Spring Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Paloalto Networks SD-WAN-Engineer Palo Alto Networks SD-WAN Engineer Exam Practice Test

Palo Alto Networks SD-WAN Engineer Questions and Answers

Question 1

A remote branch site is reporting intermittent connectivity to the Data Center. The administrator checks the System > Alarms page and sees a "VPN_DOWN" alarm for the tunnel to the DC. However, the internet circuit status is "Up".

Which specific log file or diagnostic tool in the Prisma SD-WAN portal would provide the IKE (Internet Key Exchange) error codes (e.g., "NO_PROPOSAL_CHOSEN" or "AUTH_FAILED") to pinpoint the cause of the tunnel failure?

Options:

A.

 Flow Browser

B.

 Event Logs > System

C.

 Site Summary > Topology

D.

 Link Quality Graphs

Question 2

When planning a software upgrade for a large fleet of ION devices, what is the recommended best practice regarding the "Software Version" assigned in the Site Summary?

Options:

A.

 Manually log into each device and upload the new image file via USB.

B.

 Assign the new software version to the "Global" site configuration to upgrade all 1000+ sites simultaneously.

C.

 Use Site Tags to group sites (e.g., "Pilot", "Region-1", "Region-2") and assign the new software version incrementally to these tags to minimize risk.

D.

 The ION devices upgrade themselves automatically whenever a new version is released by Palo Alto Networks.

Question 3

When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:

(SNR Graph showing Carrier-1 in blue dropping to near 0 dB and Carrier-2 in green staying relatively stable between 4.5 dB and 6.5 dB)

Question # 3

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)

Options:

A.

Using Carrier-1 as the WAN path may have experienced some performance degradation.

B.

Using Carrier-2 as the WAN path may have experienced some performance degradation.

C.

Using Carrier-2 as the WAN path may have switched over to Carrier-1.

D.

Using Carrier-1 as the WAN path may have switched over to Carrier-2.

Question 4

In the Prisma SD-WAN portal, the Application Health dashboard assigns a color-coded "Health Score" (Green, Yellow, Red) to applications.

Which three metrics are combined to calculate this composite AppX (Application Experience) score? (Choose three.)

Options:

A.

 Transaction Failure Rate

B.

 Network Transfer Time (NTT)

C.

 Server Response Time (SRT)

D.

 Bandwidth Utilization

E.

 Jitter

Question 5

An administrator has configured a Path Policy for "ERP_Traffic". The policy allows two public internet links, "ISP-A" and "ISP-B", both marked as "Active". The Path Quality Profile (SLA) requires a latency of less than 150ms. Currently, both ISP-A and ISP-B have a latency of 40ms, well within the SLA.

How does the Prisma SD-WAN ION determine which link to use for a new flow of "ERP_Traffic" when both active paths meet the SLA requirements?

Options:

A.

It selects the path with the lowest numerical latency (e.g., if ISP-A drops to 39ms).

B.

It selects the path with the highest available bandwidth capacity.

C.

It duplicates the packets across both paths (Packet Duplication) to ensure delivery.

D.

It selects the path that appears first in the interface configuration list.

Question 6

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.

 Both sites must disable NAT and use public IPs on the ION interface.

C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.

 Dynamic VPNs are not supported if both sides are behind NAT.

Question 7

When allocating Aggregate Bandwidth for a Prisma Access "Remote Network" deployment (connecting 50 branch sites), how is the bandwidth license enforced?

Options:

A.

 Each branch site is hard-capped at the specific bandwidth limit defined in its individual IPSec tunnel configuration.

B.

 The bandwidth is shared as a pool across all sites in a specific Compute Location (Region); individual sites can burst up to the available pool capacity.

C.

 The bandwidth is allocated per device serial number and cannot be shared.

D.

 The bandwidth license is only checked once during the initial onboarding; there is no ongoing enforcement.

Question 8

For how many hours are Prisma SD-WAN VPN shared secrets valid?

Options:

A.

1

B.

8

C.

24

D.

72

Question 9

An administrator is configuring an ION 2000 device for a deployment where high availability is required, but the site has only a single internet circuit. The administrator configures a Bypass Pair (Fail-to-Wire) on ports 1 and 2 connecting the ISP modem to the legacy firewall.

If the ION device loses power, what is the resulting behavior of the traffic flowing through this Bypass Pair?

Options:

A.

 Traffic is blocked to prevent uninspected packets from entering the network (Fail-to-Block).

B.

 The internal relay closes, physically bridging Port 1 and Port 2, allowing traffic to flow transparently between the modem and firewall.

C.

 The device reboots into "Safe Mode" and acts as a Layer 2 switch.

D.

 Traffic is rerouted to the LTE modem automatically.

Question 10

Where is route leaking configured between VRFs?

Options:

A.

VRF definition

B.

BGP peer

C.

Site configuration

D.

VRF profile

Question 11

An engineer at a managed services provider is updating an application that allows its customers to request firewall changes to also manage SD-WAN. The application will be able to make any approved changes directly to devices via API.

What is a requirement for the application to create SD-WAN interfaces?

Options:

A.

REST API’s “sdwanInterfaceprofiles” parameter on a Panorama device

B.

REST API’s “sdwanInterfaces” parameter on a firewall device

C.

XML API’s “sdwanprofiles/interfaces” parameter on a Panorama device

D.

XML API’s “InterfaceProfiles/sdwan” parameter on a firewall device

Question 12

User-ID integration is configured for a Prisma SD-WAN deployment. Branch-1 has the user-to-IP mappings available, and User-1 is mapped to IP-1.

To which two use cases can User-ID based zone-based firewall policies be applied? (Choose two.)

Options:

A.

User-1 accessing a SaaS application on direct internet and source User-ID based zone-based firewall rules on Branch-1 ION

B.

User-1 accessing a private application within Branch-1, and source User-ID based zone-based firewall rules on Branch-1 ION

C.

User-1 accessing a private application in data center via SD-WAN overlay, and destination User-ID based zone-based firewall rules on DC ION

D.

User-1 accessing a private application in Branch-2 via SD-WAN overlay, and destination User-ID based zone-based firewall rules on Branch-2 ION

Question 13

An administrator is configuring a High Availability (HA) pair of ION 3000 devices at a Data Center.

Which statement accurately describes the requirement for the HA Control Interface connection between the two devices?

Options:

A.

 The HA Control interface must be connected via a Layer 3 routed network to ensure reachability across different subnets.

B.

 The HA Control interface must be a direct physical connection or a Layer 2 adjacent connection on a dedicated VLAN, with no routing between them.

C.

 The HA Control connection is optional if both devices are managed by the same Cloud Controller.

D.

 The HA Control interface uses the management port and must be connected to the internet.

Question 14

A site has two internet circuits: Circuit A with 500 Mbps capacity and Circuit B with 100 Mbps capacity.

Which path policy configuration will ensure traffic is automatically shifted from a saturated circuit to the circuit with available bandwidth?

Options:

A.

Circuit A as an active, Circuit B as a backup

B.

Circuit B as an active, Circuit A as a backup

C.

Both circuits under active path

D.

Circuit B as an L3 failure path

Question 15

An ION 3000 device at a remote branch has suffered a critical hardware failure and must be replaced via the RMA process. The administrator has received the replacement unit.

What is the correct procedure to transfer the configuration and license from the defective unit to the replacement unit to ensure minimal downtime and retention of historical data?

Options:

A.

 Manually configure the new device from scratch, then open a support ticket to transfer the license.

B.

 Use the "Replace Device" workflow in the Prisma SD-WAN portal, which automatically transfers the configuration (Device Shell) and re-associates the site to the new serial number.

C.

 Backup the configuration of the old device to a USB drive and restore it to the new device using the local console.

D.

 Delete the old device from the portal, create a new site for the replacement device, and rebuild the policies manually.

Question 16

Which condition, when configured within a performance policy, is a trigger for generating an incident related to application performance or path degradation?

Options:

A.

Violation of defined service-level agreement (SLA) thresholds for application performance or link quality.

B.

Exceeding the configured threshold for total concurrent flows in the ION device, resulting in a SYSTEM_CONCURRENT_FLOW_THRESHOLD_EXCEEDED incident.

C.

Loss of a BGP peering session on a data center ION device, leading to potential routing instability.

D.

Physical WAN interface transitioning from an “up” to a “down” state, resulting in a NETWORK_ANYNETLINK_DOWN event.

Question 17

The UI triggers incident DEVICESW_CONCURRENT_FLOWLIMIT_EXCEEDED for a branch site. Based in the image below, which tool can be used to identify the host?

Question # 17

Options:

A.

Run tcpdump under the LAN interface

B.

Monitor → Activity → Flows

C.

Monitor → Activity → New flows

D.

Monitor → Activity → Transaction Stats

Question 18

A network engineer is troubleshooting a user complaint regarding "slow application performance" for an internal web application. While viewing the Flow Browser in the Prisma SD-WAN portal, the engineer notices that the Server Response Time (SRT) is consistently high (over 500ms), while the Network Transfer Time (NTT) and Round Trip Time (RTT) are low (under 50ms).

What does this data indicate about the root cause of the issue?

Options:

A.

The issue is likely caused by congestion on the WAN circuit, requiring a QoS policy adjustment.

B.

The issue is likely on the application server itself (e.g., high CPU, slow database query), not the network.

C.

The issue is caused by a high packet loss rate on the internet path.

D.

The issue is due to a misconfigured DNS server at the branch.

Question 19

When deploying a branch gateway, secure fabric VPN tunnels are automatically established between which two site types? (Choose two.)

Options:

A.

Branch to branch gateway (same domain)

B.

Branch gateway to data center

C.

Branch gateway to branch gateway

D.

Branch to branch gateway (different domain)

Question 20

A network design mandates segmentation at the routing level and traffic isolation across various services, such as teller cash registers, ATM traffic, guest Wi-Fi, and corporate applications. Which command can be used to validate and display the Virtual Routing and Forwarding (VRF) route leak rules?

Options:

A.

show interface vrf route_leak_rule all

B.

dump vrf route_leak_rule

C.

inspect flow_browser vrf all

D.

inspect vrf route_leak_rule all

Question 21

In a data center (DC) with two ION devices, all of the remote branch Prisma SD-WAN VPNs are active only on DC ION-1.

Why are no VPNs active on DC ION-2?

Options:

A.

The BGP core peer is down.

B.

The static route to core as a next hop is missing.

C.

The ION device is behind a NAT.

D.

The DC and branches are in a different domain.

Question 22

Full discovery and classification of IoT devices by the IoT Security service is failing. Which Prisma SD-WAN ION device configuration will cause this behavior?

Options:

A.

The ION devices are missing DHCP Configuration. If ION devices are not explicitly configured as either a DHCP relay agent or a DHCP server, DHCP traffic logs will not be sent to the Strata Logging Service, resulting in incomplete device profiles for IoT Security.

B.

The Prisma SD-WAN ION devices lack properly configured or enabled Service Health Probes specifically targeting the IoT device subnets. Without these active probes, the system cannot gather critical real-time reachability and performance metrics essential for dynamic device profiling and classification.

C.

The Syslog export configuration on the ION devices to the Strata Logging Service has filters that are too restrictive, potentially excluding logs vital for IoT Security’s device identification and classification engine. This prevents comprehensive event data, including device discovery messages, from reaching the portal.

D.

The ION devices are not configured to explicitly enable and export IPFIX flow records, especially those containing Layer 2 and Layer 7 context, to the Strata Logging Service for IoT Security. While ARP data is sent by default, comprehensive device classification relies on these detailed flow records, which are not being captured.

Question 23

An administrator needs to generate a monthly report showing the "Top Applications" by bandwidth usage across all branch sites to justify a bandwidth upgrade.

Which specific component of the Prisma SD-WAN interface is designed to create, schedule, and email these PDF summaries?

Options:

A.

 Activity Charts

B.

 Media Analytics

C.

 Reports

D.

 Flow Browser

Question 24

A branch manager reports slow network performance, and the network administrator wants to use Prisma SD-WAN Copilot to quickly identify if a specific user, by source IP address, is consuming excessive bandwidth as well as which applications are contributing to this consumption. How can Copilot assist in this investigation?

Options:

A.

It will automatically generate and email a “User Bandwidth Consumption” report for the specified branch, which the administrator can use to find the top user and the application details.

B.

It can identify the top applications being used across the entire branch and can be correlated with Flow Browser to attribute specific application usage or total bandwidth consumption to individual source IPs.

C.

It can directly process a natural language query such as “Show top bandwidth source IPs at SD-WAN Branch X over last 3 hours,” provide summarized views of the top-consuming source IPs, and view the primary applications they are using.

D.

It will redirect the administrator to the WAN Clarity “Top N: Source IPs” report and the “Flow Browser” utility, suggesting correlation between these tools to determine a user’s specific application usage.

Question 25

A network installer is at a remote branch site to deploy a new ION 3000 device. The device has been racked, cabled to the internet, and powered on. The installer has the "Claim Code" displayed on the email sent by the administrator.

When the administrator enters this Claim Code into the Prisma SD-WAN portal, what is the immediate status of the device before the configuration is fully pushed?

Options:

A.

Online

B.

Claimed

C.

Provisioned

D.

Active