View Full Palo Alto Networks SD-WAN-Engineer Exam Dumps and Practice Test Dumps.
Question 21
A newly created Path Policy Stack contains valid rules, but the ION device at a branch does not enforce them. What should the administrator verify first?
- Whether the Path Stack is bound to the site
- Whether DNS caching is disabled
- Whether the branch uses DHCP
- Whether the LAN switch supports IPv6
Correct Answer: 1
Explanation
Path and QoS policy stacks must be bound to a site before their rules become active on the associated ION device. Creating a policy stack alone does not automatically apply it to every branch. Administrators can assign the appropriate stack through the stacked bindings configuration and associate it with the required site. A site can have one Path Stack and one QoS Stack attached at a time. Therefore, when correctly configured rules appear inactive at a branch, verifying the policy-stack binding is an appropriate first troubleshooting step before investigating unrelated LAN or DNS settings.
Question 22
Which statement correctly describes the relationship between a Path Policy Set and a QoS Policy Set in an advanced stack?
- Both perform identical NAT functions
- Path determines traffic engineering, while QoS determines business priority
- QoS selects VPN tunnels, while Path assigns IP addresses
- Both are used exclusively for application discovery
Correct Answer: 2
Explanation
Advanced Path and QoS Stacks separate two important policy functions. Path Policy Sets specify traffic engineering, including how application flows should use available network paths. QoS Policy Sets specify business priority and determine how network resources are prioritized among applications. This separation allows administrators to control where traffic travels independently from how traffic should be prioritized. For example, an organization can use Path policies to steer an application over a preferred WAN path while using QoS policies to assign that application a higher priority class. This provides structured and flexible traffic management.
Question 23
An organization needs to translate internal addresses when traffic leaves a branch through a specific WAN zone. Which Prisma SD-WAN policy should be configured?
- Performance policy
- Path policy
- NAT policy
- QoS policy
Correct Answer: 3
Explanation
A NAT policy is used when Prisma SD-WAN needs to translate source or destination addressing for matching traffic. NAT policy rules can use source and destination zones, prefixes, protocols, and ports as match criteria. Available actions include Source NAT, Destination NAT, Static Source NAT, Static Destination NAT, and No NAT. NAT policies are therefore distinct from Path policies, which determine traffic paths, and QoS policies, which determine application priority. When internal branch addresses must be translated according to traffic direction or specific matching conditions, the NAT policy framework provides the appropriate control.
Question 24
Which priority classes are available for Prisma SD-WAN QoS policy rules?
- Critical, Standard, Low, Background
- Platinum, Gold, Silver, Bronze
- Voice, Video, Data, Default
- High, Medium, Normal, Low
Correct Answer: 2
Explanation
Prisma SD-WAN QoS policy rules provide four priority classes: Platinum, Gold, Silver, and Bronze. Each class contains subqueues associated with traffic categories such as Real Time Video, Real Time Audio, Transactional, and Bulk. This hierarchy allows administrators to classify applications according to business importance and traffic characteristics. The priority class influences the relative allocation of network resources to applications. Administrators can also configure DSCP actions as part of QoS rules. Therefore, when a question asks specifically for the predefined Prisma SD-WAN QoS priority classes, Platinum, Gold, Silver, and Bronze are the applicable choices.
Question 25
An administrator wants to create a policy for an internally developed application that is not included in the standard application catalog. What should be configured?
- Custom application
- NAT zone
- Circuit label
- Device profile
Correct Answer: 1
Explanation
Prisma SD-WAN supports custom applications for enterprise-specific application requirements. ION devices identify application flows using application definitions and fingerprinting techniques, and administrators can configure custom application definitions when the standard catalog does not adequately represent an application. Custom applications can subsequently be referenced in policy rules for path selection, QoS, and security. This is particularly useful for proprietary business applications that use distinctive traffic characteristics. Instead of creating broad IP-based rules for the entire network, a custom application can provide more granular application-aware policy control.
Question 26
What is the main purpose of a Network Context in Prisma SD-WAN policy configuration?
- To segment traffic so different policy rules can be applied to the same application
- To replace all WAN circuits
- To create physical switch VLANs automatically
- To disable application identification
Correct Answer: 1
Explanation
A Network Context provides a way to segment network traffic for policy purposes. It can allow different policy rules to be applied to the same application when the traffic belongs to different logical network contexts. This becomes useful when an organization needs distinct treatment for traffic based on business or network segmentation requirements. Network Context is also an important match attribute in Path and QoS policy rules. Rather than requiring separate application definitions for every situation, administrators can use network context information to apply different traffic-engineering or priority behavior to the same application.
Question 27
A path policy uses Best Path Selection instead of SLA Compliant Path. Which two general selection approaches are available under Best Path Policy?
- LQM-based and Probe-based
- DNS-based and DHCP-based
- NAT-based and QoS-based
- TCP-only and UDP-only
Correct Answer: 1
Explanation
Prisma SD-WAN supports Best Path Selection using either an LQM-based or Probe-based approach. LQM, or Link Quality Metrics, uses measurements such as latency, packet loss, and jitter to evaluate path quality. Probe-based selection uses configured probes to assess network behavior through measurements such as ICMP, DNS, or HTTP/S performance. This differs from SLA Compliant Path selection, where paths are evaluated against defined SLA thresholds. Understanding the distinction is important because Best Path Selection focuses on selecting the best available candidate according to the chosen measurement method.
Question 28
A QoS rule should preserve the existing DSCP value instead of changing it. Which DSCP action should be selected?
- Mark
- Remark
- No Action
- Rewrite All
Correct Answer: 3
Explanation
The No Action option leaves the existing DSCP marking unchanged. Prisma SD-WAN QoS policies can alternatively use Mark/Remark to assign a specified DSCP value to matching traffic. DSCP marking can therefore be used when the organization needs to modify packet classification, while No Action is appropriate when existing markings should remain intact. This distinction is important in environments where another network device may already have applied appropriate DSCP markings. Selecting No Action avoids unnecessarily rewriting those values while still allowing the QoS rule to classify and prioritize the application according to its configured policy.
Question 29
Which statement about an advanced Path Stack is correct?
- It can contain only one policy set
- It contains Path Policy Sets evaluated in stack order
- It is used only for NAT translation
- It cannot be attached to a site
Correct Answer: 2
Explanation
An advanced Path Stack is a collection of Path Policy Sets arranged in an evaluation order. The policy sets are evaluated from left to right, with the left-most policy set having the highest priority. An advanced stack can accommodate multiple policy sets, allowing organizations to organize policies by business requirement, geography, application group, or another logical distinction. Only one Path Stack can be attached to a site at a given time. This design provides modular policy management while allowing a site to inherit multiple ordered policy sets through a single stack binding.
Question 30
A performance policy administrator wants to evaluate whether an application meets a defined SLA using application behavior rather than only link measurements. Which metric category is relevant?
- Application metrics
- Hardware serial numbers
- Interface descriptions
- NAT pool addresses
Correct Answer: 1
Explanation
Performance Policy can use application metrics in addition to link-quality measurements. Application metrics include measurements such as Application RTT and initialization failure percentage, which provide information about application behavior and user-facing performance. Link-quality metrics such as latency, loss, and jitter describe network conditions, while application metrics help determine whether those conditions are affecting the application itself. Prisma SD-WAN Performance Policy combines these measurements to support Application and Network SLA enforcement. This distinction allows administrators to evaluate performance from both the network and application perspectives instead of relying solely on link statistics.
Question 31
An administrator creates a very specific Performance Policy rule but places a broad rule above it. What is the likely concern?
- The specific rule may not be matched as intended
- The ION device automatically deletes both rules
- The broad rule becomes a NAT rule
- Performance policies stop collecting metrics
Correct Answer: 1
Explanation
Performance Policy uses explicit rule ordering, so administrators should place more specific rules above less specific rules. A broad rule positioned earlier can match traffic before the more specific rule receives an opportunity to apply its intended action. Palo Alto Networks recommends organizing specific rules toward the top of the policy set and less-specific rules toward the bottom. This principle is important when configuring application-specific SLA requirements, path filters, or data-center group conditions. Correct ordering ensures that the intended policy is selected rather than being unintentionally bypassed by a broader earlier rule.
Question 32
Which overlay option can be selected when defining a Prisma SD-WAN path?
- Direct
- Ethernet-only
- MPLS-only
- Wireless-only
Correct Answer: 1
Explanation
Prisma SD-WAN path policy rules support several overlay choices, including Direct, Prisma SD-WAN VPN, and Standard VPN. Direct represents forwarding without using a Prisma SD-WAN VPN overlay, while the VPN options provide overlay-based connectivity according to the configured architecture. The overlay selection is combined with circuit-category information when defining paths. An administrator cannot repeat the same overlay and circuit-category combination within one policy rule. Understanding the available overlay choices is important when constructing path policies because the overlay determines how the selected traffic is transported across the WAN infrastructure.
Question 33
A branch has a Path Stack with correct rules, but another branch should use a different Path Stack. What should the administrator configure?
- Separate site-to-stack bindings
- A new DNS server
- A different application signature
- A second management browser
Correct Answer: 1
Explanation
Prisma SD-WAN allows Path Stacks to be assigned to sites through policy bindings. Different sites can therefore receive different Path Stack configurations according to their requirements. For example, one geographic region may need different WAN path preferences from another region even though both use the same applications. The administrator can select the appropriate stack for each site rather than modifying the same policy for every location. This site-based binding mechanism provides flexibility while maintaining centralized policy management. The important requirement is that the relevant stack must be bound to the site for its rules to become active.
Question 34
Which metric combination belongs to Link Quality Metrics used by Prisma SD-WAN Performance Policy?
- Latency, loss, and jitter
- CPU, memory, and disk
- DNS name, hostname, and MAC
- Username, group, and role
Correct Answer: 1
Explanation
Prisma SD-WAN Performance Policy uses Link Quality Metrics such as latency, packet loss, and jitter to evaluate network performance. These measurements describe characteristics of the network path and can be used as SLA criteria. Performance Policy can also incorporate application metrics such as Application RTT and initialization failure percentage, allowing network and application behavior to be evaluated together. System Health rules can address device and circuit resources separately. Therefore, latency, loss, and jitter are the appropriate measurements when a question specifically refers to Link Quality Metrics in Prisma SD-WAN Performance Policy.
Question 35
An organization wants a policy rule to apply to a particular TCP application and a defined destination prefix. Which Prisma SD-WAN Path Policy capability supports this combination?
- Match criteria
- Device reboot scheduling
- Hardware inventory
- Software licensing
Correct Answer: 1
Explanation
Prisma SD-WAN Path Policy Rules support multiple match criteria that can be combined to identify traffic precisely. Available criteria include network contexts, source and destination prefixes, ports, protocols, Application ID, User or Group ID, and Device ID. This allows an administrator to construct a rule that applies only to traffic matching the required application and destination network conditions. Combining match criteria provides more granular traffic engineering than relying on a single broad rule. Once the traffic matches the rule, the configured path-selection behavior determines how the eligible network paths should be used.
Question 36
What does the Performance Policy action “Move Flows” provide when an application no longer satisfies the configured SLA?
- It can move affected application flows toward a suitable path
- It permanently deletes the application
- It changes the ION hardware model
- It disables all policy stacks
Correct Answer: 1
Explanation
Performance Policy can use the Move Flows action to respond when application or network performance conditions no longer meet configured SLA requirements. The policy framework evaluates relevant metrics and can trigger actions that improve application performance by moving flows to a more suitable path. Performance Policy is designed to provide measurement, enforcement, and alerting for application SLAs. The Move Flows capability therefore connects performance monitoring with traffic remediation. It does not delete applications or disable policy stacks; instead, it provides a mechanism for dynamically responding to degraded application or network conditions.
Question 37
Which NAT action should be selected when the administrator explicitly wants matching traffic to bypass address translation?
- Source NAT
- Destination NAT
- No NAT
- Static Source NAT
Correct Answer: 3
Explanation
The No NAT action explicitly indicates that the matching traffic should not undergo NAT processing under that rule. Prisma SD-WAN NAT policies support No NAT along with Source NAT, Destination NAT, Static Source NAT, and Static Destination NAT. When No NAT is selected, other NAT actions cannot be specified within that same policy rule. This is useful when a broad translation policy exists but particular traffic must retain its original addressing. Administrators can use match criteria such as zones, prefixes, protocols, and ports to identify the traffic that should bypass translation.
Question 38
A QoS administrator wants packets matching a rule to receive a specific DSCP value. Which action should be configured?
- No Action
- Mark/Remark
- Drop
- Reject
Correct Answer: 2
Explanation
The Mark/Remark action allows a Prisma SD-WAN QoS rule to assign a specific DSCP value to matching traffic. DSCP values range from 0 through 63. When a DSCP value is specified and a flow matches the rule in the LAN-to-WAN direction, the packets belonging to that flow can be changed to the configured value. No Action is different because it leaves the existing DSCP marking unchanged. DSCP marking can therefore help communicate traffic-classification information to downstream network devices and support consistent QoS treatment across the network.
Question 39
Which statement best describes the default rules in an advanced Path Stack?
- They provide fallback policy behavior when an explicit rule does not match
- They are used only during device boot
- They automatically create NAT pools
- They disable all application policies
Correct Answer: 1
Explanation
Advanced Path Stacks include default policy behavior for flows that do not match an explicit policy rule. Prisma SD-WAN documentation describes a Default Rule and an Enterprise Default Rule as part of the advanced Path Stack structure. An application flow that does not match an explicit rule can therefore fall through to the appropriate default behavior based on its destination. This prevents unmatched traffic from being left without defined forwarding treatment. Administrators can add more specific policy sets above the default behavior so that important applications or network contexts receive customized traffic-engineering decisions.
Question 40
A company wants application SLA monitoring to consider both latency and application initialization failures. Which Prisma SD-WAN policy framework should be used?
- NAT Policy
- Performance Policy
- Device Management Policy
- Inventory Policy
Correct Answer: 2
Explanation
Performance Policy is designed to measure and enforce application and network SLAs using both network and application performance information. Link-quality metrics can include latency, loss, and jitter, while application metrics can include Application RTT and initialization failure percentage. This combination allows administrators to evaluate whether application performance meets defined requirements and take appropriate policy actions. Performance Policy is therefore more suitable than NAT or device-management policies when the objective is application SLA monitoring and enforcement. It provides a dedicated framework for measurement, actions, visibility, and incident handling around application performance.