1000 branches are to be deployed on Prisma SD-WAN with the following constraints:
Devices will be shipped in batches directly to the site
Configuration Management Database (CMDB) has all the necessary details for a site deployment
Field tech will be responsible for rack, stack, and cabling of the IONs at each site
Field tech will need to spend minimum amount of time at each branch site to reduce the cost
The NOC operates in shifts and is responsible for remote cutover support
Which method will achieve the mass deployment in shortest possible time?
When configuring SASE connectivity with easy onboarding at a branch, which two options must be selected? (Choose two.)
An organization has created a custom internal application definition for "Inventory_App" on the Prisma SD-WAN controller based on its destination IP address and port (L3/L4 rule). The application server IP has just changed.
After updating the custom application definition on the controller, how is this change propagated to the branch ION devices?
While designing a greenfield Prisma SD-WAN solution for a retailer, the risk management group requires segmentation of the retail network to avoid one large fault domain.
The following data points are provided:
Two data centers and all sites need to access applications in both data centers
1000 retail branches with stores concentrated in multiple metropolitan areas
Data Center 1 and Data Center 2 have different sets of applications that are not replicated
Maintaining application availability is the primary goal
Which action will segment the retail network and reduce regional outages?
When troubleshooting an issue at a site that is running on two cellular links from two carriers, the operations team shared some evidence shown in the graph below:
(SNR Graph showing Carrier-1 in blue dropping to near 0 dB and Carrier-2 in green staying relatively stable between 4.5 dB and 6.5 dB)

For the time duration shown in the graph, what are two inferences about the site’s traffic that can be made? (Choose two.)
In a data center (DC) with two ION devices, all of the remote branch Prisma SD-WAN VPNs are active only on DC ION-1.
Why are no VPNs active on DC ION-2?
An administrator has configured a Zone-Based Firewall (ZBFW) policy on a branch ION. They created a rule to "Allow" traffic from the "Guest" zone to the "Internet" zone. However, users in the "Guest" zone are reporting they cannot reach a specific public website, and the Flow Browser shows the flow state as "REJECT".
What is the most likely reason for this specific rejection, assuming the "Allow" rule is correctly placed at the top of the list?
When integrating Prisma SD-WAN with Prisma Access, what is the specific role of the Service Connection (SC)?
What does Prisma SD-WAN use for monitoring and operations to deliver flow data and application visibility?
A customer wants to deploy Prisma SD-WAN ION devices at small home offices that use consumer-grade broadband routers. These routers typically use Symmetric NAT and do not allow static port forwarding.
Which standard mechanism does Prisma SD-WAN utilize to successfully establish direct Branch-to-Branch (Dynamic) VPN tunnels through these Symmetric NAT devices?
TESTED 01 Mar 2026