Winter Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ex2p65

Exact2Pass Menu

Palo Alto Networks SD-WAN Engineer

Last Update 9 hours ago Total Questions : 86

The Palo Alto Networks SD-WAN Engineer content is now fully updated, with all current exam questions added 9 hours ago. Deciding to include SD-WAN-Engineer practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our SD-WAN-Engineer exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these SD-WAN-Engineer sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Palo Alto Networks SD-WAN Engineer practice test comfortably within the allotted time.

Question # 4

How can a network administrator detect a site outage or a service-level agreement (SLA) violation using controller-generated incidents?

A.

Incidents, SNMP traps, and audits

B.

Device logs, alerts, and incidents

C.

Incidents, alerts, statistics, and audit logs

D.

Priority alerts, informational alerts, and audit logs

Question # 5

BGP core peers on data center IONs are learning only a default route from the core router. Which action will protect the SD-WAN network from getting isolated in the event of BGP misconfiguration on the core routers?

A.

Enable BGP Bidirectional Forwarding Detection (BFD) on the core peer sessions to rapidly detect BGP neighbor failures.

B.

Configure BGP max-prefix limits on the ION devices to prevent them from accepting too many routes from the core routers.

C.

Add a static default route with higher admin distance pointing to the core peer IPs.

D.

Implement BGP route filtering using prefix lists and route maps on the ION devices to only accept specific, known prefixes from the core.1

Question # 6

For how many hours are Prisma SD-WAN VPN shared secrets valid?

A.

1

B.

8

C.

24

D.

72

Question # 7

When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:

(SNR Graph showing Carrier-1 in blue dropping to near 0 dB and Carrier-2 in green staying relatively stable between 4.5 dB and 6.5 dB)

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)

A.

Using Carrier-1 as the WAN path may have experienced some performance degradation.

B.

Using Carrier-2 as the WAN path may have experienced some performance degradation.

C.

Using Carrier-2 as the WAN path may have switched over to Carrier-1.

D.

Using Carrier-1 as the WAN path may have switched over to Carrier-2.

Question # 8

An administrator has configured a Zone-Based Firewall (ZBFW) policy on a branch ION. They created a rule to "Allow" traffic from the "Guest" zone to the "Internet" zone. However, users in the "Guest" zone are reporting they cannot reach a specific public website, and the Flow Browser shows the flow state as "REJECT".

What is the most likely reason for this specific rejection, assuming the "Allow" rule is correctly placed at the top of the list?

A.

 The implicit default action at the bottom of the security policy is "Deny All".

B.

 The "Allow" rule does not have the specific "Application" defined (it is set to Any), causing a mismatch.

C.

 There is a "Deny" rule in the "Global" policy stack that is taking precedence over the "Local" site rule.

D.

 The ION device does not support firewalling for HTTP traffic.

Question # 9

When defining a Path Quality Profile (SLA) for a "Transactional" application group (e.g., Citrix, Oracle), the administrator sets the "Packet Loss" threshold to 1%.

What happens to the traffic for this application if all active paths currently exceed this 1% loss threshold?

A.

 The traffic is dropped to prevent data corruption.

B.

 The system selects the best available path (lowest loss) among the active paths, even if it violates the profile.

C.

 The traffic is queued indefinitely until a path recovers.

D.

 The system automatically enables a Backup path, even if the Active paths are technically "Up" but degraded.

Question # 10

A network engineer is troubleshooting a "Voice Quality" issue. They suspect that the DSCP markings are being stripped or altered by the ISP.

Which tool in the Prisma SD-WAN portal allows the engineer to capture live packets on the WAN interface and inspect the IP header ToS/DSCP field?

A.

 Flow Browser

B.

 Packet Capture (PCAP)

C.

 Path Quality Monitor

D.

 Event Logs

Go to page: