Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Palo Alto Networks SD-WAN Engineer

Last Update 2 hours ago Total Questions : 86

The Palo Alto Networks SD-WAN Engineer content is now fully updated, with all current exam questions added 2 hours ago. Deciding to include SD-WAN-Engineer practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our SD-WAN-Engineer exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these SD-WAN-Engineer sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Palo Alto Networks SD-WAN Engineer practice test comfortably within the allotted time.

Question # 4

When configuring SASE connectivity with easy onboarding at a branch, which two options must be selected? (Choose two.)

A.

IPSec Crypto Profile

B.

Prisma Access Primary Location

C.

Prisma Access IKE Profile

D.

IPSec Termination Node

Question # 5

A network engineer is troubleshooting a " Voice Quality " issue. They suspect that the DSCP markings are being stripped or altered by the ISP.

Which tool in the Prisma SD-WAN portal allows the engineer to capture live packets on the WAN interface and inspect the IP header ToS/DSCP field?

A.

 Flow Browser

B.

 Packet Capture (PCAP)

C.

 Path Quality Monitor

D.

 Event Logs

Question # 6

Which IONs can support Branch Gateway?

A.

3102V, 3200, 1200S, 5200

B.

1200, 3200, 9200, 7108V 1

C.

3104V, 1200S, 5200, 7108V

D.

9200, 3200, 5200, 7116V

Question # 7

Which component of Prisma SD-WAN is responsible for distributing User-IP and user-group mappings to branch devices that match the corresponding source IPs?

A.

DC ION

B.

Cloud Identity Engine

C.

Controller

D.

NGFW

Question # 8

A network administrator notices that a branch ION device is experiencing high CPU utilization due to a suspected TCP SYN Flood attack originating from a compromised host on the local LAN.

Which specific security feature should be configured and applied to the " LAN " zone to mitigate this Denial of Service (DoS) attack?

A.

 Zone-Based Firewall (ZBFW) Rule with a " Deny " action

B.

 Zone Protection Profile

C.

 Application Quality Profile (AQP)

D.

 Access Control List (ACL) on the WAN interface

Question # 9

When integrating Prisma SD-WAN with Prisma Access, what is the specific role of the Service Connection (SC)?

A.

 It connects the Prisma Access cloud infrastructure back to the customer ' s Headquarters or Data Center for access to internal private resources (e.g., AD, DNS, Intranet).

B.

 It is the IPSec tunnel that connects a Branch site to the Prisma Access gateway for internet access.

C.

 It is the SSL VPN portal used by mobile users to connect to the network.

D.

 It is the peering link between different Prisma Access regions to optimize global traffic.

Question # 10

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

A.

The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.

B.

The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.

C.

The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

D.

The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.

Go to page: