Spring Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers

Questions 4

Which troubleshooting action should be taken when resources at one branch site can reach the internet but cannot be reached from the data center (DC)?

Options:

A.

Create static route with DC ION as a next hop.

B.

Ensure the LAN branch prefixes are set to “global.”

C.

Set the site in a control mode.

D.

Admin up the Prisma SD-WAN DC endpoints.

Buy Now
Questions 5

When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:

SD-WAN-Engineer Question 5

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)

Options:

A.

Using Carrier-1 as the WAN path may have experienced some performance degradation.

B.

Using Carrier-2 as the WAN path may have experienced some performance degradation.

C.

Using Carrier-2 as the WAN path may have switched over to Carrier-1.

D.

Using Carrier-1 as the WAN path may have switched over to Carrier-2.

Buy Now
Questions 6

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

Options:

A.

The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.

B.

The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.

C.

The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

D.

The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.

Buy Now
Questions 7

When defining a Path Quality Profile (SLA) for a "Transactional" application group (e.g., Citrix, Oracle), the administrator sets the "Packet Loss" threshold to 1%.

What happens to the traffic for this application if all active paths currently exceed this 1% loss threshold?

Options:

A.

 The traffic is dropped to prevent data corruption.

B.

 The system selects the best available path (lowest loss) among the active paths, even if it violates the profile.

C.

 The traffic is queued indefinitely until a path recovers.

D.

 The system automatically enables a Backup path, even if the Active paths are technically "Up" but degraded.

Buy Now
Questions 8

Which IONs can support Branch Gateway?

Options:

A.

3102V, 3200, 1200S, 5200

B.

1200, 3200, 9200, 7108V1

C.

3104V, 1200S, 5200, 7108V

D.

9200, 3200, 5200, 7116V

Buy Now
Questions 9

Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

SD-WAN-Engineer Question 9

Options:

A.

Both the connection to ISP A and the connection to LTE/5G will be usable.

B.

The VRRP Virtual IP address assigned to any SVIs will be moved to the newly active ION.

C.

The newly active ION will send a gratuitous ARP to the LAN for the IP address of any SVIs.

D.

The connection to ISP A will be usable, but the connection to LTE/5G will not.

Buy Now
Questions 10

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.

 Both sites must disable NAT and use public IPs on the ION interface.

C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.

 Dynamic VPNs are not supported if both sides are behind NAT.

Buy Now
Questions 11

Which component of Prisma SD-WAN is responsible for distributing User-IP and user-group mappings to branch devices that match the corresponding source IPs?

Options:

A.

DC ION

B.

Cloud Identity Engine

C.

Controller

D.

NGFW

Buy Now
Questions 12

In the Prisma SD-WAN portal, an administrator is viewing the "Media" analytics for a branch site to troubleshoot complaints about poor voice quality.

When calculating the Mean Opinion Score (MOS) for voice traffic, which two metrics does the system prioritize active monitoring for, even when no user voice traffic is present on the link? (Choose two.)

Options:

A.

 Latency (One-Way)

B.

 Jitter

C.

 Throughput

D.

 Packet Loss

Buy Now
Questions 13

In the Prisma SD-WAN portal, the Application Health dashboard assigns a color-coded "Health Score" (Green, Yellow, Red) to applications.

Which three metrics are combined to calculate this composite AppX (Application Experience) score? (Choose three.)

Options:

A.

 Transaction Failure Rate

B.

 Network Transfer Time (NTT)

C.

 Server Response Time (SRT)

D.

 Bandwidth Utilization

E.

 Jitter

Buy Now
Questions 14

An administrator needs to generate a monthly report showing the "Top Applications" by bandwidth usage across all branch sites to justify a bandwidth upgrade.

Which specific component of the Prisma SD-WAN interface is designed to create, schedule, and email these PDF summaries?

Options:

A.

 Activity Charts

B.

 Media Analytics

C.

 Reports

D.

 Flow Browser

Buy Now
Questions 15

A network engineer is able to ping and traceroute from SD-WAN branch IP 192.168.1.123 to servers in primary data center – DC1, but is unable to ping or traceroute to a server 10.2.2.22 in the newly configured secondary data center, DC2.

The DC2 ION device is advertising the branch IP subnet 192.168.1.0/24 to the DC2 core via eBGP Core Peer. The DC2 data center site has site prefix 10.2.2.0/23 configured.

Which configuration will resolve the issue in this scenario?

Options:

A.

The default 0.0.0.0/0 static route to the DC2 ION pointing to the DC2 next hop.

B.

Reconfigure eBGP Core Peer to iBGP Core Peer.

C.

Reconfigure eBGP Core Peer as Edge Peer type.

D.

Remove site prefix 10.2.2.0/23 from DC2 site configuration.

Buy Now
Questions 16

An organization has provided the following technical requirements and details:

    High availability (HA) at all data center and branch locations

    Two geographically separate main data center locations

    One small data center location that contains local users and applications requiring policies

    50 branch locations

    ISP capacities for all branch locations but no accurate measurement of the actual bandwidth consumption

Based on Palo Alto Networks best practices and recommendations, which two licensing options will meet the customer objectives? (Choose two.)

Options:

A.

Six data center subscriptions

B.

Aggregate bandwidth subscription

C.

Four data center subscriptions

D.

Branch subscription per site

Buy Now
Questions 17

Where is route leaking configured between VRFs?

Options:

A.

VRF definition

B.

BGP peer

C.

Site configuration

D.

VRF profile

Buy Now
Questions 18

Return traffic for an application from the branch is being dropped on the branch ION. Application traffic arrives via SD-WAN internet overlay at the branch, and path policy for the application at the branch has the following settings:

Active = MPLS Overlay

Backup = Prisma Access on internet

Which branch configuration is the probable cause of this behavior?

Options:

A.

It has Prisma Access tunnel over MPLS circuit but not on the internet circuit.

B.

It has one MPLS and one internet circuit.

C.

It has two internet circuits and no MPLS circuit.

D.

It has no MPLS circuit, and the Prisma Access tunnel is down.

Buy Now
Questions 19

What is the primary function of the "CloudBlade" platform in a Prisma SD-WAN deployment when integrating with third-party services or Prisma Access?

Options:

A.

It acts as a physical line card on the ION device to provide additional 10Gbps interfaces.

B.

It is a containerized application running on the ION device that performs Deep Packet Inspection (DPI).

C.

It is a cloud-based API integration layer that automates the configuration of the ION devices and the remote service.

D.

It is a monitoring dashboard used exclusively for viewing flow records.

Buy Now
Questions 20

In a Prisma SD-WAN deployment, what is the defining characteristic of a "Standard VPN" compared to a "Secure Fabric Link"?

Options:

A.

 Standard VPNs use GRE encapsulation, while Secure Fabric Links use VXLAN.

B.

 Standard VPNs are automatically built between ION devices, while Secure Fabric Links require manual configuration.

C.

 Standard VPNs are manually configured IPSec tunnels to non-ION endpoints, while Secure Fabric Links are automated tunnels between ION devices.

D.

 Standard VPNs support BGP, whereas Secure Fabric Links only support static routing.

Buy Now
Questions 21

An organization has created a custom internal application definition for "Inventory_App" on the Prisma SD-WAN controller based on its destination IP address and port (L3/L4 rule). The application server IP has just changed.

After updating the custom application definition on the controller, how is this change propagated to the branch ION devices?

Options:

A.

 The administrator must manually "Push" the policy to all sites.

B.

 The administrator must reboot the ION devices for the new object to load.

C.

 The controller automatically pushes the updated Application Definition (App-Def) to all ION devices immediately.

D.

 The change will only take effect after the daily "App-ID" scheduled update.

Buy Now
Questions 22

User-ID integration is configured for a Prisma SD-WAN deployment. Branch-1 has the user-to-IP mappings available, and User-1 is mapped to IP-1.

To which two use cases can User-ID based zone-based firewall policies be applied? (Choose two.)

Options:

A.

User-1 accessing a SaaS application on direct internet and source User-ID based zone-based firewall rules on Branch-1 ION

B.

User-1 accessing a private application within Branch-1, and source User-ID based zone-based firewall rules on Branch-1 ION

C.

User-1 accessing a private application in data center via SD-WAN overlay, and destination User-ID based zone-based firewall rules on DC ION

D.

User-1 accessing a private application in Branch-2 via SD-WAN overlay, and destination User-ID based zone-based firewall rules on Branch-2 ION

Buy Now
Questions 23

Which metrics can be monitored at the individual Prisma SD-WAN ION device level to assess its health and operational performance?

Options:

A.

Device software version and interface bandwidth

B.

Device CPU, memory and disk use, interface bandwidth, and errors/discards

C.

Device VPN tunnels and controller reachability status

D.

Device application flow statistics, Autonomous Digital Experience Manager (ADEM) metrics, and site health score

Buy Now
Questions 24

An administrator has configured a Path Policy for "ERP_Traffic". The policy allows two public internet links, "ISP-A" and "ISP-B", both marked as "Active". The Path Quality Profile (SLA) requires a latency of less than 150ms. Currently, both ISP-A and ISP-B have a latency of 40ms, well within the SLA.

How does the Prisma SD-WAN ION determine which link to use for a new flow of "ERP_Traffic" when both active paths meet the SLA requirements?

Options:

A.

It selects the path with the lowest numerical latency (e.g., if ISP-A drops to 39ms).

B.

It selects the path with the highest available bandwidth capacity.

C.

It duplicates the packets across both paths (Packet Duplication) to ensure delivery.

D.

It selects the path that appears first in the interface configuration list.

Buy Now
Questions 25

An administrator wants to configure a Path Policy that routes all "Guest Wi-Fi" traffic directly to the internet using the local broadband interface, bypassing all VPN tunnels.

Which Service & DC Group setting should be selected in the policy rule to achieve this "Direct Internet Access" (DIA) behavior?

Options:

A.

 Standard VPN

B.

 Direct

C.

 Any-Private

D.

 Default-Cluster

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Feb 14, 2026
Questions: 86

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now SD-WAN-Engineer testing engine

PDF (Q&A)

$31.5  $104.99
buy now SD-WAN-Engineer pdf
dumpsmate guaranteed to pass

24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 14 Feb 2026