New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Questions and Answers

Questions 4

An administrator wants to configure a Path Policy that routes all "Guest Wi-Fi" traffic directly to the internet using the local broadband interface, bypassing all VPN tunnels.

Which Service & DC Group setting should be selected in the policy rule to achieve this "Direct Internet Access" (DIA) behavior?

Options:

A.

 Standard VPN

B.

 Direct

C.

 Any-Private

D.

 Default-Cluster

Buy Now
Questions 5

A network engineer is troubleshooting a user complaint regarding "slow application performance" for an internal web application. While viewing the Flow Browser in the Prisma SD-WAN portal, the engineer notices that the Server Response Time (SRT) is consistently high (over 500ms), while the Network Transfer Time (NTT) and Round Trip Time (RTT) are low (under 50ms).

What does this data indicate about the root cause of the issue?

Options:

A.

The issue is likely caused by congestion on the WAN circuit, requiring a QoS policy adjustment.

B.

The issue is likely on the application server itself (e.g., high CPU, slow database query), not the network.

C.

The issue is caused by a high packet loss rate on the internet path.

D.

The issue is due to a misconfigured DNS server at the branch.

Buy Now
Questions 6

In the Prisma SD-WAN portal, the Application Health dashboard assigns a color-coded "Health Score" (Green, Yellow, Red) to applications.

Which three metrics are combined to calculate this composite AppX (Application Experience) score? (Choose three.)

Options:

A.

 Transaction Failure Rate

B.

 Network Transfer Time (NTT)

C.

 Server Response Time (SRT)

D.

 Bandwidth Utilization

E.

 Jitter

Buy Now
Questions 7

By default, how many days will Prisma SD-WAN VPNs stay operational before the keys expire when an ION device loses connection with the controller?

Options:

A.

1

B.

3

C.

5

D.

7

Buy Now
Questions 8

A network operator receives a critical SITE_CONNECTIVITY_DOWN alarm for a branch site in the Prisma SD-WAN portal.

What specific condition triggers this alarm type?

Options:

A.

 The device has lost power and rebooted.

B.

 One of the two internet circuits at the site has gone down.

C.

 All Secure Fabric Links (VPNs) to all remote peers are down, isolating the site from the overlay.

D.

 The site has exceeded its licensed bandwidth capacity.

Buy Now
Questions 9

When using the CloudBlade to integrate Prisma SD-WAN with Prisma Access, how does the system ensure that the IPSec tunnels between the branch ION and the Prisma Access Security Processing Node (SPN) are kept alive during periods of no user traffic?

Options:

A.

 The administrator must configure a continuous ping script on a branch PC.

B.

 The CloudBlade automatically configures the ION to send Synthetic Probes (ICMP/HTTP) across the tunnel.

C.

 The IPSec tunnel uses standard DPD (Dead Peer Detection) and the ION sends keepalives.

D.

 Prisma Access initiates the connection to the branch every 60 seconds.

Buy Now
Questions 10

An administrator is configuring a BGP peer on a Data Center ION to learn routes from the core switch. The goal is to have the ION learn these prefixes and then advertise them to all remote branch sites across the SD-WAN overlay.

Which setting must be configured on the BGP Peer to ensure these learned routes are redistributed into the SD-WAN fabric?

Options:

A.

 Set the "Admin Distance" to 20.

B.

 Enable "Graceful Restart".

C.

 Set the "Scope" to "Global".

D.

 Configure a "Prefix List" to deny all.

Buy Now
Questions 11

What are two requirements for implementing user/group-based path policies? (Choose two.)

Options:

A.

Cloud Identity Engine

B.

Internal host detection

C.

Autonomous Digital Experience Manager (ADEM)

D.

Data center ION

Buy Now
Questions 12

A network engineer is troubleshooting an ION device that is showing as "Offline" in the Prisma SD-WAN portal, despite the site reporting that local internet access is working. The engineer has console access to the device.

Which CLI command should be used to specifically validate the device's ability to resolve the controller's hostname and establish a secure connection to it over a specific interface?

Options:

A.

 ping

B.

 debug controller reachability

C.

 show system connectivity

D.

 dump vpn summary

Buy Now
Questions 13

A multinational company is deploying Prisma SD-WAN across North America, Europe, and Asia. The data centers in the North America region have served all regions, but regional policies are now being enforced that mandate each of the regions to build their own data centers and branch sites to only connect to their respective regional data centers.

How can this regionalization be achieved so that new or existing branch sites only build tunnels to the regional DC IONs?

Options:

A.

Create a new cluster for each regional DC ION and move the sites from the existing cluster to the new cluster.

B.

Disable the auto-tunnel feature globally on the Prisma SD-WAN portal and manually create all necessary tunnels exclusively between IONs within their designated regions.

C.

Remove the circuit labels and apply new circuit labels for in-region circuits only.

D.

Assign WAN interfaces to distinct Virtual Routing and Forwarding (VRF) instances for each region on the DC IONs, ensuring that branches only connect to the WAN interfaces/VRFs designated for their region.

Buy Now
Questions 14

An administrator has configured a Zone-Based Firewall (ZBFW) policy on a branch ION. They created a rule to "Allow" traffic from the "Guest" zone to the "Internet" zone. However, users in the "Guest" zone are reporting they cannot reach a specific public website, and the Flow Browser shows the flow state as "REJECT".

What is the most likely reason for this specific rejection, assuming the "Allow" rule is correctly placed at the top of the list?

Options:

A.

 The implicit default action at the bottom of the security policy is "Deny All".

B.

 The "Allow" rule does not have the specific "Application" defined (it is set to Any), causing a mismatch.

C.

 There is a "Deny" rule in the "Global" policy stack that is taking precedence over the "Local" site rule.

D.

 The ION device does not support firewalling for HTTP traffic.

Buy Now
Questions 15

When defining a Path Quality Profile (SLA) for a "Transactional" application group (e.g., Citrix, Oracle), the administrator sets the "Packet Loss" threshold to 1%.

What happens to the traffic for this application if all active paths currently exceed this 1% loss threshold?

Options:

A.

 The traffic is dropped to prevent data corruption.

B.

 The system selects the best available path (lowest loss) among the active paths, even if it violates the profile.

C.

 The traffic is queued indefinitely until a path recovers.

D.

 The system automatically enables a Backup path, even if the Active paths are technically "Up" but degraded.

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Dec 21, 2025
Questions: 52
SD-WAN-Engineer pdf

SD-WAN-Engineer PDF

$25.5  $84.99
SD-WAN-Engineer Engine

SD-WAN-Engineer Testing Engine

$30  $99.99
SD-WAN-Engineer PDF + Engine

SD-WAN-Engineer PDF + Testing Engine

$40.5  $134.99