SD-WAN-Engineer Sample Questions & Answers
Revolves around two tied leaders: planning device selection and bandwidth, and deploying Prisma SD-WAN with configuration templates, plus device and controller monitoring with alerts, Prisma Access and ADEM integration, and troubleshooting connectivity and routing.
Launch the full SD-WAN-Engineer simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Planning and Design · Data Center and Branch Configuration
A consultant is planning a Data Center Interconnect (DCI) topology using Prisma SD-WAN. The customer has two active data centers (DC-A and DC-B) and wants all branch offices to reach applications in either data center dynamically, while DC-to-DC traffic must never transit a branch office. How should the topology be designed?
Show answer & explanation
Correct answer: D
Branch IONs treat each underlay and Standard VPN as a separate routing domain and do not advertise routes learned from one domain into another, so a branch never dynamically becomes a transit point. Branches build Secure Fabric VPNs to the data centers. From ION 6.5.1, DC-to-DC Secure Fabric Links can be created under Data Centers > Overlay Connections, and prefixes learned on inter-DC VPNs are not redistributed further, which prevents loops. There is no 'Transit' toggle on branch sites.
- Question 2Intermediate
Planning and Design · Security and High Availability Planning
Review the following scenario: An organization requires encryption for all WAN traffic but wants to minimize overhead on high-latency satellite links. They are considering Prisma SD-WAN's secure fabric. Which statement correctly describes the encryption handling in the App-Fabric?
Show answer & explanation
Correct answer: A
Secure Fabric tunnels between IONs are always IPsec-encrypted with AES-256-GCM, AES-256-CBC, AES-128-GCM or AES-128-CBC; the controller picks the best common cipher. They do not use IKE. The controller sends three encrypted shared secrets (each valid for one day), the endpoints exchange nonces and derive tunnel-specific session keys, and the keys are renegotiated every hour without the controller (tunnels survive up to 3 days without it). IKEv1/IKEv2 apply only to Standard VPNs, and encryption cannot be turned off per circuit.
- Question 3Advanced
Planning and Design · Policy Design and Management
Case Study: TechGlobal Inc.
TechGlobal is deploying Prisma SD-WAN to 500 retail locations. Each location has:
- 1x MPLS Circuit (Private)
- 1x Business Broadband (Public)
- 1x LTE Backup (Public)
Requirements:
- POS traffic must prefer MPLS but fail over to Broadband if MPLS jitter > 20ms.
- Guest Wi-Fi must use Broadband only, never MPLS.
- Corporate Data must use all available bandwidth on both MPLS and Broadband active-active.
To meet Requirement 2 (Guest Wi-Fi), which configuration strategy is most appropriate?
Show answer & explanation
Correct answer: D
A path policy rule can use only the paths it lists: Active paths (load-shared while SLA-compliant), Backup paths and L3 Failure paths, each an overlay plus a circuit category. If the guest rule lists only the public Broadband and LTE circuit categories, guest traffic can never be placed on MPLS. Listing MPLS as a Backup path would allow it, and a security rule is not the intended path-steering control.
- Question 4Beginner
Deployment and Configuration · Prisma SD-WAN Deployment
A customer is preparing to deploy 100 ION devices using Zero Touch Provisioning (ZTP). They have created the site configurations in the portal. When the installer connects the ION device to the internet at the branch, what is the prerequisite for the device to successfully contact the ZTP controller?
Show answer & explanation
Correct answer: D
Per the Prisma SD-WAN Administrator's Guide (Connect the ION Device), the ION controller port is DHCP-enabled by default and must be connected to a subnet with internet access; models without a dedicated controller port use port 1 or port 2 on a DHCP-enabled network. The device then resolves and connects to the controller (controller.cgnx.net / locator.cgnx.net over TCP 443), changes from Offline to Online, and can be claimed and assigned to its site, after which the controller pushes the site configuration. A static IP (set from the AUX console) is needed only when the circuit has no DHCP; there is no claim key and no MPLS-first requirement.
- Question 5Intermediate
Deployment and Configuration · Site-Specific Settings and Templates
In a template-based deployment, an administrator needs to configure unique LAN IP subnets for 50 different branch sites using a single configuration template. Which feature should be used to achieve this differentiation without creating 50 separate configuration files?
Show answer & explanation
Correct answer: D
Prisma SD-WAN site configuration templates are Jinja blueprints. Values that differ per site, such as LAN subnets, are turned into variables with 'Make Variable' and rendered as {{ variable_name }}; each site's value is supplied in the CSV site data file (or entered manually) when the sites are deployed, so one template serves all 50 sites. Device shells only pre-stage a device configuration before the hardware arrives, 'Site Overrides' are not a Prisma SD-WAN template feature, and dynamic routing does not assign LAN subnets.
- Question 6Advanced
Deployment and Configuration · Routing Protocol Configuration
An engineer is configuring BGP on an ION device to peer with a core switch at a branch site. The requirement is to advertise the SD-WAN overlay subnets to the switch but filter out any prefixes smaller than /30. Which configuration element is required to control these advertisements?
Show answer & explanation
Correct answer: C
Prisma SD-WAN has no 'Redistribution Profile' (that is a PAN-OS object). Routes advertised to an ION BGP peer are filtered with a route map: its entries match a Prefix List (or IP Community List, AS Path List, IP Next Hop) with Permit/Deny, and the map is selected as the peer's Route Map Out on the Prefix Advertisement tab. The prefix list can carry length qualifiers (the ION routing configuration shows entries such as 'permit 10.10.10.0/24 ge 28 le 30'). After changing an associated prefix list, soft-reset the peer. Interface ACLs, a 'Global Routing Table Policy' or a peer password do not filter BGP advertisements.
- Question 7Intermediate
Deployment and Configuration · VRF Implementation
A customer requires network segmentation for their Corporate, Guest, and IoT traffic. Each segment must maintain a separate routing table and cannot communicate with others unless explicitly allowed via a firewall. Which construct should be implemented on the ION devices?
Show answer & explanation
Correct answer: A
VRF (Virtual Routing and Forwarding) allows multiple instances of a routing table to exist in a router and work simultaneously. This is the standard method for isolating traffic (segmentation) at Layer 3, ensuring Corporate, Guest, and IoT routes are kept separate.
- Question 8IntermediateSelect 2
Deployment and Configuration · Site-Specific Settings and Templates
Which TWO configuration steps are required to enable an ION device to act as a DHCP relay for a branch LAN subnet? (Select TWO)
Show answer & explanation
Correct answers: B, C
DHCP relay is an interface-level setting on a branch ION. In the DHCP Relay section of the interface that serves the subnet (a LAN port, the controller port, or a sub-interface with a static IP) you add the DHCP Server IP addresses (up to 16), optionally choose the source interface used to reach them (the controller port by default) and optionally enable Option 82. The ION then forwards client broadcasts to the servers as unicast. No NAT rule or dedicated static route is inherently required, although the source interface must be able to reach the servers.
DHCP relay is an interface-level setting on a branch ION. In the DHCP Relay section of the interface that serves the subnet (a LAN port, the controller port, or a sub-interface with a static IP) you add the DHCP Server IP addresses (up to 16), optionally choose the source interface used to reach them (the controller port by default) and optionally enable Option 82. The ION then forwards client broadcasts to the servers as unicast. No NAT rule or dedicated static route is inherently required, although the source interface must be able to reach the servers.
- Question 9Beginner
Deployment and Configuration · Routing Protocol Configuration
When configuring OSPF on a branch ION device to peer with a local layer 3 switch, the engineer notices that routes are not being exchanged. The ION is configured as an Area 0 router. The switch logs show 'Mismatch Area ID'. What is the most likely cause?
Show answer & explanation
Correct answer: B
OSPF adjacencies require matching Area IDs. If the ION is in Area 0 (Backbone) and the switch expects Area 1, the adjacency will fail with an area mismatch error.
- Question 10Intermediate
Deployment and Configuration · Site-Specific Settings and Templates
True or False: In Prisma SD-WAN, a 'Site Profile' defines the physical circuit characteristics (like bandwidth and carrier), while the 'Device Profile' defines the interface IP addresses.
Show answer & explanation
Correct answer: B
False. Prisma SD-WAN has no 'Site Profile' and 'Device Profile' with these roles. Circuits (name, ISP, Link Up/Link Down bandwidth used for QoS shaping, circuit category/label, cost, LQM and BW monitoring) are defined per site under Branch Sites/Data Centers > Configuration > Connectivity and Circuits, while interface IP addressing is configured on the ION device itself (ION Devices > Configure the device > Interfaces), where each WAN port is tied to a site circuit through its circuit label.
Ready for the real thing?
The full SD-WAN-Engineer simulator has every exam-style question, timed mode, and instant scoring.