500-490 Sample Questions

500-490 Sample Questions & Answers

Architecture design and solution defense across SD-Access, SD-WAN and ISE each carry equal top weight, with smaller portions on gathering customer requirements, demonstrating SD-WAN and SDA capabilities, and discovering ISE and SD-WAN requirements.

Launch the full 500-490 simulator →

Showing 10 of 20 free samples.

  1. Question 1Beginner

    ISE: Discover · Identity and Access Requirements

    A hospital is implementing Cisco ISE for network access control. During the Discover phase, the biomedical engineering department expresses concern about network access for critical medical devices like MRI machines and infusion pumps. These devices do not have 802.1X supplicants. The primary requirement is to securely onboard these devices while ensuring they are correctly identified and placed into a segmented 'Medical_Devices' group. What is the most appropriate initial discovery question to ask the customer to determine the best ISE design?

    Show answer & explanation

    Correct answer: B

    Given that the devices lack 802.1X supplicants, the primary authentication method will be MAC Authentication Bypass (MAB). The first and most crucial step for a secure MAB implementation is to have a known list of valid MAC addresses. Asking for this list determines if a static endpoint group can be created, which is the most secure starting point for MAB. This allows ISE to authenticate known devices and deny unknown ones. Subsequent profiling can then be used to verify that the device connecting with a known MAC is, in fact, the correct type of medical device.

  2. Question 2Beginner

    SD-WAN: Discover · WAN Transformation Requirements

    A retail company with 500 stores is planning an SD-WAN deployment. During the discovery phase, the network team states their primary goals are to reduce MPLS costs by using dual broadband internet circuits and to simplify branch deployments. They have a small IT team and require a solution that minimizes manual configuration at each store. Which SD-WAN feature directly addresses the goal of simplified branch deployments?

    Show answer & explanation

    Correct answer: A

    Zero Touch Provisioning (ZTP) is the feature specifically designed to simplify and automate the onboarding of new branch routers. With ZTP, a non-technical person at the store can simply plug in the router, which then automatically contacts the vBond orchestrator, authenticates itself, and downloads its full configuration from vManage. This eliminates the need for manual CLI configuration at each of the 500 stores, directly addressing the customer's requirement for simplified deployments with a small IT team.

  3. Question 3Intermediate

    SD-Access Design · Fabric Design Principles

    True or False: In a Cisco SD-Access fabric, the Border node is responsible for advertising fabric endpoint (EID) subnets into the external routing domain using BGP.

    Show answer & explanation

    Correct answer: B

    This statement is false. The Control Plane node, which runs the LISP Map-Server/Map-Resolver, is responsible for dynamically advertising the aggregate EID prefixes into the external routing domain via BGP. The Border node provides the data plane exit/entry point for the fabric but does not handle the EID prefix advertisement itself; it learns external routes and advertises them into the fabric.

  4. Question 4Intermediate

    ISE: Design · ISE Deployment Design

    A company is designing an ISE deployment for 50,000 endpoints across three geographically dispersed data centers. The primary requirement is high availability for authentication services and centralized management and logging. Which ISE persona should be deployed in a cluster at each of the three data centers?

    Show answer & explanation

    Correct answer: C

    The Policy Service Node (PSN) is the persona that handles all RADIUS and TACACS+ requests, making policy decisions for endpoints. To ensure high availability for authentication services, PSNs should be deployed geographically close to the endpoints they are serving. Placing a cluster of PSNs in each data center ensures that local network access devices have a low-latency, resilient connection for authentication requests, even if connectivity to other data centers is lost. The PAN and MnT personas would typically be centralized in a primary/secondary data center pair for management and logging.

  5. Question 5Intermediate

    SD-Access Discovery · Technical Requirements Assessment

    During an SD-Access discovery workshop for a manufacturing company, the OT team reveals they have a large number of legacy industrial control systems that require layer 2 adjacency to function. The company wants to integrate these devices into the new fabric to gain visibility and apply basic segmentation. Which SD-Access design feature must be included to accommodate this requirement?

    Show answer & explanation

    Correct answer: C

    SD-Access is primarily a layer 3 routed fabric, which can be a problem for legacy devices that rely on layer 2 broadcasts or multicasts to discover each other. To support these devices, a specific Layer 2 Virtual Network (VN) must be created and configured for L2 flooding. This essentially creates a layer 2 broadcast domain that is tunneled over the layer 3 fabric underlay, providing the required adjacency for the legacy systems while still allowing them to be part of the overall fabric architecture.

  6. Question 6Intermediate

    SDA Demonstration · DNA Center Demonstrations

    A field engineer is preparing a demonstration of Cisco DNA Center Assurance for a customer who is experiencing frequent complaints about poor Wi-Fi performance. The goal is to show how Assurance can proactively identify and help resolve these issues. Which Assurance dashboard or feature would be most impactful to demonstrate?

    Show answer & explanation

    Correct answer: D

    The Client 360 view provides the most direct and compelling demonstration for user-specific Wi-Fi issues. It visualizes the entire connectivity journey for a single client, showing detailed information about association, authentication, DHCP, and roaming events. It also highlights specific failures (e.g., slow DHCP, failed authentication) with AI-driven insights and suggested remediation steps. This directly addresses the customer's pain point by showing a powerful tool that can quickly pinpoint the root cause of an individual's poor Wi-Fi experience.

  7. Question 7Advanced

    SD-WAN: Design · SD-WAN Security Design

    A customer is migrating from a legacy WAN to Cisco SD-WAN. They have a strict security requirement that all internet-bound traffic from branch offices must be inspected by a centralized cloud-based security stack (SASE/SSE). They also want to maintain the ability for branches to communicate directly for internal applications. Which design component is essential to meet this requirement?

    Show answer & explanation

    Correct answer: A

    This is the standard and most efficient way to achieve service insertion for cloud security. A centralized data policy on vSmart can surgically identify only the internet-bound traffic. By using a 'service' action, it can redirect this traffic into a specific service VPN (e.g., VPN 0 or another transport VPN) where tunnels to the SASE provider are established. This forces all internet traffic through the security stack while allowing other traffic (e.g., branch-to-branch) to follow its normal path as defined by the topology, thus meeting both requirements.

  8. Question 8Beginner

    ISE: Demonstration · ISE Feature Demonstrations

    While demonstrating ISE's guest access capabilities, a customer who runs a large public venue asks how they can prevent users from consuming excessive bandwidth and ensure fair usage. Which ISE feature should be highlighted to address this concern?

    Show answer & explanation

    Correct answer: C

    ISE itself does not perform bandwidth shaping, but it can instruct the network access device (like a Wireless LAN Controller or switch) to do so. This is achieved by configuring an Authorization Profile in ISE. Within this profile, you can specify RADIUS attributes that map to a QoS policy or a per-user bandwidth limit defined on the WLC. When a guest authenticates, ISE sends these attributes as part of the RADIUS Access-Accept message, and the WLC enforces the bandwidth limitation, directly addressing the customer's requirement.

  9. Question 9Intermediate

    SD-WAN: Design · SD-WAN Fabric Design

    A global enterprise is designing its SD-WAN control plane. They have major hubs in North America, Europe, and Asia. To ensure low-latency communication between branch routers and controllers, and to maintain operational independence, what is the recommended design for deploying the vSmart controllers?

    Show answer & explanation

    Correct answer: A

    The best practice for a global deployment is to create a single, logical cluster of vSmart controllers that is physically distributed across the major geographical regions. This design provides both low-latency control plane connections (branches connect to their nearest vSmart) and high availability. All controllers in the cluster share the same domain ID and are aware of each other, but they operate as a single logical entity. This provides regional survivability without partitioning the network into separate fabrics, which would complicate policy and connectivity.

  10. Question 10Intermediate

    SD-WAN: Demonstration · Competitive Differentiation

    A customer is defending their decision to purchase a competitor's SD-WAN solution because it offers a simple, built-in stateful firewall at the branch. As a Cisco field engineer, what is the most compelling argument to counter this and defend the Cisco SD-WAN security approach?

    Show answer & explanation

    Correct answer: A

    This is the strongest defense because it shifts the conversation from a simple feature-for-feature comparison to a discussion about effective, modern security architecture. While Cisco routers do have embedded security, the key differentiator is the seamless integration with a full SASE/SSE stack like Cisco Umbrella. This provides a far more robust security posture by offloading advanced inspection to the cloud, ensuring consistent policy enforcement for all users, and protecting against threats that a simple stateful firewall cannot. It reframes the competitor's 'simple' solution as 'inadequate' for the current threat landscape.

Ready for the real thing?

The full 500-490 simulator has every exam-style question, timed mode, and instant scoring.