Spring Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

SD-WAN-Engineer Sample Questions Answers

Questions 4

A network installer is attempting to claim a new ION device using the "Claim Code" method. The device is connected to the internet, but the status in the portal remains stuck at "Claimed" and does not transition to "Online". The installer connects a laptop to the LAN port of the ION and can successfully browse the internet, confirming the uplink is active.

What is the most likely cause of the device failing to reach the "Online" state?

Options:

A.

 The device is missing the "Site" assignment in the portal.

B.

 The upstream firewall is blocking outbound TCP port 443 or UDP port 123 (NTP).

C.

 The device has not yet downloaded the latest software image.

D.

 The "Circuit Label" has not been applied to the WAN interface.

Buy Now
Questions 5

What is the number and structure of Prisma SD-WAN QoS queues supported per WAN interface?

Options:

A.

12 queues

4 classes1

3 application criteria within each class

B.

16 queues

4 classes

4 application criteria with each class

C.

8 queues

1 priority queue

7 non-priority queues

D.

8 queues

2 classes

4 application criteria within each class

Buy Now
Questions 6

Network segmentation is required due to overlapping IP address space and M&A scenarios. Which Prisma SD-WAN feature will achieve the desired segmentation and end-to-end connectivity in this use case?

Options:

A.

Virtual Routing and Forwarding (VRF) profiles with proper site bindings to achieve desired isolation across the underlay

B.

Virtual Routing and Forwarding (VRF) profiles with proper site bindings to achieve desired isolation locally and across the secure fabric

C.

Multiple contexts with interface segmentation to achieve desired isolation across the underlay

D.

Multiple virtual routers with interface segmentation to achieve desired isolation across the secure fabric

Buy Now
Questions 7

Based on the HA topology image below, which two statements describe the end-state when power is removed from the ION 1200-S labeled “Active”, assuming that the ION labeled “Standby” becomes the active ION? (Choose two.)

Options:

A.

Both the connection to ISP A and the connection to LTE/5G will be usable.

B.

The VRRP Virtual IP address assigned to any SVIs will be moved to the newly active ION.

C.

The newly active ION will send a gratuitous ARP to the LAN for the IP address of any SVIs.

D.

The connection to ISP A will be usable, but the connection to LTE/5G will not.

Buy Now
Questions 8

What are two requirements for implementing user/group-based path policies? (Choose two.)

Options:

A.

Cloud Identity Engine

B.

Internal host detection

C.

Autonomous Digital Experience Manager (ADEM)

D.

Data center ION

Buy Now
Questions 9

A customer wants to deploy Prisma SD-WAN ION devices at small home offices that use consumer-grade broadband routers. These routers typically use Symmetric NAT and do not allow static port forwarding.

Which standard mechanism does Prisma SD-WAN utilize to successfully establish direct Branch-to-Branch (Dynamic) VPN tunnels through these Symmetric NAT devices?

Options:

A.

 UPnP (Universal Plug and Play)

B.

 STUN (Session Traversal Utilities for NAT)

C.

 Manual GRE Tunnels

D.

 SSL VPN encapsulation

Buy Now
Questions 10

An administrator wants to configure a Path Policy that routes all "Guest Wi-Fi" traffic directly to the internet using the local broadband interface, bypassing all VPN tunnels.

Which Service & DC Group setting should be selected in the policy rule to achieve this "Direct Internet Access" (DIA) behavior?

Options:

A.

 Standard VPN

B.

 Direct

C.

 Any-Private

D.

 Default-Cluster

Buy Now
Questions 11

An ION 3000 device at a remote branch has suffered a critical hardware failure and must be replaced via the RMA process. The administrator has received the replacement unit.

What is the correct procedure to transfer the configuration and license from the defective unit to the replacement unit to ensure minimal downtime and retention of historical data?

Options:

A.

 Manually configure the new device from scratch, then open a support ticket to transfer the license.

B.

 Use the "Replace Device" workflow in the Prisma SD-WAN portal, which automatically transfers the configuration (Device Shell) and re-associates the site to the new serial number.

C.

 Backup the configuration of the old device to a USB drive and restore it to the new device using the local console.

D.

 Delete the old device from the portal, create a new site for the replacement device, and rebuild the policies manually.

Buy Now
Questions 12

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

Options:

A.

The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.

B.

The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.

C.

The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

D.

The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.

Buy Now
Questions 13

When allocating Aggregate Bandwidth for a Prisma Access "Remote Network" deployment (connecting 50 branch sites), how is the bandwidth license enforced?

Options:

A.

 Each branch site is hard-capped at the specific bandwidth limit defined in its individual IPSec tunnel configuration.

B.

 The bandwidth is shared as a pool across all sites in a specific Compute Location (Region); individual sites can burst up to the available pool capacity.

C.

 The bandwidth is allocated per device serial number and cannot be shared.

D.

 The bandwidth license is only checked once during the initial onboarding; there is no ongoing enforcement.

Buy Now
Questions 14

Which statement is valid when integrating Prisma SD-WAN with Prisma Access remote networks?

Options:

A.

Security policies for remote networks are configured in Prisma Access and pushed to Prisma SD-WAN for enforcement on the branch ION devices.

B.

Easy onboarding automatically recommends the closest preconfigured remote network security processing nodes and can be overridden manually.

C.

A branch with multiple internet circuits will automatically connect to Prisma Access on each circuit and will be used in an active/standby manner for internet-bound traffic.

D.

Bandwidth must be allocated to each Prisma Access remote network compute location, and this bandwidth is shared between all branches that terminate on this remote network node.

Buy Now
Questions 15

Which metrics can be monitored at the individual Prisma SD-WAN ION device level to assess its health and operational performance?

Options:

A.

Device software version and interface bandwidth

B.

Device CPU, memory and disk use, interface bandwidth, and errors/discards

C.

Device VPN tunnels and controller reachability status

D.

Device application flow statistics, Autonomous Digital Experience Manager (ADEM) metrics, and site health score

Buy Now
Questions 16

In a Data Center deployment, what is the key functional difference between configuring a BGP neighbor as a "Core Peer" versus an "Edge Peer"?

Options:

A.

 A Core Peer is used for LAN-side routing to learn DC prefixes, while an Edge Peer is used for WAN-side routing to the Service Provider.

B.

 A Core Peer automatically redistributes learned routes into the SD-WAN fabric, whereas an Edge Peer does not.

C.

 A Core Peer supports eBGP only, while an Edge Peer supports iBGP only.

D.

 A Core Peer is used for connecting to the internet, while an Edge Peer connects to the MPLS provider.

Buy Now
Questions 17

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.

 Both sites must disable NAT and use public IPs on the ION interface.

C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.

 Dynamic VPNs are not supported if both sides are behind NAT.

Buy Now
Questions 18

A branch manager reports slow network performance, and the network administrator wants to use Prisma SD-WAN Copilot to quickly identify if a specific user, by source IP address, is consuming excessive bandwidth as well as which applications are contributing to this consumption. How can Copilot assist in this investigation?

Options:

A.

It will automatically generate and email a “User Bandwidth Consumption” report for the specified branch, which the administrator can use to find the top user and the application details.

B.

It can identify the top applications being used across the entire branch and can be correlated with Flow Browser to attribute specific application usage or total bandwidth consumption to individual source IPs.

C.

It can directly process a natural language query such as “Show top bandwidth source IPs at SD-WAN Branch X over last 3 hours,” provide summarized views of the top-consuming source IPs, and view the primary applications they are using.

D.

It will redirect the administrator to the WAN Clarity “Top N: Source IPs” report and the “Flow Browser” utility, suggesting correlation between these tools to determine a user’s specific application usage.

Buy Now
Questions 19

How can a network administrator detect a site outage or a service-level agreement (SLA) violation using controller-generated incidents?

Options:

A.

Incidents, SNMP traps, and audits

B.

Device logs, alerts, and incidents

C.

Incidents, alerts, statistics, and audit logs

D.

Priority alerts, informational alerts, and audit logs

Buy Now
Questions 20

Which configuration requirement must be met to allow two branch ION devices to automatically establish a direct Dynamic VPN (branch-to-branch) connection for traffic flow, bypassing the Data Center?

Options:

A.

Both ION devices must be members of the same VPN Cluster.

B.

A static "Gre Tunnel" must be manually configured between the two sites.

C.

The Data Center ION must be offline to trigger the dynamic failover.

D.

The "Standard VPN" path policy must be selected.

Buy Now
Questions 21

When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)

Options:

A.

Using Carrier-1 as the WAN path may have experienced some performance degradation.

B.

Using Carrier-2 as the WAN path may have experienced some performance degradation.

C.

Using Carrier-2 as the WAN path may have switched over to Carrier-1.

D.

Using Carrier-1 as the WAN path may have switched over to Carrier-2.

Buy Now
Questions 22

While designing a greenfield Prisma SD-WAN solution for a retailer, the risk management group requires segmentation of the retail network to avoid one large fault domain.

The following data points are provided:

    Two data centers and all sites need to access applications in both data centers

    1000 retail branches with stores concentrated in multiple metropolitan areas

    Data Center 1 and Data Center 2 have different sets of applications that are not replicated

    Maintaining application availability is the primary goal

Which action will segment the retail network and reduce regional outages?

Options:

A.

Implement a single, large data center cluster spanning both data centers to centralize management and optimize resource use.

B.

Create more than one data center cluster for a larger pool of resources and resiliency.

C.

Create more than one data center cluster in each data center and assign sites to clusters so nearby retail locations can be spread on separate clusters.

D.

Add more data center aggregation devices within the same cluster to enhance the scalability and resilience.

Buy Now
Questions 23

For how many hours are Prisma SD-WAN VPN shared secrets valid?

Options:

A.

1

B.

8

C.

24

D.

72

Buy Now
Questions 24

A remote branch site is reporting intermittent connectivity to the Data Center. The administrator checks the System > Alarms page and sees a "VPN_DOWN" alarm for the tunnel to the DC. However, the internet circuit status is "Up".

Which specific log file or diagnostic tool in the Prisma SD-WAN portal would provide the IKE (Internet Key Exchange) error codes (e.g., "NO_PROPOSAL_CHOSEN" or "AUTH_FAILED") to pinpoint the cause of the tunnel failure?

Options:

A.

 Flow Browser

B.

 Event Logs > System

C.

 Site Summary > Topology

D.

 Link Quality Graphs

Buy Now
Questions 25

A multinational company is deploying Prisma SD-WAN across North America, Europe, and Asia. The data centers in the North America region have served all regions, but regional policies are now being enforced that mandate each of the regions to build their own data centers and branch sites to only connect to their respective regional data centers.

How can this regionalization be achieved so that new or existing branch sites only build tunnels to the regional DC IONs?

Options:

A.

Create a new cluster for each regional DC ION and move the sites from the existing cluster to the new cluster.

B.

Disable the auto-tunnel feature globally on the Prisma SD-WAN portal and manually create all necessary tunnels exclusively between IONs within their designated regions.

C.

Remove the circuit labels and apply new circuit labels for in-region circuits only.

D.

Assign WAN interfaces to distinct Virtual Routing and Forwarding (VRF) instances for each region on the DC IONs, ensuring that branches only connect to the WAN interfaces/VRFs designated for their region.

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Feb 27, 2026
Questions: 86
$57.75  $164.99
$43.75  $124.99
$36.75  $104.99
buy now SD-WAN-Engineer