Designing Cisco Enterprise Networks Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 224 questions. Use the simulator for timed and flashcard mode.

Try Simulator

500-490 Sample Questions

  1. Question 1

    Q1

    During the Defend phase for a Cisco ISE deployment, a competitor claims their NAC solution offers simpler licensing and is 'good enough' for basic guest and BYOD. The customer is concerned about the perceived complexity and cost of ISE. Which argument most effectively defends the value of ISE in an enterprise environment?

    Show answer & explanation

    Correct answer: C

    The most effective defense is to elevate the conversation beyond a simple NAC feature comparison. While TCO and scalability are valid points, the core value of ISE lies in its role as a central policy engine for the entire security architecture. Highlighting its integration with SD-Access (TrustSec) and the broader security ecosystem via pxGrid demonstrates that ISE is a strategic investment that enables advanced security capabilities like zero-trust and micro-segmentation, which a basic NAC solution cannot provide.

  2. Question 2

    Q2

    A financial services client requires a highly resilient SD-WAN design for their data centers. They have two data centers, each with dual internet circuits from different providers. The primary business requirement is to ensure that critical trading application traffic is never dropped and maintains path quality, even during a single circuit failure at either data center. Which design approach best meets this requirement?

    Show answer & explanation

    Correct answer: C

    A dual-region design provides the highest level of resiliency. By placing each data center in its own region, you create independent failure domains for the data plane and control plane within each region. This ensures that a failure event in one data center (or its associated region) does not impact the other. Centralized policies can then be crafted to steer traffic to the preferred regional hub based on SLA, with seamless failover to the secondary region's hub if the primary becomes unreachable or path quality degrades. This architecture isolates failures and provides robust business continuity.

  3. Question 3

    Q3Multiple answers

    A prospective customer is evaluating Cisco SD-Access against a solution from a competitor that uses a controller-based overlay but relies on traditional VLANs and ACLs for segmentation. The customer believes the competitor's approach is simpler to implement. Which two points should a field engineer emphasize to defend the superiority of the SD-Access segmentation model? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    This is a core value proposition. SGTs are based on identity and role, not network location. This means a single policy can be created (e.g., 'IoT devices cannot talk to Finance Servers') and it will be enforced everywhere in the fabric without needing to update hundreds of location-specific ACLs.

    This addresses the customer's concern about simplicity. While the underlying technology is more advanced, the operational management is far simpler. A visual policy matrix in a central controller is much easier to understand, manage, and audit than spreadsheets of disparate ACLs applied to various interfaces across the network.

  4. Question 4

    Q4

    A university is designing a large-scale SD-Access network to support students, faculty, staff, and IoT devices across a multi-building campus. They need to ensure that the control plane remains stable and that endpoint registration/de-registration events do not overwhelm the LISP Map-Server. Which design choice is critical for achieving this goal?

    Show answer & explanation

    Correct answer: D

    In a large-scale, dynamic environment like a university campus, endpoints connect and disconnect frequently. LISP EID-Notify messages allow an Edge node to immediately inform the Control Plane node (Map-Server) when an endpoint disconnects. This prevents the Map-Server from having to wait for the registration timer to expire, purging the stale entry quickly and keeping the database clean and efficient. Properly tuning the registration interval is also important, but EID-Notify is the key mechanism for handling dynamic endpoint churn at scale.

  5. Question 5

    Q5

    During a demonstration of Cisco SD-WAN, a customer asks to see how the solution can guarantee performance for their critical SaaS applications like Microsoft 365 and Salesforce, which are accessed directly from branch offices. Which vManage feature is the most direct and effective way to demonstrate this capability?

    Show answer & explanation

    Correct answer: C

    Cloud OnRamp for SaaS is the specific feature designed for this exact use case. It moves beyond simple path selection based on latency/jitter. It continuously measures the performance of all possible paths from each branch to the SaaS provider's front door and calculates a Quality of Experience (vQoE) score. Demonstrating this feature shows an intelligent, automated solution that actively finds and maintains the optimal path for critical SaaS applications, directly addressing the customer's requirement.

  6. Question 6

    Q6

    A hospital is implementing Cisco ISE for network access control. During the Discover phase, the biomedical engineering department expresses concern about network access for critical medical devices like MRI machines and infusion pumps. These devices do not have 802.1X supplicants. The primary requirement is to securely onboard these devices while ensuring they are correctly identified and placed into a segmented 'Medical_Devices' group. What is the most appropriate initial discovery question to ask the customer to determine the best ISE design?

    Show answer & explanation

    Correct answer: B

    Given that the devices lack 802.1X supplicants, the primary authentication method will be MAC Authentication Bypass (MAB). The first and most crucial step for a secure MAB implementation is to have a known list of valid MAC addresses. Asking for this list determines if a static endpoint group can be created, which is the most secure starting point for MAB. This allows ISE to authenticate known devices and deny unknown ones. Subsequent profiling can then be used to verify that the device connecting with a known MAC is, in fact, the correct type of medical device.

  7. Question 7

    Q7

    A retail company with 500 stores is planning an SD-WAN deployment. During the discovery phase, the network team states their primary goals are to reduce MPLS costs by using dual broadband internet circuits and to simplify branch deployments. They have a small IT team and require a solution that minimizes manual configuration at each store. Which SD-WAN feature directly addresses the goal of simplified branch deployments?

    Show answer & explanation

    Correct answer: C

    Zero Touch Provisioning (ZTP) is the feature specifically designed to simplify and automate the onboarding of new branch routers. With ZTP, a non-technical person at the store can simply plug in the router, which then automatically contacts the vBond orchestrator, authenticates itself, and downloads its full configuration from vManage. This eliminates the need for manual CLI configuration at each of the 500 stores, directly addressing the customer's requirement for simplified deployments with a small IT team.

  8. Question 8

    Q8

    True or False: In a Cisco SD-Access fabric, the Border node is responsible for advertising fabric endpoint (EID) subnets into the external routing domain using BGP.

    Show answer & explanation

    Correct answer: B

    This statement is false. The Control Plane node, which runs the LISP Map-Server/Map-Resolver, is responsible for dynamically advertising the aggregate EID prefixes into the external routing domain via BGP. The Border node provides the data plane exit/entry point for the fabric but does not handle the EID prefix advertisement itself; it learns external routes and advertises them into the fabric.

  9. Question 9

    Q9

    A company is designing an ISE deployment for 50,000 endpoints across three geographically dispersed data centers. The primary requirement is high availability for authentication services and centralized management and logging. Which ISE persona should be deployed in a cluster at each of the three data centers?

    Show answer & explanation

    Correct answer: A

    The Policy Service Node (PSN) is the persona that handles all RADIUS and TACACS+ requests, making policy decisions for endpoints. To ensure high availability for authentication services, PSNs should be deployed geographically close to the endpoints they are serving. Placing a cluster of PSNs in each data center ensures that local network access devices have a low-latency, resilient connection for authentication requests, even if connectivity to other data centers is lost. The PAN and MnT personas would typically be centralized in a primary/secondary data center pair for management and logging.

  10. Question 10

    Q10

    During an SD-Access discovery workshop for a manufacturing company, the OT team reveals they have a large number of legacy industrial control systems that require layer 2 adjacency to function. The company wants to integrate these devices into the new fabric to gain visibility and apply basic segmentation. Which SD-Access design feature must be included to accommodate this requirement?

    Show answer & explanation

    Correct answer: C

    SD-Access is primarily a layer 3 routed fabric, which can be a problem for legacy devices that rely on layer 2 broadcasts or multicasts to discover each other. To support these devices, a specific Layer 2 Virtual Network (VN) must be created and configured for L2 flooding. This essentially creates a layer 2 broadcast domain that is tunneled over the layer 3 fabric underlay, providing the required adjacency for the legacy systems while still allowing them to be part of the overall fabric architecture.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 500-490 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 224 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon