New Year Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Paloalto Networks SD-WAN-Engineer Practice Exam with Questions & Answers | Set: 2

Questions 11

What are two potential causes when a secondary public circuit has been added to the branch site, but the Prisma SD-WAN tunnel is not forming to the data center? (Choose two.)

Options:
A.

Interface role is not selected as “internet.”

B.

Circuit label is missing from interface type.

C.

DNS is not configured.

D.

Interface scope is set to “local.”

Paloalto Networks SD-WAN-Engineer Premium Access
Questions 12

Two branch sites, "Branch-A" and "Branch-B", are both behind active NAT devices (Source NAT) on their local internet circuits.

What requirement must be met for these two branches to successfully establish a direct Dynamic VPN (ION-to-ION) tunnel over the internet?

Options:
A.

 One of the sites must have a Static Public IP (1:1 NAT) to act as the initiator.

B.

 Both sites must disable NAT and use public IPs on the ION interface.

C.

 The ION devices automatically use STUN (Session Traversal Utilities for NAT) to discover their public IPs and negotiate the connection.

D.

 Dynamic VPNs are not supported if both sides are behind NAT.

Questions 13

When using the CloudBlade to integrate Prisma SD-WAN with Prisma Access, how does the system ensure that the IPSec tunnels between the branch ION and the Prisma Access Security Processing Node (SPN) are kept alive during periods of no user traffic?

Options:
A.

 The administrator must configure a continuous ping script on a branch PC.

B.

 The CloudBlade automatically configures the ION to send Synthetic Probes (ICMP/HTTP) across the tunnel.

C.

 The IPSec tunnel uses standard DPD (Dead Peer Detection) and the ION sends keepalives.

D.

 Prisma Access initiates the connection to the branch every 60 seconds.

Questions 14

An administrator is configuring a BGP peer on a Data Center ION to learn routes from the core switch. The goal is to have the ION learn these prefixes and then advertise them to all remote branch sites across the SD-WAN overlay.

Which setting must be configured on the BGP Peer to ensure these learned routes are redistributed into the SD-WAN fabric?

Options:
A.

 Set the "Admin Distance" to 20.

B.

 Enable "Graceful Restart".

C.

 Set the "Scope" to "Global".

D.

 Configure a "Prefix List" to deny all.

Questions 15

Which configuration requirement must be met to allow two branch ION devices to automatically establish a direct Dynamic VPN (branch-to-branch) connection for traffic flow, bypassing the Data Center?

Options:
A.

Both ION devices must be members of the same VPN Cluster.

B.

A static "Gre Tunnel" must be manually configured between the two sites.

C.

The Data Center ION must be offline to trigger the dynamic failover.

D.

The "Standard VPN" path policy must be selected.

Questions 16

An engineer at a managed services provider is updating an application that allows its customers to request firewall changes to also manage SD-WAN. The application will be able to make any approved changes directly to devices via API.

What is a requirement for the application to create SD-WAN interfaces?

Options:
A.

REST API’s “sdwanInterfaceprofiles” parameter on a Panorama device

B.

REST API’s “sdwanInterfaces” parameter on a firewall device

C.

XML API’s “sdwanprofiles/interfaces” parameter on a Panorama device

D.

XML API’s “InterfaceProfiles/sdwan” parameter on a firewall device

Questions 17

An administrator is configuring an ION 2000 device for a deployment where high availability is required, but the site has only a single internet circuit. The administrator configures a Bypass Pair (Fail-to-Wire) on ports 1 and 2 connecting the ISP modem to the legacy firewall.

If the ION device loses power, what is the resulting behavior of the traffic flowing through this Bypass Pair?

Options:
A.

 Traffic is blocked to prevent uninspected packets from entering the network (Fail-to-Block).

B.

 The internal relay closes, physically bridging Port 1 and Port 2, allowing traffic to flow transparently between the modem and firewall.

C.

 The device reboots into "Safe Mode" and acts as a Layer 2 switch.

D.

 Traffic is rerouted to the LTE modem automatically.

Exam Code: SD-WAN-Engineer
Certification Provider: Paloalto Networks
Exam Name: Palo Alto Networks SD-WAN Engineer
Last Update: Jan 17, 2026
Questions: 57