New Year Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers

Questions 4

An administrator has configured a Path Policy for "ERP_Traffic". The policy allows two public internet links, "ISP-A" and "ISP-B", both marked as "Active". The Path Quality Profile (SLA) requires a latency of less than 150ms. Currently, both ISP-A and ISP-B have a latency of 40ms, well within the SLA.

How does the Prisma SD-WAN ION determine which link to use for a new flow of "ERP_Traffic" when both active paths meet the SLA requirements?

Options:

A.

It selects the path with the lowest numerical latency (e.g., if ISP-A drops to 39ms).

B.

It selects the path with the highest available bandwidth capacity.

C.

It duplicates the packets across both paths (Packet Duplication) to ensure delivery.

D.

It selects the path that appears first in the interface configuration list.

Buy Now
Questions 5

In the Prisma SD-WAN portal, the Application Health dashboard assigns a color-coded "Health Score" (Green, Yellow, Red) to applications.

Which three metrics are combined to calculate this composite AppX (Application Experience) score? (Choose three.)

Options:

A.

 Transaction Failure Rate

B.

 Network Transfer Time (NTT)

C.

 Server Response Time (SRT)

D.

 Bandwidth Utilization

E.

 Jitter

Buy Now
Questions 6

In the Prisma SD-WAN portal, an administrator is viewing the "Media" analytics for a branch site to troubleshoot complaints about poor voice quality.

When calculating the Mean Opinion Score (MOS) for voice traffic, which two metrics does the system prioritize active monitoring for, even when no user voice traffic is present on the link? (Choose two.)

Options:

A.

 Latency (One-Way)

B.

 Jitter

C.

 Throughput

D.

 Packet Loss

Buy Now
Questions 7

A network engineer is troubleshooting a "Voice Quality" issue. They suspect that the DSCP markings are being stripped or altered by the ISP.

Which tool in the Prisma SD-WAN portal allows the engineer to capture live packets on the WAN interface and inspect the IP header ToS/DSCP field?

Options:

A.

 Flow Browser

B.

 Packet Capture (PCAP)

C.

 Path Quality Monitor

D.

 Event Logs

Buy Now
Questions 8

A network engineer is troubleshooting a user complaint regarding "slow application performance" for an internal web application. While viewing the Flow Browser in the Prisma SD-WAN portal, the engineer notices that the Server Response Time (SRT) is consistently high (over 500ms), while the Network Transfer Time (NTT) and Round Trip Time (RTT) are low (under 50ms).

What does this data indicate about the root cause of the issue?

Options:

A.

The issue is likely caused by congestion on the WAN circuit, requiring a QoS policy adjustment.

B.

The issue is likely on the application server itself (e.g., high CPU, slow database query), not the network.

C.

The issue is caused by a high packet loss rate on the internet path.

D.

The issue is due to a misconfigured DNS server at the branch.

Buy Now
Questions 9

A customer wants to deploy Prisma SD-WAN ION devices at small home offices that use consumer-grade broadband routers. These routers typically use Symmetric NAT and do not allow static port forwarding.

Which standard mechanism does Prisma SD-WAN utilize to successfully establish direct Branch-to-Branch (Dynamic) VPN tunnels through these Symmetric NAT devices?

Options:

A.

 UPnP (Universal Plug and Play)

B.

 STUN (Session Traversal Utilities for NAT)

C.

 Manual GRE Tunnels

D.

 SSL VPN encapsulation

Buy Now
Questions 10

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.

 Both sites must disable NAT and use public IPs on the ION interface.

C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.

 Dynamic VPNs are not supported if both sides are behind NAT.

Buy Now
Questions 11

In a data center (DC) with two ION devices, all of the remote branch Prisma SD-WAN VPNs are active only on DC ION-1.

Why are no VPNs active on DC ION-2?

Options:

A.

The BGP core peer is down.

B.

The static route to core as a next hop is missing.

C.

The ION device is behind a NAT.

D.

The DC and branches are in a different domain.

Buy Now
Questions 12

In a Prisma SD-WAN deployment, what is the defining characteristic of a "Standard VPN" compared to a "Secure Fabric Link"?

Options:

A.

 Standard VPNs use GRE encapsulation, while Secure Fabric Links use VXLAN.

B.

 Standard VPNs are automatically built between ION devices, while Secure Fabric Links require manual configuration.

C.

 Standard VPNs are manually configured IPSec tunnels to non-ION endpoints, while Secure Fabric Links are automated tunnels between ION devices.

D.

 Standard VPNs support BGP, whereas Secure Fabric Links only support static routing.

Buy Now
Questions 13

An administrator is configuring an ION 2000 device for a deployment where high availability is required, but the site has only a single internet circuit. The administrator configures a Bypass Pair (Fail-to-Wire) on ports 1 and 2 connecting the ISP modem to the legacy firewall.

If the ION device loses power, what is the resulting behavior of the traffic flowing through this Bypass Pair?

Options:

A.

 Traffic is blocked to prevent uninspected packets from entering the network (Fail-to-Block).

B.

 The internal relay closes, physically bridging Port 1 and Port 2, allowing traffic to flow transparently between the modem and firewall.

C.

 The device reboots into "Safe Mode" and acts as a Layer 2 switch.

D.

 Traffic is rerouted to the LTE modem automatically.

Buy Now
Questions 14

Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

SD-WAN-Engineer Question 14

Options:

A.

Both the connection to ISP A and the connection to LTE/5G will be usable.

B.

The VRRP Virtual IP address assigned to any SVIs will be moved to the newly active ION.

C.

The newly active ION will send a gratuitous ARP to the LAN for the IP address of any SVIs.

D.

The connection to ISP A will be usable, but the connection to LTE/5G will not.

Buy Now
Questions 15

A network engineer is troubleshooting an ION device that is showing as "Offline" in the Prisma SD-WAN portal, despite the site reporting that local internet access is working. The engineer has console access to the device.

Which CLI command should be used to specifically validate the device's ability to resolve the controller's hostname and establish a secure connection to it over a specific interface?

Options:

A.

 ping

B.

 debug controller reachability

C.

 show system connectivity

D.

 dump vpn summary

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Dec 13, 2025
Questions: 52

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now SD-WAN-Engineer testing engine

PDF (Q&A)

$43.57  $124.49
buy now SD-WAN-Engineer pdf