PALO ALTO NETWORKS · SD-WAN

Palo Alto Networks SD-WAN Engineer Exam Practice Questions

70 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 70 questions in this pack

Question 1

When identifying devices for IoT classification purposes, which two methods does Prisma SD-WAN use to discover devices that are not directly connected to the branch ION? (Choose two.)

  1. LLDP
  2. CDP
  3. SNMP
  4. Syslog
Show answer and explanation

Correct answer: A, C

A. LLDP C. SNMP Prisma SD-WAN uses LLDP (Link Layer Discovery Protocol) and SNMP (Simple Network Management Protocol) to discover devices that are not directly connected to the branch ION. LLDP operates at Layer 2 to identify neighboring devices and their capabilities, while SNMP queries devices for detailed inventory and configuration information. CDP is Cisco- proprietary and not universally supported across multi-vendor environments, and Syslog is a logging mechanism rather than a discovery protocol.

Why the other options are wrong

  • B. CDP is a Cisco-proprietary protocol and is not a standard discovery method used by Prisma SD-WAN for device classification.
  • D. Syslog is a logging and event reporting mechanism, not a device discovery protocol.

Question 2

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

  1. The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.
  2. The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.
  3. The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.
  4. The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.
Show answer and explanation

Correct answer: C. The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped. When a Standard VPN is configured as an L3 failure path but no corresponding Standard Services and DC Group is designated in the path policy rule, the system lacks the necessary destination group mapping to properly route and process traffic flows. This configuration gap causes flows to be dropped because the system cannot determine the appropriate service handling for traffic arriving via the Standard VPN path, even though the tunnel itself is operationally up.

Why the other options are wrong

  • A. Move Flows Forced is a performance policy action for active optimization, not a requirement for L3 failure path functionality.
  • B. The Required checkbox on a Service & DC Group works correctly when combined with other configured paths; it does not inherently conflict or cause drops.
  • D. Minimize Cellular Usage is a data consumption setting and would not directly cause flow drops on a Standard VPN path.

Question 3

User-ID integration is configured for a Prisma SD-WAN deployment. Branch- 1 has the user-to-IP mappings available, and User-1 is mapped to IP-1.

To which two use cases can User-ID based zone-based firewall policies be applied? (Choose two.)

  1. User-1 accessing a SaaS application on direct internet and source User-ID based zone-based firewall rules on Branch-1 ION
  2. User-1 accessing a private application within Branch-1, and source User-ID based zone-based firewall rules on Branch-1 ION
  3. User-1 accessing a private application in data center via SD-WAN overlay, and destination User-ID based zone-base firewall rules DC ION
  4. User-1 accessing a private application in Branch-2 via SD-WAN overlay, and destination User-ID based zone-based firewall rules on Branch-2 ION
Show answer and explanation

Correct answer: A, B

A. User-1 accessing a SaaS application on direct internet and source User-ID based zone-based firewall rules on Branch-1 ION B. User-1 accessing a private application within Branch-1, and source User-ID based zone-based firewall rules on Branch-1 ION User-ID based zone-based firewall policies can be applied when the user-to-IP mapping is available at the enforcement point and the source of the traffic originates from that location. User-1 accessing a SaaS application on direct internet from Branch-1 and User-1 accessing a private application within Branch-1 both allow source User-ID based firewall rules to be applied at Branch-1 ION, where the user-to-IP mapping is known. For options C and D, destination-based User-ID policies cannot be reliably applied because the remote ION does not have the user-to-IP mapping information from Branch-1.

Why the other options are wrong

  • C. Destination User-ID based firewall rules at a DC ION cannot be reliably sourced because the datacenter ION lacks the user-to-IP mapping information from the remote branch.
  • D. Destination User-ID based firewall rules at Branch-2 ION cannot be applied because Branch-2 does not have visibility into the user-to-IP mappings from Branch-1.

See all 10 free questions Get the full pack, US$39

70 practice questions for Palo Alto Networks SD-WAN Engineer, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 70 questions mapped to the SD-WAN Engineer exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A failed SD-WAN Engineer attempt costs US$250. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 70 questions

What makes the SD-WAN Engineer exam hard

SD-WAN Engineer is the Prisma SD-WAN exam, the CloudGenix product Palo Alto Networks folded into Prisma SASE, and it replaced the old PCSDWAN-era credential in the 2025 restructure. It reads like a professional services engagement from scoping to steady state, which is exactly the job it was written for, and the whole exam is app-defined SD-WAN with ION devices and a cloud controller rather than PAN-OS SD-WAN on a firewall.

Planning and Design and Deployment and Configuration are 24% each. Planning covers device selection, bandwidth planning, licensing tiers, assessing the existing architecture, data centre and DCI options, branch gateway configuration, HA and interconnectivity, and the five policy types: path, security, QoS, performance and NAT. Deployment covers site-specific settings, configuration templates for data centres and branches, tuning dynamic and static routing, and VRF segmentation. Troubleshooting at 20% goes from site-to-site connectivity, routing and forwarding and application performance to policy problems, data analysis with the co-pilot, and using analytics to optimise configuration. Operations at 18% is device statistics, controller incidents, alerts and audit logs, notifications, WAN Clarity reports, real-time monitoring tools and SASE event handling. Unified SASE at 14% is the integration domain: Prisma SD-WAN with Prisma Access and security policy, ADEM for application performance, Device-ID for IoT, Cloud Identity Engine, and path and security policy by user or group.

About the exam

The Palo Alto Networks Certified SD-WAN Engineer is a Specialist-level certification covering Prisma SD-WAN planning and design, deployment and configuration, operations and monitoring, Unified SASE integration, and troubleshooting. No formal prerequisites; Palo Alto Networks recommends the Prisma SD-WAN: Design and Operation course. Datasheet dated August 2025.

Exam domains

  • Planning and Design: 24%
  • Deployment and Configuration: 24%
  • Operations and Monitoring: 18%
  • Unified SASE: 14%
  • Troubleshooting: 20%

90 minutes, multiple choice and multiple select, US$250 per attempt, in person at Pearson VUE test centres only (no online proctoring), certification valid for two years. Palo Alto Networks does not publish a fixed passing score.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the Palo Alto Networks SD-WAN Engineer pack?

70 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.