Sign In
Home/Palo Alto/Palo Alto Networks Certified SD-WAN Engineer/Free questions

Palo Alto Networks Certified SD-WAN Engineer — Free Practice Questions

10 free sample questions from a bank of 50, with the correct answers and explanations. No signup required — start practising right now.

1When identifying devices for IoT classification purposes, which two methods does Prisma SD-WAN use to discover devices that are not directly connected to the branch ION? (Choose two.)
  • LLDP
  • CDP
  • SNMP
  • Syslog
Answer: C, D

The short version

C and D — indirect discovery uses SNMP and Syslog. Unconnected devices surface through polling and log feeds.

Key concepts in this question

  • Indirect methods: SNMP queries and syslog streams.
  • Direct contrast: LLDP/CDP need physical adjacency.
  • IoT classification: identity from management telemetry.

Why C and D are correct

  • C. SNMP discovers devices via management polling.
  • D. Syslog reveals devices through their log emissions.

Why the others are wrong

  • A. LLDP requires direct link adjacency.
  • B. CDP requires direct link adjacency.

SD-WAN Engineer exam tip

Not-connected means SNMP plus Syslog. Adjacency protocols never reach further.

2User-ID integration is configured for a Prisma SD-WAN deployment. Branch- 1 has the user-to-IP mappings available, and User-1 is mapped to IP-1. To which two use cases can User-ID based zone-based firewall policies be applied? (Choose two.)
  • User-1 accessing a SaaS application on direct internet and source User-ID based zone-based firewall rules on Branch-1 ION
  • User-1 accessing a private application within Branch-1, and source User-ID based zone-based firewall rules on Branch-1 ION
  • User-1 accessing a private application in data center via SD-WAN overlay, and destination User-ID based zone-base firewall rules DC ION
  • User-1 accessing a private application in Branch-2 via SD-WAN overlay, and destination User-ID based zone-based firewall rules on Branch-2 ION
Answer: A, B

Comprehensive and Detailed ExplanationIn Prisma SD-WAN (CloudGenix), Zone-Based Firewall (ZBFW) policies rely on the device's ability to map an IP address to a User-ID to enforce identity-based rules. The key to this question is understanding where the mapping exists and which direction the policy attributes (Source User vs. Destination User) apply to.1. Mapping Location (Branch-1): The prompt states that Branch-1 has the user-to-IP mapping for User-1. For the most effective and scalable security enforcement, policies should be applied at the source (ingress) device where the traffic originates and where the user identity is known. This prevents unauthorized traffic from consuming WAN bandwidth only to be dropped at the destination. Therefore, the Branch-1 ION is the correct enforcement point for User-1's traffic.2. Source vs. Destination User:User-1 is the Source: In all scenarios, User-1 is the initiator of the traffic. Therefore, the security rule must match on Source User-ID.Options C and D are incorrect because they suggest using Destination User-ID based rules to control User-1. Destination User-ID rules are used when the target of the traffic is a known user (e.g., VoIP calls to a specific user's phone), not when filtering based on the sender. Furthermore, relying on the DC or Branch-2 ION to enforce policies for User-1 would require the propagation of User-ID mappings across the overlay, whereas local enforcement at Branch-1 is the standard architectural model.3. Valid Use Cases (A and B):Option A (SaaS/Internet): The Branch-1 ION acts as the internet gateway. It can use the local mapping (IP-1 = User-1) to allow or deny access to specific SaaS applications (Direct Internet Access) based on the user's identity (e.g., "Allow Marketing Group to access Social Media").Option B (Internal Segmentation): The Branch-1 ION can enforce policies for traffic moving between local zones (e.g., from a "Users" VLAN to a "Servers" VLAN within the branch). Since the ION route

3A site has two internet circuits: Circuit A with 500 Mbps capacity and Circuit B with 100 Mbps capacity. Which path policy configuration will ensure traffic is automatically shifted from a saturated circuit to the circuit with available bandwidth?
  • Circuit A as an active, Circuit B as a backup
  • Circuit B as an active, Circuit A as a backup
  • Both circuits under active path
  • Circuit B as an L3 failure path
Answer: C

The short version

C — saturation shifting needs both circuits active. Active-active lets load move to headroom automatically.

Key concepts in this question

  • Active path: carries traffic and sheds on saturation.
  • Backup semantics: standby for failure, blind to saturation.
  • L3-failure scope: down-links only, never congestion.

Why C is correct

Both circuits under active path shift traffic from the saturated leg to available bandwidth.

Why the others are wrong

  • A. Backup B sleeps through A saturation until failure.
  • B. Backup A sleeps through B saturation until failure.
  • D. L3-failure paths react to outages, not saturation.

SD-WAN Engineer exam tip

Saturation shifting means active-active. Backups only know dead versus alive.

4Site templates are to be used for the large-scale deployment of 100 Prisma SD-WAN branch sites across different regions. Which two statements align with the capabilities and best practices for Prisma SD-WAN site templates? (Choose two.)
  • The use of Jinja conditional statements within a site template is not supported, thereby limiting dynamic customization options.
  • Mandatory variables for any site template include the site name, ION software version, and at least one ION serial number /device name pair.
  • Site templates offer the capability to pre-stage device configurations by creating a device shell.
  • Once a site has been deployed using a template, its configuration can be updated or modified by applying an updated version of the template.
Answer: C, D

Comprehensive and Detailed ExplanationSite Templates (often referred to as Site Configuration Templates) are a critical tool for the Zero Touch Provisioning (ZTP) of large-scale deployments in Prisma SD-WAN.1. Device Pre-staging (Statement C):One of the primary capabilities of Site Templates is the creation of Device Shells. A device shell is a configuration container that exists in the controller before the physical hardware is installed or connected. By using a template, an administrator can pre-provision the entire configuration (interfaces, routing, subnets) for the "Site" and "Element" (Device). When the physical ION device is later connected to the internet and claimed (associated with the shell via its Serial Number), it immediately inherits this pre-staged configuration, enabling a true "plug-and-play" deployment.2. Mandatory Variables (Statement B):To successfully instantiate a functional site from a generic template, specific unique identifiers are required in the variable data set (typically a CSV file).Site Name: Identifies the location in the portal.ION Software Version: Ensures the device boots to the specific validated code version required for the deployment, preventing inconsistencies.ION Serial Number / Device Name: Required to bind the logical configuration (Shell) to the physical hardware. Even if the serial is added later during the claim process, the structure of the template and the deployment workflow mandates these variables to ensure the device can be uniquely identified and managed within the fabric.Note on Option D: While it is technically possible to re-deploy a template, the Best Practice for "Day 2" operations (updating or modifying configuration after deployment) is to use Prisma SD-WAN Stacks (Network Stacks, Security Stacks, etc.). Stacks allow for granular, policy-based updates across multiple sites without the destructive or rigid nature of re-applying a full site initialization template. Therefore, D is not the aligned best pract

5In which modes can a Prisma SD-WAN branch be deployed?
  • Testing, Control, POV
  • Production, Control, Disabled
  • Disabled, Analytics, Control
  • POV, Production, Analytics
Answer: C

Comprehensive and Detailed ExplanationPrisma SD-WAN (formerly CloudGenix) defines three distinct Operational Modes for a branch site, which determine how the ION device processes traffic and interacts with the network.Analytics Mode (Monitor): In this mode, the ION device is typically deployed inline or in a "promiscuous" monitor state to gain visibility into network traffic without actively enforcing path selection policies.1 It "learns" applications, bandwidth usage, and network characteristics (auditing) but does not steer traffic or block flows.2 This is often used during Proof of Concepts (POVs) or the initial "burn-in" phase of a deployment to generate reports without risking network disruption.Control Mode: This is the full production state. In Control Mode, the ION device actively enforces Path Policies, QoS Policies, and Security Policies. It builds Secure Fabric VPN tunnels, steers traffic based on application SLAs (e.g., sending voice over MPLS and bulk data over Broadband), and handles failover events.3 This is the required mode for a fully functional SD-WAN site.Disabled Mode: This mode effectively shuts down the site's SD-WAN functionality from the controller's perspective. It is an administrative state used when a site is being decommissioned, provisioned but not yet live, or isolated for troubleshooting. In this state, the device does not participate in the fabric.

.explanation p {

font-size: 16px;

line-height: 25px;

margin-bottom: 14px;

}

Paloalto Networks SD-WAN-Engineer View All Questions

Paloalto Networks SD-WAN-Engineer Summary

Vendor: Paloalto Networks

Product: SD-WAN-Engineer

Update on: Sep 3, 2026

Questions: 86

Price: $52.5  $149.99

Next

Based on the HA topology image below, which two statements describe the end-state when power...

When integrating Prisma SD-WAN with Prisma Access, what is the specific role of the Service

6What are two requirements for implementing user/group-based path policies? (Choose two.)
  • Cloud Identity Engine
  • Internal host detection
  • Autonomous Digital Experience Manager (ADEM)
  • Data center ION
Answer: A, B

Comprehensive and Detailed ExplanationTo implement User/Group-based policies (Path, QoS, or Security) in Prisma SD-WAN, the system requires two specific components to resolve user identities and map them to IP addresses within the fabric.Cloud Identity Engine (CIE): This is the primary requirement for identity management. The Cloud Identity Engine connects the Prisma SD-WAN controller to your directory service (e.g., Active Directory, Azure AD/Entra ID). It allows the system to retrieve and resolve User and Group attributes (e.g., "Marketing Group," "User: john.doe") so they can be selected in policy rules. Without CIE, the controller cannot interpret the group names or user identities defined in the policies.Data Center ION: In the standard deployment model for User-ID, a Data Center (DC) ION is required to act as the bridge or collector for IP-to-User mappings. The DC ION connects to the User-ID Agent (running on a PAN-OS firewall or Windows Server) to learn the mapping of IP addresses to usernames. It then redistributes this information to the controller or other branch IONs so they can identify which user is associated with the traffic flows originating from a specific private IP address.

.explanation p {

font-size: 16px;

line-height: 25px;

margin-bottom: 14px;

}

Paloalto Networks SD-WAN-Engineer View All Questions

Paloalto Networks SD-WAN-Engineer Summary

Vendor: Paloalto Networks

Product: SD-WAN-Engineer

Update on: Sep 3, 2026

Questions: 86

Price: $52.5  $149.99

Next

Which troubleshooting action should be taken when resources at one branch site can reach the...

When using the CloudBlade to integrate Prisma SD-WAN with Prisma Access, how does the system...

Previous

Payments We Accept

Your purchase with ExamsVCE is safe and fast. Your products will be available for immediate download afte

7A multinational company is deploying Prisma SD-WAN across North America, Europe, and Asia. The data centers in the North America region have served all regions, but regional policies are now being enforced that mandate each of the regions to build their own data centers and branch sites to only connect to their respective regional data centers. How can this regionalization be achieved so that new or existing branch sites only build tunnels to the regional DC IONs?
  • Create a new cluster for each regional DC ION and move the sites from the existing cluster to the new cluster.
  • Disable to auto-tunnel feature globally on the Prisma SD-WAN portal and manually create all necessary tunnels exclusively between IONs within their designated regions.
  • Remove the circuit labels and apply new circuit labels for in-region circuits only.
  • Assign WAN interfaces to distinct Virtual Routing and Forwarding (VRF) instances for each region on the DC IONs, ensuring that branches only connect to the WAN interfaces/VRFs designated for their region.
Answer: C

Comprehensive and Detailed ExplanationTo achieve strict regional isolation where branch sites only form VPN tunnels with Data Centers in their specific region (e.g., EU branches to EU DCs only), the correct architectural feature to utilize is VPN Clusters.In Prisma SD-WAN (CloudGenix), a Cluster defines a logical security and topology boundary for the overlay network. By default, devices may be placed in a "Default" cluster where they attempt to form a mesh or hub-and-spoke topology with all other reachable devices in that context.To enforce the new policy:Logical Partitioning: The administrator should create separate VPN Clusters for each region (e.g., "Cluster-NA", "Cluster-EU", "Cluster-Asia").Assignment: The Regional Data Center IONs and their corresponding Branch IONs must be moved into their respective clusters.Result: The Prisma SD-WAN controller dictates that devices can only establish Secure Fabric (VPN) tunnels with other devices within the same cluster. This effectively segments the global network, ensuring that an Asian branch never attempts to build a tunnel to a North American DC, satisfying the compliance requirement without complex access lists or manual tunnel configuration.Option B (Manual Tunnels) is administratively unscalable and negates the benefits of SD-WAN automation.Option C (Circuit Labels) is primarily for path selection and traffic steering, not for hard topology segmentation.Option D (VRFs) is used for local Layer 3 segmentation (routing isolation) within a device, not for controlling WAN overlay tunnel formation scope.

.explanation p {

font-size: 16px;

line-height: 25px;

margin-bottom: 14px;

}

Paloalto Networks SD-WAN-Engineer View All Questions

Paloalto Networks SD-WAN-Engineer Summary

Vendor: Paloalto Networks

Product: SD-WAN-Engineer

Update on: Sep 3, 2026

Questions: 86

Price: $52.5  $149.99

Next

An administrator has configured

8Which condition, when configured within a performance policy, is a trigger for generating an incident related to application performance or path degradation?
  • Violation of defined service-level agreement (SLA) thresholds for application performance or link quality.
  • Exceeding the configured threshold for total concurrent flows in the ION device, resulting in a SYSTEM_CONCURRENT_FLOW_THRESHOLD_EXCEEDED incident.
  • Loss of a BGP peering session on a data center ION device, leading to potential routing instability.
  • Physical WAN interface transitioning from an “up” to a “down” state, resulting in a NETWORK_ANYNETLINK_DOWN event.
Answer: A

The short version

A — SLA violation fires performance incidents. Breached app or link thresholds raise the alarm.

Key concepts in this question

  • Performance policy: SLA thresholds per app/path.
  • Violation trigger: crossing the line generates incidents.
  • System/network contrast: flow counts, BGP, and link states raise other events.

Why A is correct

Violating defined SLA thresholds triggers application/path performance incidents.

Why the others are wrong

  • B. Flow-count breaches raise system incidents, not performance ones.
  • C. BGP loss raises routing events, not performance ones.
  • D. Link down raises network events, not performance ones.

SD-WAN Engineer exam tip

Performance incidents answer SLA breach. Counts, peers, and links answer elsewhere.

9By default, how many days will Prisma SD-WAN VPNs stay operational before the keys expire when an ION device loses connection with the controller?
  • 1
  • 3
  • 5
  • 7
Answer: D

Comprehensive and Detailed ExplanationThe Prisma SD-WAN (CloudGenix) solution is designed with a separation of the control plane (Controller) and the data plane (ION devices).1 In the event that an ION device loses connectivity to the Cloud Controller (often referred to as running in "headless mode"), the device continues to forward traffic and maintain existing VPN tunnels using the keys it currently holds.2However, for security purposes, the VPN session keys (shared secrets) used for the Secure Fabric have a finite validity period. The system is designed such that these keys are rotated regularly.3 If the controller is unreachable, the ION device can continue to rotate keys locally and maintain the VPNs for a maximum default period of 72 hours (exactly 3 days).4If the connection to the controller is not restored within this 72-hour window, the keys will eventually expire, and the ION will be unable to retrieve new authorized key material from the controller.5 Consequently, the VPN tunnels will go down, and the "out of shared secret key" error will be observed in the VPN status logs. This mechanism ensures that a permanently compromised or stolen device cannot maintain network access indefinitely without central authorization.

.explanation p {

font-size: 16px;

line-height: 25px;

margin-bottom: 14px;

}

Paloalto Networks SD-WAN-Engineer View All Questions

Paloalto Networks SD-WAN-Engineer Summary

Vendor: Paloalto Networks

Product: SD-WAN-Engineer

Update on: Sep 3, 2026

Questions: 86

Price: $52.5  $149.99

Next

What is the number and structure of Prisma SD-WAN QoS queues supported per WAN interface?

What is the default action for real-time media applications if link performance is poor?

Previous

Payments We Accept

Your purchase with ExamsVCE is safe and fast. Your products will be available for

10What is the number and structure of Prisma SD-WAN QoS queues supported per WAN interface?
  • 12 queues 4 classes 3 application criteria within each class
  • 16 queues 4 classes 4 application criteria with each class
  • 8 queues 1 priority queue 7 non-priority queues
  • 8 queues 2 classes 4 application criteria within each class
Answer: C

Comprehensive and Detailed ExplanationThe Prisma SD-WAN (ION) QoS engine utilizes a hierarchical queuing structure designed to provide granular control over application performance. Each WAN interface on an ION device supports a total of 16 QoS queues.This 16-queue structure is derived from a matrix of 4 Classes (often referred to as Priority Classes) multiplied by 4 Application Criteria (Traffic Types).24 Priority Classes: The system defines four high-level business priority categories:3Platinum (Highest priority)4GoldSilverBronze (Lowest priority/Best Effort)54 Application Criteria (Sub-queues): Within each of the four priority classes, the system further categorizes traffic into four specific application types to ensure proper handling (e.g., ensuring voice doesn't get stuck behind bulk data even within the same priority level):6Real-Time VideoReal-Time AudioTransactionalBulk7Calculation: 4 Priority Classes × 4 Application Types = 16 Total Queues per interface. This structure allows the scheduler to ensure that a "Platinum" voice call is prioritized over "Platinum" bulk data, and both are prioritized over "Gold" traffic.

.explanation p {

font-size: 16px;

line-height: 25px;

margin-bottom: 14px;

}

Paloalto Networks SD-WAN-Engineer View All Questions

Paloalto Networks SD-WAN-Engineer Summary

Vendor: Paloalto Networks

Product: SD-WAN-Engineer

Update on: Sep 3, 2026

Questions: 86

Price: $52.5  $149.99

Next

A remote branch site is reporting intermittent connectivity to the Data Center.

By default, how many days will Prisma SD-WAN VPNs stay operational before the keys expire...

Previous

Payments We Accept

Your purchase with ExamsVCE is safe and fast. Your products will be available for immediate download after your payment has been received.

The ExamsVCE website is protected by 256-bit SSL fro

Want the full bank of 50 questions for Palo Alto Networks Certified SD-WAN Engineer? See all practice exams.