Palo Alto Networks · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
Which log file on the ION device provides the most detailed information about WAN interface flapping?
flow.log
controller.log
auth.log
system.log
System logs record interface events and link-state changes.
You notice an ION device is showing as 'Disconnected' in the Controller UI. What is the first step you should take?
Check physical interface status and WAN connectivity
Verifying physical and link layer connectivity is the standard starting point.
Upgrade the device firmware
Reboot the ION device
Delete and recreate the site
When analyzing a PCAP from an ION device, you see 'ICMP Destination Unreachable'. Which policy is most likely causing this?
Security Policy
Security policies are configured to drop traffic and can return ICMP unreachable messages.
NAT Policy
QoS Policy
Path Selection Policy
A specific branch is failing to steer traffic via the preferred ISP despite a defined Path Policy. What is the most likely cause?
Incorrect application identification
If the app is misidentified, the policy engine will not apply the intended path rule.
License expiry
Restart the WAN interface
Controller outage
BGP cost is too high
A branch site reports intermittent application slowness. Which tool in the Prisma SD-WAN ION dashboard is best for viewing real-time latency and jitter metrics per path?
BGP Neighbors
Flow Summary
Path Quality
Path Quality specifically tracks performance metrics for WAN paths.
Security Events
A site has two ISPs. Traffic is only using one. What is the best way to verify if both paths are available?
Ping from the LAN
Review firewall rules
Check Path Quality dashboard
This dashboard shows current latency/loss for all paths.
Check the BGP summary
Want more Troubleshooting practice?
Practice this domainWhich command or interface action is used to verify the current status of the SD-WAN overlay tunnels?
Show tunnels view in the Controller
This interface specifically tracks SD-WAN overlay status.
show routing table
show interface status
ping gateway
A branch office requires local breakout for SaaS traffic. How do you configure the policy to ensure this traffic does not traverse the data center?
Set the VRF to global
Apply a hub-and-spoke routing policy
Configure a destination-based policy with a Local Breakout action
Local breakout action directs traffic to the local WAN interface.
Enable NAT on the WAN interface
You need to ensure that specific branch traffic is encrypted over a public internet link. Which configuration step is mandatory?
Enable Auto-VPN on the WAN interface
Auto-VPN is the primary mechanism for secure site-to-site connectivity.
Manually configure IPsec parameters
Disable firewall policies
Configure a static route to the peer
You are implementing a QoS policy. Why would you configure a 'Shaping' rate on a WAN interface?
To enable load balancing
To increase the circuit bandwidth
To match the physical interface speed
To manage congestion and match the provider's provisioned rate
Shaping aligns egress traffic with the ISP's bandwidth contract.
What is the impact of assigning a site to a specific 'Site Group' in a Prisma SD-WAN policy?
It allows the application of policy sets to multiple sites simultaneously
This is the core purpose of logical grouping.
It creates a new physical network
It forces all sites into the same VRF
It limits the number of peers
You are configuring a path policy to prioritize VoIP traffic. Which specific metric should you leverage to ensure the best call quality when multiple paths are available?
DSCP marking
Bandwidth consumption
Source IP address
Path performance metric
Performance metrics monitor latency, jitter, and loss to steer traffic.
Want more Deployment And Configuration practice?
Practice this domainA network administrator is configuring Prisma SD-WAN to integrate with Prisma Access using the Automated Service Connection. During the onboarding process, which specific parameter must be configured in the ION device's service route to ensure traffic is correctly steered to the Prisma Access Service Infrastructure?
The specific Service Connection object representing the Prisma Access tunnel
The Service Connection object is the abstraction that defines the tunnel properties and routing destination.
The WAN interface MTU size exclusively
The BGP AS number of the remote Prisma Access node
The local controller's IP address
You are deploying Cloud Identity Engine (CIE) to enable identity-based security policies across your SD-WAN and SASE environment. Which configuration step is required to ensure that user identity information is successfully propagated from the enterprise directory to the Prisma Access security nodes?
Link the Prisma Access instance to the CIE instance using the API Key and Tenant ID
The connection between Prisma Access and CIE is established via API credentials for identity mapping.
Configure a local user database on every ION device
Manually map IP addresses to usernames in the Cloud SWG UI
Enable the Identity Service on the Prisma SD-WAN Controller
When onboarding a new branch site into a Unified SASE environment, what is the prerequisite for the branch ION device to establish a tunnel to Prisma Access?
An active Service Connection configuration
The Service Connection is the logical tunnel definition needed to connect to Prisma Access.
A pre-installed certificate on the endpoint host
An on-premise Active Directory server
A physical MPLS line at the branch
In a Unified SASE architecture, an administrator needs to ensure that branch offices prioritize voice traffic while using Prisma Access. Where should the Quality of Service (QoS) policy be defined to ensure consistent application performance?
On the local ION device CLI only
Inside the Prisma Access Security Policy
On the Prisma SD-WAN Controller under Application QoS Policy
The SD-WAN controller manages the traffic shaping and prioritization before it hits the WAN.
Within the Cloud Identity Engine
A customer is experiencing intermittent connectivity to internal applications after enabling Unified SASE. Traffic is being routed through Prisma Access. What is the most likely cause?
The ION device is overheating
MTU size mismatch leading to packet fragmentation
IPSec encapsulation adds overhead, requiring MSS adjustment to prevent fragmentation.
Incorrect DNS server configuration
Identity cache expiration in CIE
An engineer is troubleshooting a scenario where users at a branch office cannot access SaaS applications via Prisma Access. The SD-WAN path is active, but the traffic is not reaching the Cloud SWG. What is the most likely cause related to the Unified SASE policy?
The ION device is missing the latest firmware
The Cloud Identity Engine is not reachable
The Security Policy rule for the branch traffic is set to 'Direct to Internet' instead of 'Service Connection'
Traffic must be explicitly routed to the Service Connection to reach Prisma Access.
The WAN port is set to DHCP
Want more Unified SASE practice?
Practice this domainA branch office uses both MPLS and Broadband. The design requires that business-critical traffic prefers MPLS, failing over to Broadband only if the MPLS path experiences packet loss exceeding 1%. Which metric should the PFR policy utilize?
Bandwidth Utilization
Packet Loss
This is the specific metric to trigger the failover based on the 1% threshold.
Jitter
Round Trip Time (RTT)
A customer requires a granular segmentation strategy where HR, Engineering, and Guest traffic must remain isolated across the SD-WAN fabric. Which configuration construct provides this logical separation?
IPsec Tunnel Groups
Virtual Networks (VNets)
VNets provide end-to-end segmentation across the SD-WAN fabric.
Subnet Masking
VLAN Tagging
A network architect is designing a branch site deployment requiring sub-second failover. Which Prisma SD-WAN component must be configured to prioritize real-time traffic across multiple transport paths based on path quality metrics?
Performance Routing (PFR) Policy
PFR is the mechanism for path selection based on real-time metrics.
Traffic Policing Rule
NAT Control Policy
Access Control List (ACL)
Which Prisma SD-WAN tool is used to monitor real-time health and performance of the SD-WAN fabric during the deployment phase?
SNMP Traps
CLI Debugging
Controller Dashboard
The Controller Dashboard is the primary tool for monitoring fabric health.
Packet Capture (PCAP)
What is the primary function of the CloudBlades platform in the Prisma SD-WAN architecture?
Encryption key rotation
Hardware acceleration
Local breakout management
API-based service integration
CloudBlades facilitates integration with cloud security and infrastructure providers.
During pre-deployment planning for a high-security site, you must implement an identity-aware firewall policy. Where is this configuration mapped in the Prisma SD-WAN Controller?
Identity-Based Security Policy
This is the specific location for identity-driven firewall rules.
NAT Policy
Routing Policy
Quality of Service Policy
Want more Planning And Design practice?
Practice this domainWhen configuring Data Center Interconnect (DCI) between two sites, you notice that routing loops are occurring. What is the most effective way to prevent this in a dual-homed DCI scenario?
Disable OMP on the DCI interface.
Increase the OMP cost on all routes.
Implement Site-of-Origin (SoO) extended communities on the DCI links.
SoO tags are specifically designed to prevent loops in multi-homed BGP/OMP environments.
Configure a static route to the peer site.
Which dashboard component in vManage provides an 'at-a-glance' health score for the entire SD-WAN fabric?
Application Health.
Network Health Dashboard.
This dashboard provides the high-level health score for the overlay.
Control Connections.
Interface Usage.
If a device is stuck in 'In-Progress' during a template push, what is the first troubleshooting step?
Check the Device Tasks in vManage to view the specific error log.
Device Tasks provide the most accurate status of a deployment operation.
Reboot the vManage server.
Perform a factory reset on the device.
Change the vBond address.
In a multi-homed DCI scenario, you are seeing asymmetric routing. What is the most likely cause within the OMP domain?
The TLOC preference is higher on one of the exit points, causing traffic to prefer that path for return.
Inconsistent TLOC preference is a common source of asymmetry in DCI.
The MTU size is different on the DCI interfaces.
The site IDs are identical.
BFD is disabled on one of the links.
Where do you go in vManage to generate a report on historical bandwidth utilization for a specific site?
Configuration > Templates.
Administration > Maintenance.
Tools > Logs.
Monitor > Reports.
This is the central location for generating historical usage reports.
When performing a 'Soft Shutdown' on an HA device, what is the expected behavior?
The device disables all interfaces without notifying the peer.
The device immediately reboots.
The device enters a maintenance mode that clears all routes.
The device gracefully transitions the active state to the standby device.
Soft shutdown is designed to prevent traffic loss by shifting the active role.
Want more Operations And Monitoring practice?
Practice this domainThe SD-WAN-Engineer exam has 200 questions and must be completed in 90 minutes. The passing score is 860/1000.
Scenario-based questions covering exam objectives with detailed answer explanations.
The exam covers 5 domains: Troubleshooting, Deployment And Configuration, Unified SASE, Planning And Design, Operations And Monitoring. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Palo Alto Networks SD-WAN-Engineer exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.