New Year Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Palo Alto Networks SD-WAN Engineer Question and Answers

Palo Alto Networks SD-WAN Engineer

Last Update Jan 14, 2026
Total Questions : 57

We are offering FREE SD-WAN-Engineer Paloalto Networks exam questions. All you do is to just go and sign up. Give your details, prepare SD-WAN-Engineer free exam questions and then go for complete pool of Palo Alto Networks SD-WAN Engineer test questions that will help you more.

SD-WAN-Engineer pdf

SD-WAN-Engineer PDF

$36.75  $104.99
SD-WAN-Engineer Engine

SD-WAN-Engineer Testing Engine

$43.75  $124.99
SD-WAN-Engineer PDF + Engine

SD-WAN-Engineer PDF + Testing Engine

$57.75  $164.99
Questions 1

A multinational company is deploying Prisma SD-WAN across North America, Europe, and Asia. The data centers in the North America region have served all regions, but regional policies are now being enforced that mandate each of the regions to build their own data centers and branch sites to only connect to their respective regional data centers.

How can this regionalization be achieved so that new or existing branch sites only build tunnels to the regional DC IONs?

Options:

A.  

Create a new cluster for each regional DC ION and move the sites from the existing cluster to the new cluster.

B.  

Disable the auto-tunnel feature globally on the Prisma SD-WAN portal and manually create all necessary tunnels exclusively between IONs within their designated regions.

C.  

Remove the circuit labels and apply new circuit labels for in-region circuits only.

D.  

Assign WAN interfaces to distinct Virtual Routing and Forwarding (VRF) instances for each region on the DC IONs, ensuring that branches only connect to the WAN interfaces/VRFs designated for their region.

Discussion 0
Questions 2

Which configuration requirement must be met to allow two branch ION devices to automatically establish a direct Dynamic VPN (branch-to-branch) connection for traffic flow, bypassing the Data Center?

Options:

A.  

Both ION devices must be members of the same VPN Cluster.

B.  

A static "Gre Tunnel" must be manually configured between the two sites.

C.  

The Data Center ION must be offline to trigger the dynamic failover.

D.  

The "Standard VPN" path policy must be selected.

Discussion 0
Questions 3

During the Zero Touch Provisioning (ZTP) process of a new ION device at a branch site, which interface ports are supported by default to request an IP address via DHCP and reach the Prisma SD-WAN controller for claiming?

Options:

A.  

 Only the dedicated Controller port (if available)

B.  

 Any LAN or WAN port on the device

C.  

 The dedicated Controller port, or Port 1 / Internet 1 if a dedicated port is absent

D.  

 Only the USB port via a cellular modem

Discussion 0
Questions 4

When allocating Aggregate Bandwidth for a Prisma Access "Remote Network" deployment (connecting 50 branch sites), how is the bandwidth license enforced?

Options:

A.  

 Each branch site is hard-capped at the specific bandwidth limit defined in its individual IPSec tunnel configuration.

B.  

 The bandwidth is shared as a pool across all sites in a specific Compute Location (Region); individual sites can burst up to the available pool capacity.

C.  

 The bandwidth is allocated per device serial number and cannot be shared.

D.  

 The bandwidth license is only checked once during the initial onboarding; there is no ongoing enforcement.

Discussion 0
Questions 5

In a Data Center deployment, what is the key functional difference between configuring a BGP neighbor as a "Core Peer" versus an "Edge Peer"?

Options:

A.  

 A Core Peer is used for LAN-side routing to learn DC prefixes, while an Edge Peer is used for WAN-side routing to the Service Provider.

B.  

 A Core Peer automatically redistributes learned routes into the SD-WAN fabric, whereas an Edge Peer does not.

C.  

 A Core Peer supports eBGP only, while an Edge Peer supports iBGP only.

D.  

 A Core Peer is used for connecting to the internet, while an Edge Peer connects to the MPLS provider.

Discussion 0
Questions 6

In the Prisma SD-WAN portal, the Application Health dashboard assigns a color-coded "Health Score" (Green, Yellow, Red) to applications.

Which three metrics are combined to calculate this composite AppX (Application Experience) score? (Choose three.)

Options:

A.  

 Transaction Failure Rate

B.  

 Network Transfer Time (NTT)

C.  

 Server Response Time (SRT)

D.  

 Bandwidth Utilization

E.  

 Jitter

Discussion 0
Questions 7

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.  

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.  

 Both sites must disable NAT and use public IPs on the ION interface.

C.  

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.  

 Dynamic VPNs are not supported if both sides are behind NAT.

Discussion 0
Questions 8

A remote branch site is reporting intermittent connectivity to the Data Center. The administrator checks the System > Alarms page and sees a "VPN_DOWN" alarm for the tunnel to the DC. However, the internet circuit status is "Up".

Which specific log file or diagnostic tool in the Prisma SD-WAN portal would provide the IKE (Internet Key Exchange) error codes (e.g., "NO_PROPOSAL_CHOSEN" or "AUTH_FAILED") to pinpoint the cause of the tunnel failure?

Options:

A.  

 Flow Browser

B.  

 Event Logs > System

C.  

 Site Summary > Topology

D.  

 Link Quality Graphs

Discussion 0
Questions 9

A network engineer is troubleshooting an ION device that is showing as "Offline" in the Prisma SD-WAN portal, despite the site reporting that local internet access is working. The engineer has console access to the device.

Which CLI command should be used to specifically validate the device's ability to resolve the controller's hostname and establish a secure connection to it over a specific interface?

Options:

A.  

 ping

B.  

 debug controller reachability

C.  

 show system connectivity

D.  

 dump vpn summary

Discussion 0
Questions 10

A network engineer is troubleshooting a user complaint regarding "slow application performance" for an internal web application. While viewing the Flow Browser in the Prisma SD-WAN portal, the engineer notices that the Server Response Time (SRT) is consistently high (over 500ms), while the Network Transfer Time (NTT) and Round Trip Time (RTT) are low (under 50ms).

What does this data indicate about the root cause of the issue?

Options:

A.  

The issue is likely caused by congestion on the WAN circuit, requiring a QoS policy adjustment.

B.  

The issue is likely on the application server itself (e.g., high CPU, slow database query), not the network.

C.  

The issue is caused by a high packet loss rate on the internet path.

D.  

The issue is due to a misconfigured DNS server at the branch.

Discussion 0
Questions 11

A network installer is at a remote branch site to deploy a new ION 3000 device. The device has been racked, cabled to the internet, and powered on. The installer has the "Claim Code" displayed on the email sent by the administrator.

When the administrator enters this Claim Code into the Prisma SD-WAN portal, what is the immediate status of the device before the configuration is fully pushed?

Options:

A.  

Online

B.  

Claimed

C.  

Provisioned

D.  

Active

Discussion 0
Questions 12

Which specialized hardware feature is available on the ION 9000 series but NOT on the ION 3000 series, making it suitable for high-throughput Data Center deployments?

Options:

A.  

 Support for LTE/5G SIM cards

B.  

 Fail-to-Wire Bypass Pairs

C.  

 10 Gigabit Ethernet (SFP+) ports

D.  

 PoE+ (Power over Ethernet) output ports

Discussion 0
Questions 13

What is the default action for real-time media applications if link performance is poor?

Options:

A.  

Drop the flow.

B.  

Move flows.

C.  

Apply Forward Error Correction (FEC).1

D.  

Raise an alarm.

Discussion 0
Questions 14

A network administrator is viewing the Flow Browser to investigate a report that a specific user cannot access an internal web server. The flow entry for this traffic shows the "Flow State" as "INIT" and it remains in that state until it times out.

What does the "INIT" state indicate about the traffic flow?

Options:

A.  

 The TCP 3-way handshake was completed successfully, and data is being transferred.

B.  

 The ION device received the SYN packet from the client but never saw a SYN-ACK response from the server.

C.  

 The flow was denied by a Zone-Based Firewall policy on the ION.

D.  

 The traffic is being buffered while the ION waits for a dynamic VPN tunnel to establish.

Discussion 0
Questions 15

What is the primary function of the "CloudBlade" platform in a Prisma SD-WAN deployment when integrating with third-party services or Prisma Access?

Options:

A.  

It acts as a physical line card on the ION device to provide additional 10Gbps interfaces.

B.  

It is a containerized application running on the ION device that performs Deep Packet Inspection (DPI).

C.  

It is a cloud-based API integration layer that automates the configuration of the ION devices and the remote service.

D.  

It is a monitoring dashboard used exclusively for viewing flow records.

Discussion 0
Questions 16

A network engineer is troubleshooting a "Voice Quality" issue. They suspect that the DSCP markings are being stripped or altered by the ISP.

Which tool in the Prisma SD-WAN portal allows the engineer to capture live packets on the WAN interface and inspect the IP header ToS/DSCP field?

Options:

A.  

 Flow Browser

B.  

 Packet Capture (PCAP)

C.  

 Path Quality Monitor

D.  

 Event Logs

Discussion 0
Questions 17

When identifying devices for IoT classification purposes, which two methods does Prisma SD-WAN use to discover devices that are not directly connected to the branch ION? (Choose two.)

Options:

A.  

LLDP

B.  

CDP

C.  

SNMP

D.  

Syslog

Discussion 0