500-220 Sample Questions & Answers
Designing scalable Auto VPN architectures ties with monitoring and troubleshooting for the heaviest weight, alongside cloud dashboard access and segmentation, setting up MX security appliances plus MS and MR hardware, and firmware-upgrade awareness.
Launch the full 500-220 simulator →Showing 10 of 20 free samples.
- Question 1Advanced
Implementation · Configuring SM endpoint management Sentry for Meraki managed deployments
A large retail chain is using Systems Manager to manage thousands of corporate-owned iOS devices used as point-of-sale terminals. The security team wants to ensure that these devices can only connect to corporate Wi-Fi networks and that their network traffic is always routed through the corporate MX security appliances for content filtering, even when the devices are taken off-site. Which Systems Manager feature, when integrated with Meraki wireless and security appliances, achieves this?
Show answer & explanation
Correct answer: C
Systems Manager Sentry provides several key integrations. Sentry Policies enforce that only managed devices can connect to specific SSIDs. Furthermore, Sentry VPN automatically provisions and enables a VPN connection on the managed device back to a Meraki MX, ensuring that all traffic is tunneled through the corporate network for security inspection and policy enforcement, regardless of the device's location.
- Question 2Intermediate
Monitoring and Troubleshooting · Describe how to use the dashboard API to monitor and maintain networks
What is the primary function of the Meraki Dashboard API's 'Action Batches' endpoint?
Show answer & explanation
Correct answer: B
Action Batches are designed for automation and efficiency. They allow a developer to bundle multiple API actions (e.g., update 100 switch port configurations, create 5 new VLANs, bind a network to a template) into a single API request. The Dashboard then executes these actions asynchronously, which is ideal for large-scale or long-running configuration tasks without having to wait for each individual call to complete.
- Question 3Beginner
Cisco Meraki Cloud Management · Explain licensing, co-termination, and renewals
A consultant is designing a Meraki network for a new corporate headquarters. The design requires Layer 3 routing to be handled by a pair of MS425 switches configured as the core. OSPF will be used to exchange routes with the MX100 edge appliances. Which license is required for the MS425 switches to support dynamic routing protocols like OSPF?
Show answer & explanation
Correct answer: B
While the standard Meraki MS Enterprise License enables basic Layer 3 functionality like static routing, advanced features such as support for dynamic routing protocols (OSPF, BGP) require the MS Advanced License. This license tier unlocks the full routing capabilities of the switch hardware.
- Question 4Intermediate
Design · Design scalable Meraki Auto VPN architectures
When designing a Meraki Auto VPN topology, what is a primary advantage of a hub-and-spoke design compared to a full-mesh design for a company with one central datacenter and 200 remote retail stores?
Show answer & explanation
Correct answer: B
In a hub-and-spoke topology, all traffic from the spokes (retail stores) must pass through the central hub (datacenter) to reach other spokes or the internet. This architecture forces traffic through a central point, making it ideal for applying consistent security policies, content filtering, and threat inspection using the hub MX appliance before traffic proceeds to its destination.
- Question 5Intermediate
Implementation · Configuring MR wireless access points SSIDs for Enterprise and BYOD deployments
An administrator is configuring an SSID on an MR46 access point for guest access. The requirement is to present users with a terms-of-service splash page that they must click through before gaining access. Additionally, all guest traffic must be completely isolated from the internal corporate network and NATed directly to the internet using the AP's uplink. Which set of configurations on the SSID's 'Access control' page achieves this?
Show answer & explanation
Correct answer: D
For a simple guest network, 'Open' association is standard. 'Click-through' splash page meets the terms-of-service requirement. Most importantly, 'NAT mode' instructs the Meraki AP to act as a DHCP server and NAT gateway for guest clients. This isolates their traffic onto a separate subnet and sends it directly to the internet, completely bypassing the internal corporate network, which is a critical security practice for guest access.
- Question 6Intermediate
Monitoring and Troubleshooting · Application performance issues using Meraki Insight
A school district is using Meraki Insight to monitor the performance of a critical online testing application. During final exams, teachers report that the application is slow. The network team checks Meraki Insight and sees a high 'Server Response Time' for the application, while 'WAN Latency' and 'Local Network Delay' are low. Based on this information, where does the root cause of the performance issue most likely reside?
Show answer & explanation
Correct answer: B
Meraki Insight breaks down application performance into distinct segments. Low 'Local Network Delay' rules out the school's LAN, and low 'WAN Latency' rules out the internet connection path. A high 'Server Response Time' specifically indicates that the delay is occurring after the request has reached the application's hosting environment. This points directly to a problem with the server itself (e.g., overloaded CPU/memory) or the infrastructure within its datacenter.
- Question 7Advanced
Design · Explain deployment consideration for the vMX
An engineer is deploying a vMX100 into an existing AWS VPC to extend the corporate Auto VPN fabric into the cloud. The VPC has a private subnet (10.50.1.0/24) where application servers reside and a public subnet (10.50.0.0/24) with an Internet Gateway. To function correctly, what is a critical AWS networking requirement for the vMX100 instance?
Show answer & explanation
Correct answer: C
By default, AWS EC2 instances perform a source/destination check, meaning they must be the source or destination of any traffic they send or receive. A vMX, acting as a router and VPN concentrator, needs to forward traffic on behalf of other devices (i.e., traffic where it is neither the source nor the destination). Disabling this check is a mandatory step to allow the vMX to perform its routing functions correctly within the VPC.
- Question 8Intermediate
Cisco Meraki Cloud Management · Explain access methods to dashboard and devices
A company has configured their Meraki organization to use SAML for administrator single sign-on, with Okta acting as the Identity Provider (IdP). An administrator attempts to log in but receives an error. A review of the SAML assertion from Okta shows that the 'username' attribute is being sent as the user's email address. For the login to succeed, what must be configured in the Meraki Dashboard?
Show answer & explanation
Correct answer: B
For SAML SSO to work, Meraki needs to know how to map the incoming identity from the IdP to a set of permissions. This is done by creating a SAML administrator role. In this role, the administrator specifies the attribute name from the IdP (in this case, 'username') and the value that will be sent (the user's email). This mapping tells the Dashboard, 'When a user logs in with this email in the username attribute, grant them these specific organization/network permissions.'
- Question 9IntermediateSelect 3
Implementation · Configuring MX security appliances Traffic shaping and SD-WAN
A network engineer needs to configure a traffic shaping rule on an MX84 to limit bandwidth for all peer-to-peer applications for the entire network. Which three components are necessary to create this rule? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
The rule needs to know what traffic to act upon. Meraki's Layer 7 application intelligence provides predefined categories, such as 'All peer-to-peer', which must be selected as the traffic signature.
The rule must specify the action to take. A per-client bandwidth limit ensures that each individual user is throttled, preventing one user from consuming the entire allocated pool of bandwidth for P2P traffic.
All traffic shaping rules must have a schedule. To apply the rule at all times, the 'All day' schedule must be selected.
- Question 10Intermediate
Implementation · Configuring MR wireless access points Air Marshal
True or False: The Meraki Air Marshal feature can automatically contain rogue SSIDs by sending deauthentication frames to clients connected to them, but this functionality is only active for APs operating in 'gateway' mode.
Show answer & explanation
Correct answer: B
The statement is false because Air Marshal containment can be performed by any Meraki AP that has an Ethernet connection to the network (i.e., gateway or repeater APs). It does not have to be the specific AP acting as the network gateway. APs in 'repeater' mode can also perform containment as long as they have a wired uplink.
Ready for the real thing?
The full 500-220 simulator has every exam-style question, timed mode, and instant scoring.