Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

SD-WAN-Engineer Exam Dumps - Paloalto Networks Network Security Administrator Questions and Answers

Question # 14

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

Options:

A.

The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.

B.

The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.

C.

The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

D.

The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.

Buy Now
Question # 15

What is the basis for calculating the minimum bandwidth subscription required for branch IONs?

Options:

A.

Maximum throughput supported by the ION hardware deployed at data center locations

B.

Amount of traffic which will traverse the SD-WAN secure fabric

C.

Maximum traffic (ingress and egress) passing through the ION device

D.

ISP circuit capacity at the branch location

Buy Now
Question # 16

Return traffic for an application from the branch is being dropped on the branch ION. Application traffic arrives via SD-WAN internet overlay at the branch, and path policy for the application at the branch has the following settings:

Active = MPLS Overlay

Backup = Prisma Access on internet

Which branch configuration is the probable cause of this behavior?

Options:

A.

It has Prisma Access tunnel over MPLS circuit but not on the internet circuit.

B.

It has one MPLS and one internet circuit.

C.

It has two internet circuits and no MPLS circuit.

D.

It has no MPLS circuit, and the Prisma Access tunnel is down.

Buy Now
Question # 17

Which condition, when configured within a performance policy, is a trigger for generating an incident related to application performance or path degradation?

Options:

A.

Violation of defined service-level agreement (SLA) thresholds for application performance or link quality.

B.

Exceeding the configured threshold for total concurrent flows in the ION device, resulting in a SYSTEM_CONCURRENT_FLOW_THRESHOLD_EXCEEDED incident.

C.

Loss of a BGP peering session on a data center ION device, leading to potential routing instability.

D.

Physical WAN interface transitioning from an “up” to a “down” state, resulting in a NETWORK_ANYNETLINK_DOWN event.

Buy Now
Question # 18

An administrator wants to configure a Path Policy that routes all "Guest Wi-Fi" traffic directly to the internet using the local broadband interface, bypassing all VPN tunnels.

Which Service & DC Group setting should be selected in the policy rule to achieve this "Direct Internet Access" (DIA) behavior?

Options:

A.

 Standard VPN

B.

 Direct

C.

 Any-Private

D.

 Default-Cluster

Buy Now
Question # 19

An organization has provided the following technical requirements and details:

    High availability (HA) at all data center and branch locations

    Two geographically separate main data center locations

    One small data center location that contains local users and applications requiring policies

    50 branch locations

    ISP capacities for all branch locations but no accurate measurement of the actual bandwidth consumption

Based on Palo Alto Networks best practices and recommendations, which two licensing options will meet the customer objectives? (Choose two.)

Options:

A.

Six data center subscriptions

B.

Aggregate bandwidth subscription

C.

Four data center subscriptions

D.

Branch subscription per site

Buy Now
Question # 20

When allocating Aggregate Bandwidth for a Prisma Access "Remote Network" deployment (connecting 50 branch sites), how is the bandwidth license enforced?

Options:

A.

 Each branch site is hard-capped at the specific bandwidth limit defined in its individual IPSec tunnel configuration.

B.

 The bandwidth is shared as a pool across all sites in a specific Compute Location (Region); individual sites can burst up to the available pool capacity.

C.

 The bandwidth is allocated per device serial number and cannot be shared.

D.

 The bandwidth license is only checked once during the initial onboarding; there is no ongoing enforcement.

Buy Now
Question # 21

An organization has created a custom internal application definition for "Inventory_App" on the Prisma SD-WAN controller based on its destination IP address and port (L3/L4 rule). The application server IP has just changed.

After updating the custom application definition on the controller, how is this change propagated to the branch ION devices?

Options:

A.

 The administrator must manually "Push" the policy to all sites.

B.

 The administrator must reboot the ION devices for the new object to load.

C.

 The controller automatically pushes the updated Application Definition (App-Def) to all ION devices immediately.

D.

 The change will only take effect after the daily "App-ID" scheduled update.

Buy Now
Question # 22

A network administrator is viewing the Flow Browser to investigate a report that a specific user cannot access an internal web server. The flow entry for this traffic shows the "Flow State" as "INIT" and it remains in that state until it times out.

What does the "INIT" state indicate about the traffic flow?

Options:

A.

 The TCP 3-way handshake was completed successfully, and data is being transferred.

B.

 The ION device received the SYN packet from the client but never saw a SYN-ACK response from the server.

C.

 The flow was denied by a Zone-Based Firewall policy on the ION.

D.

 The traffic is being buffered while the ION waits for a dynamic VPN tunnel to establish.

Buy Now
Question # 23

When identifying devices for IoT classification purposes, which two methods does Prisma SD-WAN use to discover devices that are not directly connected to the branch ION? (Choose two.)

Options:

A.

LLDP

B.

CDP

C.

SNMP

D.

Syslog

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Feb 20, 2026
Questions: 86
SD-WAN-Engineer pdf

SD-WAN-Engineer PDF

$25.5  $84.99
SD-WAN-Engineer Engine

SD-WAN-Engineer Testing Engine

$28.5  $94.99
SD-WAN-Engineer PDF + Engine

SD-WAN-Engineer PDF + Testing Engine

$40.5  $134.99