Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers

Questions 4

A network operator receives a critical SITE_CONNECTIVITY_DOWN alarm for a branch site in the Prisma SD-WAN portal.

What specific condition triggers this alarm type?

Options:

A.

 The device has lost power and rebooted.

B.

 One of the two internet circuits at the site has gone down.

C.

 All Secure Fabric Links (VPNs) to all remote peers are down, isolating the site from the overlay.

D.

 The site has exceeded its licensed bandwidth capacity.

Buy Now
Questions 5

When deploying a branch gateway, secure fabric VPN tunnels are automatically established between which two site types? (Choose two.)

Options:

A.

Branch to branch gateway (same domain)

B.

Branch gateway to data center

C.

Branch gateway to branch gateway

D.

Branch to branch gateway (different domain)

Buy Now
Questions 6

A multinational company is deploying Prisma SD-WAN across North America, Europe, and Asia. The data centers in the North America region have served all regions, but regional policies are now being enforced that mandate each of the regions to build their own data centers and branch sites to only connect to their respective regional data centers.

How can this regionalization be achieved so that new or existing branch sites only build tunnels to the regional DC IONs?

Options:

A.

Create a new cluster for each regional DC ION and move the sites from the existing cluster to the new cluster.

B.

Disable the auto-tunnel feature globally on the Prisma SD-WAN portal and manually create all necessary tunnels exclusively between IONs within their designated regions.

C.

Remove the circuit labels and apply new circuit labels for in-region circuits only.

D.

Assign WAN interfaces to distinct Virtual Routing and Forwarding (VRF) instances for each region on the DC IONs, ensuring that branches only connect to the WAN interfaces/VRFs designated for their region.

Buy Now
Questions 7

What does Prisma SD-WAN use for monitoring and operations to deliver flow data and application visibility?

Options:

A.

ADEM

B.

IPFIX

C.

SNMPv3

D.

IP SLA

Buy Now
Questions 8

A network engineer is troubleshooting a user complaint regarding " slow application performance " for an internal web application. While viewing the Flow Browser in the Prisma SD-WAN portal, the engineer notices that the Server Response Time (SRT) is consistently high (over 500ms), while the Network Transfer Time (NTT) and Round Trip Time (RTT) are low (under 50ms).

What does this data indicate about the root cause of the issue?

Options:

A.

The issue is likely caused by congestion on the WAN circuit, requiring a QoS policy adjustment.

B.

The issue is likely on the application server itself (e.g., high CPU, slow database query), not the network.

C.

The issue is caused by a high packet loss rate on the internet path.

D.

The issue is due to a misconfigured DNS server at the branch.

Buy Now
Questions 9

Which action meets the needs of an organization that requires elevated incident notifications for its headquarters location?

Options:

A.

Export syslog to an external syslog collector and mark all messages as “Critical.”

B.

Implement performance policy specifically for the site with very aggressive service-level agreement (SLA) thresholds.

C.

Enable an event policy rule for the site with the action to set priority to the highest available level.

D.

Enable SNMPv3 trap notifications to an external network management system.

Buy Now
Questions 10

An administrator is configuring a High Availability (HA) pair of ION 3000 devices at a Data Center.

Which statement accurately describes the requirement for the HA Control Interface connection between the two devices?

Options:

A.

 The HA Control interface must be connected via a Layer 3 routed network to ensure reachability across different subnets.

B.

 The HA Control interface must be a direct physical connection or a Layer 2 adjacent connection on a dedicated VLAN, with no routing between them.

C.

 The HA Control connection is optional if both devices are managed by the same Cloud Controller.

D.

 The HA Control interface uses the management port and must be connected to the internet.

Buy Now
Questions 11

A network engineer is troubleshooting an ION device that is showing as " Offline " in the Prisma SD-WAN portal, despite the site reporting that local internet access is working. The engineer has console access to the device.

Which CLI command should be used to specifically validate the device ' s ability to resolve the controller ' s hostname and establish a secure connection to it over a specific interface?

Options:

A.

 ping < controller-ip >

B.

 debug controller reachability < interface >

C.

 show system connectivity

D.

 dump vpn summary

Buy Now
Questions 12

When integrating Prisma SD-WAN with Prisma Access, what is the specific role of the Service Connection (SC)?

Options:

A.

 It connects the Prisma Access cloud infrastructure back to the customer ' s Headquarters or Data Center for access to internal private resources (e.g., AD, DNS, Intranet).

B.

 It is the IPSec tunnel that connects a Branch site to the Prisma Access gateway for internet access.

C.

 It is the SSL VPN portal used by mobile users to connect to the network.

D.

 It is the peering link between different Prisma Access regions to optimize global traffic.

Buy Now
Questions 13

What are two potential causes when a secondary public circuit has been added to the branch site, but the Prisma SD-WAN tunnel is not forming to the data center? (Choose two.)

Options:

A.

Interface role is not selected as “internet.”

B.

Circuit label is missing from interface type.

C.

DNS is not configured.

D.

Interface scope is set to “local.”

Buy Now
Questions 14

A network design mandates segmentation at the routing level and traffic isolation across various services, such as teller cash registers, ATM traffic, guest Wi-Fi, and corporate applications. Which command can be used to validate and display the Virtual Routing and Forwarding (VRF) route leak rules?

Options:

A.

show interface vrf route_leak_rule all

B.

dump vrf route_leak_rule

C.

inspect flow_browser vrf all

D.

inspect vrf route_leak_rule all

Buy Now
Questions 15

When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:

SD-WAN-Engineer Question 15

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)

Options:

A.

Using Carrier-1 as the WAN path may have experienced some performance degradation.

B.

Using Carrier-2 as the WAN path may have experienced some performance degradation.

C.

Using Carrier-2 as the WAN path may have switched over to Carrier-1.

D.

Using Carrier-1 as the WAN path may have switched over to Carrier-2.

Buy Now
Questions 16

How can a network administrator detect a site outage or a service-level agreement (SLA) violation using controller-generated incidents?

Options:

A.

Incidents, SNMP traps, and audits

B.

Device logs, alerts, and incidents

C.

Incidents, alerts, statistics, and audit logs

D.

Priority alerts, informational alerts, and audit logs

Buy Now
Questions 17

When configuring SASE connectivity with easy onboarding at a branch, which two options must be selected? (Choose two.)

Options:

A.

IPSec Crypto Profile

B.

Prisma Access Primary Location

C.

Prisma Access IKE Profile

D.

IPSec Termination Node

Buy Now
Questions 18

When an ION device has been claimed, the cloud-based controller generates and communicates with the device by which method?

Options:

A.

Manufacturer Installed Certificate (MIC)

B.

Existing customer public key infrastructure (KPI)

C.

Self-signed certificate

D.

Customer Installed Certificate (CIC)

Buy Now
Questions 19

A network installer is attempting to claim a new ION device using the " Claim Code " method. The device is connected to the internet, but the status in the portal remains stuck at " Claimed " and does not transition to " Online " . The installer connects a laptop to the LAN port of the ION and can successfully browse the internet, confirming the uplink is active.

What is the most likely cause of the device failing to reach the " Online " state?

Options:

A.

 The device is missing the " Site " assignment in the portal.

B.

 The upstream firewall is blocking outbound TCP port 443 or UDP port 123 (NTP).

C.

 The device has not yet downloaded the latest software image.

D.

 The " Circuit Label " has not been applied to the WAN interface.

Buy Now
Questions 20

When configuring a Path Policy rule for a " Real-Time Video " application, the administrator wants to ensure the traffic uses the path with the lowest packet loss.

How does the Prisma SD-WAN ION determine the " Packet Loss " metric for a given path when there is no active user traffic flowing on that link?

Options:

A.

 It sends Active Probes (synthetic UDP packets) across the Secure Fabric to measure path quality continuously.

B.

 It relies solely on Passive Monitoring of TCP retransmissions from other user traffic on that link.

C.

 It queries the ISP ' s router via SNMP to retrieve interface error counters.

D.

 It defaults to a static value of 0% loss until user traffic begins.

Buy Now
Questions 21

A network engineer is able to ping and traceroute from SD-WAN branch IP 192.168.1.123 to servers in primary data center – DC1, but is unable to ping or traceroute to a server 10.2.2.22 in the newly configured secondary data center, DC2.

The DC2 ION device is advertising the branch IP subnet 192.168.1.0/24 to the DC2 core via eBGP Core Peer. The DC2 data center site has site prefix 10.2.2.0/23 configured.

Which configuration will resolve the issue in this scenario?

Options:

A.

The default 0.0.0.0/0 static route to the DC2 ION pointing to the DC2 next hop.

B.

Reconfigure eBGP Core Peer to iBGP Core Peer.

C.

Reconfigure eBGP Core Peer as Edge Peer type.

D.

Remove site prefix 10.2.2.0/23 from DC2 site configuration.

Buy Now
Questions 22

Which statements accurately describes how the Prisma SD-WAN zone-based firewall functions within a branch network?

Options:

A.

North-south traffic (internet/WAN egress) is handled by zone-based firewall and relies on external firewalls for east-west segmentation. 1

B.

East-west traffic between the zones can be explicitly blocked, but traditional Access Control List (ACLs) are required to block north-south traffic.

C.

North-south traffic is handled by application-aware policies, while east-west traffic requires traditional Access Control List (ACLs).

D.

Security zones enable granular control over both WAN-to-LAN and LAN-to-WAN as well as east-west (LAN-to-LAN) traffic flows within the branch.

Buy Now
Questions 23

Which metrics can be monitored at the individual Prisma SD-WAN ION device level to assess its health and operational performance?

Options:

A.

Device software version and interface bandwidth

B.

Device CPU, memory and disk use, interface bandwidth, and errors/discards

C.

Device VPN tunnels and controller reachability status

D.

Device application flow statistics, Autonomous Digital Experience Manager (ADEM) metrics, and site health score

Buy Now
Questions 24

There are periodic complaints about the poor performance of a real-time application.

SD-WAN-Engineer Question 24

What can be inferred about the performance issue, based on the Network Transfer Time (NTT) and Server Response Time (SRT) image below?

Options:

A.

The NTT value increases periodically resulting in higher SRT.

B.

The NTT value drops periodically due to network related issues.

C.

The SRT value increases periodically due to Application Server side issues.

D.

The SRT value drops periodically due to Application Server side issues.

Buy Now
Questions 25

Which condition, when configured within a performance policy, is a trigger for generating an incident related to application performance or path degradation?

Options:

A.

Violation of defined service-level agreement (SLA) thresholds for application performance or link quality.

B.

Exceeding the configured threshold for total concurrent flows in the ION device, resulting in a SYSTEM_CONCURRENT_FLOW_THRESHOLD_EXCEEDED incident.

C.

Loss of a BGP peering session on a data center ION device, leading to potential routing instability.

D.

Physical WAN interface transitioning from an “up” to a “down” state, resulting in a NETWORK_ANYNETLINK_DOWN event.

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: May 11, 2026
Questions: 86

PDF + Testing Engine

$64.99  $185.69

Testing Engine

$49.99  $142.83
buy now SD-WAN-Engineer testing engine

PDF (Q&A)

$54.99  $157.11
buy now SD-WAN-Engineer pdf