Skip to content

SD-WAN-Engineer Palo Alto Networks Certified SD-WAN Engineer Practice Questions

Prepare for SD-WAN-Engineer with more than an answer.

249 questions in the full set20 sample questionsUpdated Jan 31, 2026
Exam fee
$250 USD
Level
Specialist
Valid for
2 years
Domains covered on the exam 5
  1. Planning and Design24%
  2. Deployment and Configuration24%
  3. Operations and Monitoring18%
  4. Unified SASE14%
  5. Troubleshooting20%
  1. 1

    A network operator is monitoring the application health score for a critical SaaS application in Prisma SD-WAN. The score has dropped to 45/100. Which two metrics primarily contribute to this health score calculation? (Select TWO)

    Show answer details

    Correct answer: B, C

    Per the Prisma SD-WAN Administrator's Guide, an application's health score is assessed per path from application round-trip time (RTT), which is the predominant factor, and packet loss on the path. Jitter, bandwidth utilisation and device CPU are not inputs to the application health score (jitter and MOS appear in circuit/link quality views).

    Per the Prisma SD-WAN Administrator's Guide, an application's health score is assessed per path from application round-trip time (RTT), which is the predominant factor, and packet loss on the path. Jitter, bandwidth utilisation and device CPU are not inputs to the application health score (jitter and MOS appear in circuit/link quality views).

  2. 2

    The operations team is receiving too many 'Circuit Down' incidents for a site with a flaky 4G backup connection that flaps every few minutes. They want an incident only if the circuit stays down for more than 10 minutes. Where should this be configured?

    Show answer details

    Correct answer: D

    Prisma SD-WAN Incident Policies let you match resources (for example the site's circuits) and incident codes and apply actions. Setting Suppress with a dampening interval of 10 minutes suppresses the incident until the interval ends; if the condition has not cleared by then, the incident is unsuppressed and raised, so short flaps of the 4G circuit no longer generate noise (dampening applies to incidents, not alerts). A flap rule can additionally raise a 'Flap Rate Exceeded' incident. Disabling monitoring hides real outages, BFD timers do not control notifications, and 'Maintenance Mode' is not a feature (schedule-based suppression is for planned windows).

  3. 3

    An administrator uses the Flows view in Prisma SD-WAN to investigate a reported application issue. They filter for the source IP of the user. The flow's security action shows 'Allow', but the user reports a connection failure. Which flow information is most useful to determine whether the connection is being reset at the TCP level?

    Show answer details

    Correct answer: A

    The Prisma SD-WAN Flows view (Site Summary > View all flows) shows, for each flow, the security rule and action plus TCP session metrics: the number of SYN, FIN and RST packets, init_success (whether the TCP session initiation succeeded), retransmits, RTT and server response time. A flow that the zone-based firewall allowed but that shows RST packets or a failed init indicates the connection was reset or refused at the TCP level. The App ID, ingress interface and path policy rule do not show how the session ended.

  4. 4

    What is the primary function of the 'WAN Clarity' reports in the Prisma SD-WAN portal?

    Show answer details

    Correct answer: A

    WAN Clarity Reporting (WCR) provides auto-generated, downloadable report packages, generated weekly, that show utilization trends across the Prisma SD-WAN fabric. Branch reports are Traffic Distribution, Utilization Quadrant (90th-percentile utilization), Utilization Over Threshold (time above 70% of provisioned bandwidth), Heatmap, Hotspots, Top N (top applications and IPs for the week) and Application Volume per Circuit; data centers get Traffic Distribution, Circuit Utilization, Hotspots and Top N. The license also enables AIOps insights and health scores. Administrators use them for WAN capacity planning and network or QoS policy adjustments; WAN Clarity does not change routing, upgrade software or generate claim keys.

  5. 5

    A customer wants to forward all flow logs from their Prisma SD-WAN ION devices to an external SIEM (Security Information and Event Management) system for compliance archiving. Which mechanism is supported for this purpose?

    Show answer details

    Correct answer: C

    Prisma SD-WAN ION devices export logs to syslog servers (up to 16 per device): event logs (alerts and alarms), authentication logs and flow logs in RFC 5424 format, over UDP, TCP or TLS. Syslog export is configured on the devices (with syslog server profiles), and the SIEM receives the logs directly from the IONs. FTP export, SNMP traps and e-mail attachments are not flow-log export mechanisms.

  6. 6

    An enterprise is planning a migration from a traditional MPLS-based WAN to Prisma SD-WAN. The architecture team needs to select an ION device (per the April 2024 ION device specifications) for a large regional headquarters that requires 2 Gbps of encrypted throughput, support for 10 Gbps fiber handoffs, and high availability capabilities. The site also requires bypass pair functionality for fail-to-wire resilience. Which ION model series provides the optimal balance of performance and interface specifications for this requirement?

    Show answer details

    Correct answer: B

    Per the April 2024 ION specifications, the ION 9000 (positioned for multigigabit remote-office data centers and large campuses) has 8 x 10 GE SFP+ ports, four bypass (fail-to-wire) pairs, and 8 Gbps encrypted throughput in branch mode (15 Gbps in DC mode), and supports branch HA. The ION 1200 (700 Mbps, no 10 GE) and ION 3200 (1 Gbps branch, 1 GE RJ45/SFP combo ports, one bypass pair) fall short, and the legacy ION 3000 has only 1 GE RJ45 ports. The ION 9000 has since been succeeded by the ION 9200.

  7. 7

    A network architect is designing a High Availability (HA) solution for a critical branch site using two ION devices. If the primary device fails, the secondary device must automatically take over traffic forwarding and the full capacity of all WAN circuits. Which statement correctly describes Prisma SD-WAN branch HA?

    Show answer details

    Correct answer: B

    Prisma SD-WAN branch HA allows one HA group per branch site with up to two devices. One is elected active and handles path selection, BGP, VPNs and statistics; the other is the backup and only bridges traffic to the active device. Fail-to-wire cabling lets the active ION use the full capacity of all WAN circuits. Liveliness uses VRRP advertisements on the HA control interface (interval 200 ms-10 s); after 3 missed advertisements the backup becomes active. Priority (up to 255, with at least 40 difference recommended), optional preemption and up to four tracked interfaces control the election, and DHCP leases are synchronized from active to backup.

  8. 8

    During the planning phase for a retail chain, the engineer must define a policy that routes real-time Voice over IP (VoIP) traffic over MPLS when the circuit meets strict SLA criteria, but fails over to the Internet VPN if packet loss exceeds 1%. Which configuration object in Prisma SD-WAN is primarily responsible for defining these traffic steering rules based on application performance metrics?

    Show answer details

    Correct answer: B

    Path Policy rules in Prisma SD-WAN are used to define traffic steering logic. They allow administrators to select paths (Active/Backup) based on application types and specific SLA requirements (latency, jitter, packet loss).

  9. 9

    A global organization is deploying Prisma SD-WAN and needs to integrate a third-party cloud security service (for example, Zscaler Internet Access) without manually building tunnels on every ION and without deploying additional hardware. Which Prisma SD-WAN component should be configured to automate this integration?

    Show answer details

    Correct answer: C

    CloudBlades are API-based integrations in the Prisma SD-WAN controller that automate connectivity to third-party services. For example, the Zscaler Internet Access CloudBlade automatically integrates the controller, the remote IONs and the Zscaler Enforcement Nodes, building the Standard VPN (IPsec/GRE) tunnels; the Admin Guide points to CloudBlades for streamlined autoconfiguration of IPsec or GRE tunnels. A virtual ION is a device form factor, and 'Prisma Access Connector' and 'App-Fabric Gateway' are not integration platforms.

  10. 10

    While designing the NAT strategy for a branch office, the requirement is to allow guest Wi-Fi users to access the Internet directly through the local ISP circuit without consuming VPN bandwidth to the data center. Corporate users must still be backhauled. Which configuration approach best satisfies this requirement?

    Show answer details

    Correct answer: B

    Path policy rules list Active, Backup and L3 Failure paths, each an overlay (Direct, Prisma SD-WAN VPN or Standard VPN) plus a circuit category. A guest rule whose only paths are Direct on the internet circuit category keeps guest traffic local, while corporate rules keep using the VPN to the data center. By default, Prisma SD-WAN performs Source NAT out of the box on traffic going directly to public internet interfaces, so no extra NAT rule is needed unless custom translation is required.

Create an account to continue.