New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: Board70

SD-WAN-Engineer Exam Dumps - Paloalto Networks Network Security Administrator Questions and Answers

Question # 4

An organization has created a custom internal application definition for "Inventory_App" on the Prisma SD-WAN controller based on its destination IP address and port (L3/L4 rule). The application server IP has just changed.

After updating the custom application definition on the controller, how is this change propagated to the branch ION devices?

Options:

A.

 The administrator must manually "Push" the policy to all sites.

B.

 The administrator must reboot the ION devices for the new object to load.

C.

 The controller automatically pushes the updated Application Definition (App-Def) to all ION devices immediately.

D.

 The change will only take effect after the daily "App-ID" scheduled update.

Buy Now
Question # 5

A network administrator is viewing the Flow Browser to investigate a report that a specific user cannot access an internal web server. The flow entry for this traffic shows the "Flow State" as "INIT" and it remains in that state until it times out.

What does the "INIT" state indicate about the traffic flow?

Options:

A.

 The TCP 3-way handshake was completed successfully, and data is being transferred.

B.

 The ION device received the SYN packet from the client but never saw a SYN-ACK response from the server.

C.

 The flow was denied by a Zone-Based Firewall policy on the ION.

D.

 The traffic is being buffered while the ION waits for a dynamic VPN tunnel to establish.

Buy Now
Question # 6

What is the primary function of the "CloudBlade" platform in a Prisma SD-WAN deployment when integrating with third-party services or Prisma Access?

Options:

A.

It acts as a physical line card on the ION device to provide additional 10Gbps interfaces.

B.

It is a containerized application running on the ION device that performs Deep Packet Inspection (DPI).

C.

It is a cloud-based API integration layer that automates the configuration of the ION devices and the remote service.

D.

It is a monitoring dashboard used exclusively for viewing flow records.

Buy Now
Question # 7

A network installer is attempting to claim a new ION device using the "Claim Code" method. The device is connected to the internet, but the status in the portal remains stuck at "Claimed" and does not transition to "Online". The installer connects a laptop to the LAN port of the ION and can successfully browse the internet, confirming the uplink is active.

What is the most likely cause of the device failing to reach the "Online" state?

Options:

A.

 The device is missing the "Site" assignment in the portal.

B.

 The upstream firewall is blocking outbound TCP port 443 or UDP port 123 (NTP).

C.

 The device has not yet downloaded the latest software image.

D.

 The "Circuit Label" has not been applied to the WAN interface.

Buy Now
Question # 8

During the Zero Touch Provisioning (ZTP) process of a new ION device at a branch site, which interface ports are supported by default to request an IP address via DHCP and reach the Prisma SD-WAN controller for claiming?

Options:

A.

 Only the dedicated Controller port (if available)

B.

 Any LAN or WAN port on the device

C.

 The dedicated Controller port, or Port 1 / Internet 1 if a dedicated port is absent

D.

 Only the USB port via a cellular modem

Buy Now
Question # 9

When allocating Aggregate Bandwidth for a Prisma Access "Remote Network" deployment (connecting 50 branch sites), how is the bandwidth license enforced?

Options:

A.

 Each branch site is hard-capped at the specific bandwidth limit defined in its individual IPSec tunnel configuration.

B.

 The bandwidth is shared as a pool across all sites in a specific Compute Location (Region); individual sites can burst up to the available pool capacity.

C.

 The bandwidth is allocated per device serial number and cannot be shared.

D.

 The bandwidth license is only checked once during the initial onboarding; there is no ongoing enforcement.

Buy Now
Question # 10

Which component of the Prisma SD-WAN solution is responsible for the deep application identification (App-ID) and the generation of flow metrics (Network Transfer Time, Server Response Time) at the branch?

Options:

A.

 The CloudBlade container

B.

 The Prisma SD-WAN Controller

C.

 The ION Device Data Plane

D.

 The API Gateway

Buy Now
Question # 11

When integrating Prisma SD-WAN with Prisma Access, what is the specific role of the Service Connection (SC)?

Options:

A.

 It connects the Prisma Access cloud infrastructure back to the customer's Headquarters or Data Center for access to internal private resources (e.g., AD, DNS, Intranet).

B.

 It is the IPSec tunnel that connects a Branch site to the Prisma Access gateway for internet access.

C.

 It is the SSL VPN portal used by mobile users to connect to the network.

D.

 It is the peering link between different Prisma Access regions to optimize global traffic.

Buy Now
Question # 12

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:

A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.

 Both sites must disable NAT and use public IPs on the ION interface.

C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.

 Dynamic VPNs are not supported if both sides are behind NAT.

Buy Now
Question # 13

An administrator needs to ensure that critical VoIP traffic is not dropped even when the branch's primary internet link is fully saturated with bulk file transfers.

Which QoS mechanism does Prisma SD-WAN automatically apply to the "Platinum" priority class to prevent starvation by lower-priority classes?

Options:

A.

 Strict Priority Queuing (SPQ)

B.

 Weighted Round Robin (WRR)

C.

 Hierarchical Token Bucket (HTB) with guaranteed bandwidth

D.

 First-In, First-Out (FIFO)

Buy Now
Exam Code: SD-WAN-Engineer
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Dec 18, 2025
Questions: 52
SD-WAN-Engineer pdf

SD-WAN-Engineer PDF

$25.5  $84.99
SD-WAN-Engineer Engine

SD-WAN-Engineer Testing Engine

$28.5  $94.99
SD-WAN-Engineer PDF + Engine

SD-WAN-Engineer PDF + Testing Engine

$40.5  $134.99