Free Palo Alto Networks SD-WAN Engineer practice questions

10 free Palo Alto Networks SD-WAN Engineer practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 70 questions. Work through them, then open each answer to check your reasoning.

Question 1

When identifying devices for IoT classification purposes, which two methods does Prisma SD-WAN use to discover devices that are not directly connected to the branch ION? (Choose two.)

  1. LLDP
  2. CDP
  3. SNMP
  4. Syslog
Show answer and explanation

Correct answer: A, C

A. LLDP C. SNMP Prisma SD-WAN uses LLDP (Link Layer Discovery Protocol) and SNMP (Simple Network Management Protocol) to discover devices that are not directly connected to the branch ION. LLDP operates at Layer 2 to identify neighboring devices and their capabilities, while SNMP queries devices for detailed inventory and configuration information. CDP is Cisc-roprietary and not universally supported across multi-vendor environments, and Syslog is a logging mechanism rather than a discovery protocol.

Why the other options are wrong

  • B. CDP is a Cisco-proprietary protocol and is not a standard discovery method used by Prisma SD-WAN for device classification.
  • D. Syslog is a logging and event reporting mechanism, not a device discovery protocol.

Question 2

A network administrator is troubleshooting a critical SaaS application, “SuperSaaSApp”, that is experiencing connectivity issues. Initially, the configured active and backup paths for the application were reported as completely down at Layer 3. The Prisma SD-WAN system attempted to route traffic for the application over an L3 failure path that was explicitly configured as a Standard VPN to Prisma Access.

However, users are still reporting a complete outage for the application and monitoring tools show application flows being dropped when attempting to use the Standard VPN L3 failure path, even though the tunnel itself appears to be up. The administrator suspects a policy misconfiguration related to how the Standard VPN path interacts with destination groups.

What is the most likely reason for flows being dropped when attempting to use the Standard VPN L3 failure path?

  1. The “Move Flows Forced” action was not enabled in the performance policy for “SuperSaaSApp”, preventing the system from actively shifting traffic to the L3 failure path.
  2. The path policy rule for “SuperSaaSApp” has the “Required” checkbox selected for its Service & DC Group, but no direct paths were configured alongside it, creating a conflict.
  3. The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.
  4. The Standard VPN in the path policy was not configured to “Minimize Cellular Usage”, leading to the depletion of metered data and subsequent flow drops.
Show answer and explanation

Correct answer: C. The path policy rule explicitly designates a Standard VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped.

VPN as the L3 failure path, but it does not include a designated Standard Services and DC Group, causing traffic to be dropped. When a Standard VPN is configured as an L3 failure path but no corresponding Standard Services and DC Group is designated in the path policy rule, the system lacks the necessary destination group mapping to properly route and process traffic flows. This configuration gap causes flows to be dropped because the system cannot determine the appropriate service handling for traffic arriving via the Standard VPN path, even though the tunnel itself is operationally up.

Why the other options are wrong

  • A. Move Flows Forced is a performance policy action for active optimization, not a requirement for L3 failure path functionality.
  • B. The Required checkbox on a Service & DC Group works correctly when combined with other configured paths; it does not inherently conflict or cause drops.
  • D. Minimize Cellular Usage is a data consumption setting and would not directly cause flow drops on a Standard VPN path.

Question 3

User-ID integration is configured for a Prisma SD-WAN deployment. Branc- has the user-to-IP mappings available, and User-1 is mapped to IP-1.

To which two use cases can User-ID based zone-based firewall policies be applied? (Choose two.)

  1. User-1 accessing a SaaS application on direct internet and source User-ID based zone-based firewall rules on Branch-1 ION
  2. User-1 accessing a private application within Branch-1, and source User-ID based zone-based firewall rules on Branch-1 ION
  3. User-1 accessing a private application in data center via SD-WAN overlay, and destination User-ID based zone-base firewall rules DC ION
  4. User-1 accessing a private application in Branch-2 via SD-WAN overlay, and destination User-ID based zone-based firewall rules on Branch-2 ION
Show answer and explanation

Correct answer: A, B

A. User-1 accessing a SaaS application on direct internet and source User-ID based zone-based firewall rules on Branch-1 ION B. User-1 accessing a private application within Branch-1, and source User-ID based zone-based firewall rules on Branch-1 ION User-ID based zone-based firewall policies can be applied when the user-to-IP mapping is available at the enforcement point and the source of the traffic originates from that location. User-1 accessing a SaaS application on direct internet from Branch-1 and User-1 accessing a private application within Branch-1 both allow source User-ID based firewall rules to be applied at Branch-1 ION, where the user-to-IP mapping is known. For options C and D, destination-based User-ID policies cannot be reliably applied because the remote ION does not have the user-to-IP mapping information from Branch-1.

Why the other options are wrong

  • C. Destination User-ID based firewall rules at a DC ION cannot be reliably sourced because the datacenter ION lacks the user-to-IP mapping information from the remote branch.
  • D. Destination User-ID based firewall rules at Branch-2 ION cannot be applied because Branch-2 does not have visibility into the user-to-IP mappings from Branch-1.

Question 4

A site has two internet circuits: Circuit A with 500 Mbps capacity and Circuit B with 100 Mbps capacity.

Which path policy configuration will ensure traffic is automatically shifted from a saturated circuit to the circuit with available bandwidth?

  1. Circuit A as an active, Circuit B as a backup
  2. Circuit B as an active, Circuit A as a backup
  3. Both circuits under active path
  4. Circuit B as an L3 failure path
Show answer and explanation

Correct answer: C. Both circuits under active path

Configuring both circuits under active path enables dynamic load balancing where traffic is distributed across both circuits simultaneously. This configuration allows the system to automatically shift traffic to whichever circuit has available bandwidth rather than forcing all traffic onto a single active circuit. When both paths are active, the system continuously monitors utilization and allocates flows to the least saturated path, ensuring optimal use of the combined 600 Mbps capacity.

Why the other options are wrong

  • A. Circuit A as active and Circuit B as backup uses a static failover model that shifts all traffic only when Circuit A completely fails, not when it becomes saturated.
  • B. Circuit B as active and Circuit A as backup would underutilize the larger Circuit A capacity under normal conditions.
  • D. Configuring Circuit B as an L3 failure path does not enable automatic bandwidt-ased shifting and requires complete Layer 3 failure to trigger failover.

Question 5

What is the purpose of Secure Group Tag (SGT) propagation in Prisma SD-WAN?

  1. To integrate with external identity-based security solutions
  2. To manage QoS policies for traffic based on user and application type
  3. To clarify the intent of rules or configuration objects and improve rule organization
  4. To enable or disable SGT settings at the interface level and initiate services like NTP, DHCP, and App Probes
Show answer and explanation

Correct answer: A. To integrate with external identity-based security solutions

Secure Group Tag (SGT) propagation in Prisma SD-WAN enables integration with external identity-based security solutions such as Cisco TrustSec. SGTs carry user and device identity information across the network, allowing external security systems and policies to make access control decisions based on user identity, device posture, and security group membership rather than network location alone.

Why the other options are wrong

  • B. QoS management is handled through quality of service policies and applicatio-ware routing, not through SGT propagation.
  • C. Clarifying rule intent and improving organization is the purpose of comments, descriptions, and naming conventions, not SGT functionality.
  • D. Interface-level settings and service initiation are configured through interface profiles and service configuration objects, not through SGT propagation.

Question 6

Site templates are to be used for the large-scale deployment of 100 Prisma SD-WAN branch sites across different regions.

Which two statements align with the capabilities and best practices for Prisma SD-WAN site templates? (Choose two.)

  1. The use of Jinja conditional statements within a site template is not supported, thereby limiting dynamic customization options.
  2. Mandatory variables for any site template include the site name, ION software version, and at least one ION serial number /device name pair.
  3. Site templates offer the capability to pre-stage device configurations by creating a device shell.
  4. Once a site has been deployed using a template, its configuration can be updated or modified by applying an updated version of the template.
Show answer and explanation

Correct answer: C, D

C. Site templates offer the capability to pre-stage device configurations by creating a device shell. D. Once a site has been deployed using a template, its configuration can be updated or modified by applying an updated version of the template. Prisma SD-WAN site templates support Jinja conditional statements for dynamic customization, enabling flexible and scalable deployments across diverse environments. Templates can pre-stage device configurations by creating a device shell before physical deployment, reducing on-site configuration time. Additionally, site configurations deployed from templates can be updated or modified by applying an updated template version, allowing for ongoing management and remediation across the deployment.

Why the other options are wrong

  • A. Jinja conditional statements are fully supported within site templates, providing powerful dynamic customization capabilities for large-scale deployments.
  • B. While site name is mandatory, ION software version and serial number pairs are not absolute mandatory requirements for template creation; many deployments use device naming variables instead.

Question 7

Network segmentation is required due to overlapping IP address space and M&A scenarios.

Which Prisma SD-WAN feature will achieve the desired segmentation and end-to-end connectivity in this use case?

  1. Virtual Routing and Forwarding (VRF) profiles with proper site bindings to achieve desired isolation across the underlay
  2. Virtual Routing and Forwarding (VRF) profiles with proper site bindings to achieve desired isolation locally and across the secure fabric
  3. Multiple contexts with interface segmentation to achieve desired isolation across the underlay
  4. Multiple virtual routers with interface segmentation to achieve desired isolation across the secure fabric
Show answer and explanation

Correct answer: B. Virtual Routing and Forwarding (VRF) profiles with proper site bindings to achieve desired isolation locally and across the secure fabric

Virtual Routing and Forwarding (VRF) profiles in Prisma SD-WAN provide the necessary isolation to handle overlapping IP address space in M&A scenarios. VRF profiles properly bound to sites achieve isolation both locally within each site and end-to-end across the secure fabric overlay, enabling multiple logical networks with independent routing tables to coexist and communicate securely without IP conflicts.

Why the other options are wrong

  • A. VRF isolation across the underlay alone does not provide end-to-end connectivity across the secure fabric overlay, which is required for this use case.
  • C. Multiple contexts with interface segmentation provides underlay isolation but does not offer the overlay connectivity capabilities needed for end-to-end secure communication.
  • D. Multiple virtual routers are not a primary Prisma SD-WAN feature for this purpose; VRF profiles are the correct mechanism for achieving segmentation with overlay connectivity.

Question 8

Which implementation allows Prisma SD-WAN to improve application performance for organizations facing inconsistent user experiences across branch locations, especially due to varying device types and network conditions, by using Layer 4 and Layer 7 optimization to boost throughput?

  1. Packet duplication
  2. WAN optimization
  3. Forward Error Correction (FEC)
  4. Application acceleration
Show answer and explanation

Correct answer: B. WAN optimization

WAN optimization in Prisma SD-WAN uses Layer 4 and Layer 7 optimization techniques including compression, deduplication, and protocol optimization to improve application throughput and performance across branch locations. It addresses inconsistent user experiences caused by varying device types and network conditions by making more efficient use of available bandwidth.

Why the other options are wrong

  • A. Packet duplication is a technique for improving reliability and latency but does not focus on throughput optimization across varying network conditions.
  • C. Forward Error Correction (FEC) improves reliability by enabling recovery from packet loss but does not provide Layer 4 and Layer 7 optimization for throughput improvement.
  • D. Application acceleration is a related but distinct feature focused on applicatio-pecific performance enhancements, not the comprehensive Layer 4-7 optimization described in the question.

Question 9

Which metrics can be monitored at the individual Prisma SD-WAN ION device level to assess its health and operational performance?

  1. Device software version and interface bandwidth
  2. Device CPU, memory and disk use, interface bandwidth, and errors/discards
  3. Device VPN tunnels and controller reachability status
  4. Device application flow statistics, Autonomous Digital Experience Manager (ADEM) metrics, and site health score
Show answer and explanation

Correct answer: B. Device CPU, memory and disk use, interface bandwidth, and errors/discards

Individual Prisma SD-WAN ION devices can be monitored for CPU, memory, and disk utilization along with interface bandwidth consumption and error/discard statistics. These are the core operational health indicators available at the device level. Device software version is informational rather than a health metric. VPN tunnels and controller reachability are network-level metrics. Application flow statistics and ADEM metrics are applicatio-ayer analytics rather than device health indicators.

Why the other options are wrong

  • A. Software version is configuration information, not an operational health metric.
  • C. VPN tunnel and controller status are network connectivity metrics, not individual device health metrics.
  • D. Application flow statistics and ADEM metrics are higher-layer analytics, not core device health indicators.

Question 10

Where is route leaking configured between VRFs?

  1. VRF definition
  2. BGP peer
  3. Site configuration
  4. VRF profile
Show answer and explanation

Correct answer: D. VRF profile

Route leaking between VRFs in Prisma SD-WAN is configured at the VRF profile level, which defines the routing policies and inter-VRF route distribution settings. The VRF profile is where you specify which routes from one VRF should be visible or propagated to other VRFs. VRF definitions establish the VRF itself but not inter-VRF routing. BGP peers handle external routing protocol communication. Site configuration contains device-level settings but not VRF route leaking policies.

Why the other options are wrong

  • A. VRF definition creates the VRF but does not configure route leaking behavior.
  • B. BGP peers are used for external routing protocol sessions, not intra-VRF route leaking.
  • C. Site configuration manages device-level settings, not VRF-specific route leaking policies.

That was 10 of 70.

The full Palo Alto Networks SD-WAN Engineer pack has all 70 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack