which action will protect the SD-WAN network from getting isolated in the event of BGP misconfiguration on the core routers?

Options:

A.

Enable BGP Bidirectional Forwarding Detection (BFD) on the core peer sessions to rapidly detect BGP neighbor failures.

B.

Configure BGP max-prefix limits on the ION devices to prevent them from accepting too many routes from the core routers.

C.

Add a static default route with higher admin distance pointing to the core peer IPs.

D.

Implement BGP route filtering using prefix lists and route maps on the ION devices to only accept specific, known prefixes from the core.1

Buy Now
Questions 14

In a Data Center deployment, what is the key functional difference between configuring a BGP neighbor as a "Core Peer" versus an "Edge Peer"?

Options:

A.

 A Core Peer is used for LAN-side routing to learn DC prefixes, while an Edge Peer is used for WAN-side routing to the Service Provider.

B.

 A Core Peer automatically redistributes learned routes into the SD-WAN fabric, whereas an Edge Peer does not.

C.

 A Core Peer supports eBGP only, while an Edge Peer supports iBGP only.

D.

 A Core Peer is used for connecting to the internet, while an Edge Peer connects to the MPLS provider.

Buy Now
Questions 15

What is the basis for calculating the minimum bandwidth subscription required for branch IONs?

Options:

A.

Maximum throughput supported by the ION hardware deployed at data center locations

B.

Amount of traffic which will traverse the SD-WAN secure fabric

C.

Maximum traffic (ingress and egress) passing through the ION device

D.

ISP circuit capacity at the branch location

Buy Now
Questions 16

Which troubleshooting action should be taken when resources at one branch site can reach the internet but cannot be reached from the data center (DC)?

Options:

A.

Create static route with DC ION as a next hop.

B.

Ensure the LAN branch prefixes are set to “global.”

C.

Set the site in a control mode.

D.

Admin up the Prisma SD-WAN DC endpoints.

Buy Now
Questions 17

An ION 3000 device at a remote branch has suffered a critical hardware failure and must be replaced via the RMA process. The administrator has received the replacement unit.

What is the correct procedure to transfer the configuration and license from the defective unit to the replacement unit to ensure minimal downtime and retention of historical data?

Options:

A.

 Manually configure the new device from scratch, then open a support ticket to transfer the license.

B.

 Use the "Replace Device" workflow in the Prisma SD-WAN portal, which automatically transfers the configuration (Device Shell) and re-associates the site to the new serial number.

C.

 Backup the configuration of the old device to a USB drive and restore it to the new device using the local console.

D.

 Delete the old device from the portal, create a new site for the replacement device, and rebuild the policies manually.

Buy Now
Questions 18

The UI triggers incident DEVICESW_CONCURRENT_FLOWLIMIT_EXCEEDED for a branch site. Based in the image below, which tool can be used to identify the host?

SD-WAN-Engineer Question 18

Options:

A.

Run tcpdump under the LAN interface

B.

Monitor → Activity → Flows

C.

Monitor → Activity → New flows

D.

Monitor → Activity → Transaction Stats

Buy Now
Questions 19

An administrator has configured a Zone-Based Firewall (ZBFW) policy on a branch ION. They created a rule to "Allow" traffic from the "Guest" zone to the "Internet" zone. However, users in the "Guest" zone are reporting they cannot reach a specific public website, and the Flow Browser shows the flow state as "REJECT".

What is the most likely reason for this specific rejection, assuming the "Allow" rule is correctly placed at the top of the list?

Options:

A.

 The implicit default action at the bottom of the security policy is "Deny All".

B.

 The "Allow" rule does not have the specific "Application" defined (it is set to Any), causing a mismatch.

C.

 There is a "Deny" rule in the "Global" policy stack that is taking precedence over the "Local" site rule.

D.

 The ION device does not support firewalling for HTTP traffic.

Buy Now
Questions 20

An organization has provided the following technical requirements and details:

    High availability (HA) at all data center and branch locations

    Two geographically separate main data center locations

    One small data center location that contains local users and applications requiring policies

    50 branch locations

    ISP capacities for all branch locations but no accurate measurement of the actual bandwidth consumption

Based on Palo Alto Networks best practices and recommendations, which two licensing options will meet the customer objectives? (Choose two.)

Options:

A.

Six data center subscriptions

B.

Aggregate bandwidth subscription

C.

Four data center subscriptions

D.

Branch subscription per site

Buy Now
Questions 21

Which configuration requirement must be met to allow two branch ION devices to automatically establish a direct Dynamic VPN (branch-to-branch) connection for traffic flow, bypassing the Data Center?

Options:

A.

Both ION devices must be members of the same VPN Cluster.

B.

A static "Gre Tunnel" must be manually configured between the two sites.

C.

The Data Center ION must be offline to trigger the dynamic failover.

D.

The "Standard VPN" path policy must be selected.

Buy Now
Questions 22

Where is route leaking configured between VRFs?

Options:

A.

VRF definition

B.

BGP peer

C.

Site configuration

D.

VRF profile

Buy Now
Questions 23

What is the number and structure of Prisma SD-WAN QoS queues supported per WAN interface?

Options:

A.

12 queues

4 classes1

3 application criteria within each class

B.

16 queues

4 classes

4 application criteria with each class

C.

8 queues

1 priority queue

7 non-priority queues

D.

8 queues

2 classes

4 application criteria within each class

Buy Now
Questions 24

A site has two internet circuits: Circuit A with 500 Mbps capacity and Circuit B with 100 Mbps capacity.

Which path policy configuration will ensure traffic is automatically shifted from a saturated circuit to the circuit with available bandwidth?

Options:

A.

Circuit A as an active, Circuit B as a backup

B.

Circuit B as an active, Circuit A as a backup

C.

Both circuits under active path

D.

Circuit B as an L3 failure path

Buy Now
Questions 25

Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

SD-WAN-Engineer Question 25

Options:

A.

Both the connection to ISP A and the connection to LTE/5G will be usable.

B.

The VRRP Virtual IP address assigned to any SVIs will be moved to the newly active ION.

C.

The newly active ION will send a gratuitous ARP to the LAN for the IP address of any SVIs.

D.

The connection to ISP A will be usable, but the connection to LTE/5G will not.

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Feb 10, 2026
Questions: 86

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now SD-WAN-Engineer testing engine

PDF (Q&A)

$43.57  $124.49
buy now SD-WAN-Engineer pdf