
Online Questions - Valid Practice 500-490 Exam Dumps Test Questions
100% Real 500-490 dumps - Brilliant 500-490 Exam Questions PDF
Certification Path
There is no prerequisite for this exam.
NEW QUESTION # 13
What statement is true regarding the current time in Enterprise Networking history?
- A. pervasive use of mobile devices
- B. advent of loT
- C. pace of change
- D. advent of cloud computing
Answer: B
NEW QUESTION # 14
Which two statements regarding Cisco SD WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two)
- A. Open Certificate Authority and automated enrollment feature
- B. Only authorized controllers are allowed to communicate back to the vEdge router after the vEdge router establishes connections with the controllers
- C. The vEdge routers run on hardened Linux operating systems
- D. In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.
- E. By default, all incoming traffic is denied art the transport (WAN) side interfaces,
Answer: B,D
NEW QUESTION # 15
Which three key differentiators that DNA Assurance provides that our competitors are unable match? (Choose three.)
- A. VXLAN support
- B. Network time travel
- C. Support for Overlay Virtual Transport
- D. Apple Insights
- E. On-premise and cloud-based analytics
- F. Proactive approach to guided remediation
Answer: B,D,F
NEW QUESTION # 16
Which are the three focus areas for reinventing the WAN? (Choose three.)
- A. Operations
- B. Execution
- C. Secure Elastic Connectivity
- D. Application Quality of Experience
- E. Cloud Fast
- F. Centralized device authentication
Answer: C,D,E
NEW QUESTION # 17
What are three ways in which Cisco ISE learns information about devices? (Choose three.)
- A. RPC mechanism via HTTPS
- B. RADIUS attributes
- C. user authentication to the ISE
- D. SMTP agents
- E. traffic generated by the device
- F. network servers the device has accessed
Answer: A,B,E
NEW QUESTION # 18
What are three ways in Which Cisco ISE learns information about devices? (Choose three,)
- A. SMIP agents
- B. RADIUS attributes
- C. network servers the device has accessed
- D. user authentication to the ISE
- E. RPC mechanism via HTTPS
- F. traffic generated by the device
Answer: B,C,F
NEW QUESTION # 19
Winch two primary categories are displayed on the overall health page of the assurance component in the Cisco DNA Center? (Choose two.)
- A. Access-Distribution
- B. Server
- C. Wired
- D. Network
- E. Client
Answer: A,D
NEW QUESTION # 20
Which two Cisco ISE use cases typically involve the highest level of implementation complexity? (Choose two.)
- A. Asset visibility
- B. Guest and wireless access
- C. Software-defined access
- D. Software-defined segmentation
- E. Device management
Answer: C,D
Explanation:
Explanation
Cisco ISE use cases can be classified into four categories: device management, asset visibility, software-defined segmentation, and software-defined access. Each of these use cases has a different level of implementation complexity, depending on the network size, topology, security requirements, and integration with other technologies. Among these use cases, software-defined segmentation and software-defined access typically involve the highest level of implementation complexity, because they require:
A thorough understanding of the network architecture and design principles, such as hierarchical, modular, and scalable design.
A comprehensive assessment of the network devices, endpoints, users, applications, and policies, and their interdependencies and interactions.
A careful planning and testing of the network segmentation and access policies, using tools such as Cisco TrustSec, Cisco DNA Center, Cisco SD-Access, and Cisco ISE .
A smooth and secure migration from the existing network to the software-defined network, with minimal disruption and downtime.
A continuous monitoring and optimization of the network performance, security, and compliance, using tools such as Cisco Stealthwatch, Cisco Tetration, and Cisco ISE .
References:
Cisco Identity Services Engine (ISE) Use Cases,
https://www.cisco.com/c/en/us/products/security/identity-services-engine/use-cases.html : Cisco Enterprise Network Architecture and Design,
https://www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/enterprise-networking-design.ht: Cisco ISE Network Discovery,
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide: Cisco TrustSec, https://www.cisco.com/c/en/us/solutions/enterprise-networks/trustsec/index.html : Cisco DNA Center, https://www.cisco.com/c/en/us/products/cloud-systems-management/dna-center/index.html :
Cisco SD-Access,
https://www.cisco.com/c/en/us/solutions/enterprise-networks/software-defined-access/index.html : Cisco ISE Software-Defined Access,
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide : Cisco SD-Access Migration Guide,
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/sda-migration-guide.html : Cisco Stealthwatch, https://www.cisco.com/c/en/us/products/security/stealthwatch/index.html : Cisco Tetration,
https://www.cisco.com/c/en/us/products/data-center-analytics/tetration/index.html : Cisco ISE Monitoring and Troubleshooting,
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide
NEW QUESTION # 21
Which Cisco product supports SD-Access and specifically built lo address new challenges faced by enterprises?
- A. CSRv virtual router
- B. Catalyst 6807-XL W/ Sup6T and C6800 10G line cards
- C. ASR 1000 MX
- D. Catalyst 9500
- E. Nexus 7700 w/ Sup2E and M3 line cards
- F. ISR 4221
Answer: F
NEW QUESTION # 22
Which is a function of lite Proactive Insights feature of Cisco DNA Center Assurance'?
- A. generating synthetic traffic to perform tests that raise awareness of potential network issues
- B. enabling you to quickly view all of the contextual information related to the end application
- C. pointing out where the most serious issues are happening in the network
- D. enabling you to see the complete path of packets from the client to the end application
Answer: D
NEW QUESTION # 23
Which Cisco product were incorporated into Cisco ISE between ISE releases 2.0 and 2.3?
- A. Cisco ACS
- B. Cisco WSA
- C. Cisco ESA
- D. Cisco ASA
Answer: A
Explanation:
Explanation
Cisco ISE incorporated Cisco ACS (Cisco Secure Access Control System) between ISE releases 2.0 and 2.3.
Cisco ACS was a network access policy platform that provided authentication, authorization, and accounting (AAA) services for network devices and users. Cisco ACS was discontinued in 2017 and replaced by Cisco ISE, which offers more advanced features and capabilities for identity-based network access control. Cisco ISE provides a migration tool that allows customers to migrate their data and configurations from Cisco ACS to Cisco ISE. The migration tool supports Cisco ACS versions 5.5, 5.6, 5.7, and 5.8 and Cisco ISE versions
2.0, 2.1, 2.2, and 2.3.
References:
Cisco Secure Access Control System End-of-Life Announcement [Cisco Secure Access Control System] Cisco Secure ACS to Cisco ISE Migration Tool [Cisco Identity Services Engine] Cisco Identity Services Engine Administrator Guide, Release 2.3 - Cisco Secure ACS to Cisco ISE Migration [Cisco Identity Services Engine] Cisco Identity Services Engine Administrator Guide, Release 2.3 - Manage Migration [Cisco Identity Services Engine]
[Cisco Identity Services Engine Migration Guide, Release 2.3 [Cisco Identity Services Engine]]
[Designing Cisco Enterprise Networks (ENDESIGN) Exam Topics [Cisco]]
[Cisco Validated Design Guides [Cisco]]
NEW QUESTION # 24
Which three options focus of the current digital business era'? (Choose three.)
- A. Human scale
- B. loT scale
- C. automation
- D. virtualized services
- E. connectivity
- F. centralized enterprise and web applications
Answer: C,D,E
NEW QUESTION # 25
Which two statements are true regarding Cisco ISE? (Choose two.)
- A. Without integration with any other product, ISE can track the actual physical location of a wireless endpoint as it moves
- B. An ISE deployment requires only a Cisco ISE network access control appliance
- C. ISE plays critical role in SD Access
- D. ISE am provide data about when a specific device connected to the network
- E. The major business outcomes of ISE are enhanced user experience and secure VLAN segmentation
Answer: C,D
NEW QUESTION # 26
Which are two Cisco ISE that benefits our customers? (Choose two.)
- A. helps t hem stop and contain real-time threats
- B. provides network access control
- C. enables them to set traffic priorities across the network
- D. helps t hem accelerate application deployment and delivery
Answer: A,B
Explanation:
Explanation
Cisco ISE benefits our customers by providing network access control and helping them stop and contain real-time threats. Network access control is the ability to enforce policies on who and what can access the network, based on the identity and context of users, devices, and applications. Cisco ISE allows customers to authenticate, authorize, and audit network access, as well as to segment and isolate network traffic based on security and compliance requirements. Cisco ISE also helps customers stop and contain real-time threats by leveraging intel from across the network and security ecosystem, and by automating threat response actions.
Cisco ISE can integrate with various security solutions, such as Cisco Stealthwatch, Cisco Firepower, and Cisco Umbrella, to detect and mitigate attacks on the network quickly and effectively. References:
Cisco Identity Services Engine (ISE) - Cisco1
Cisco Identity Services Engine (ISE) - Cisco2
Network Visibility and Segmentation (NVS) - Cisco3
Rapid Threat Containment - Cisco4
NEW QUESTION # 27
Which two statements describes Cisco SD-Access? (Choose two.)
- A. a collection of tools and applications that are a combination of loose and tight couping
- B. an automated encryption/decryption engine for highly secured transport requirements
- C. programmable overlays enabling network virtualization across the campus
- D. an overlay for the wired infrastructure in which traffic is tunneled via a GRE tunnel to a mobility controller for policy and application visibility
- E. software-defined segmentation and policy enforcement based on user identity and group membership
Answer: C,E
Explanation:
Explanation
Cisco SD-Access is a solution within Cisco DNA, which is built on intent-based networking principles. Cisco SD-Access provides visibility-based, automated end-to-end segmentation to separate user, device, and application traffic without redesigning the underlying physical network1. Cisco SD-Access also enables programmable overlays that allow network virtualization across the campus, branch, data center, and cloud2. Cisco SD-Access has two main components: the fabric and the policy3.
The fabric is the network overlay that consists of interconnected nodes that provide a consistent and scalable way of delivering network services and functions. The fabric nodes are classified into four types: edge nodes, border nodes, control plane nodes, and intermediate nodes. The edge nodes are the access switches or wireless controllers that connect to the end devices. The border nodes are the routers or switches that connect the fabric to external networks, such as the Internet, WAN, or data center. The control plane nodes are the routers or switches that maintain the mapping between the endpoint identifiers and the network locators. The intermediate nodes are the routers or switches that provide transit services within the fabric3.
The policy is the network configuration that defines the network behavior and outcomes, based on the business intent and requirements. The policy is composed of three elements: the endpoint groups, the contracts, and the virtual networks. The endpoint groups are the logical containers that group the endpoints based on their attributes, such as user identity, device type, or application. The contracts are the rules that specify the allowed interactions between the endpoint groups, such as the protocols, ports, and quality of service. The virtual networks are the logical partitions that isolate the endpoint groups and contracts from each other, based on the network scope and security3.
Cisco SD-Access addresses the following challenges and benefits:
It simplifies the network design and management, as it reduces the complexity and variability of the network elements and interfaces.
It enhances the network security and compliance, as it enforces granular and dynamic policies based on the endpoint identity and context, rather than the network topology and IP addresses.
It improves the network performance and user experience, as it optimizes the network path, load balancing, and traffic engineering based on the network conditions and application requirements.
It enables the network agility and scalability, as it supports the rapid deployment and integration of new devices, applications, and services, without affecting the existing network operations.
References:
Cisco Software-Defined Access - Cisco Software-Defined Access Solution Overview What Is Software-Defined Access? - SD-Access - Cisco Cisco SD-Access Architecture Overview
NEW QUESTION # 28
Which two options help you sell Cisco ISE? (Choose two.)
- A. Show casing the entire ISE feature set
- B. Explaining ISE support for 3rd party network devices
- C. Discussing (he importance of custom profiling
- D. Downplaying the value of px Grid as compared to REST ful APIs
- E. Referring to Trust Sec as being only supported on Cisco networks
Answer: A,B
NEW QUESTION # 29
Which two statements are true regarding SD-WAN demonstrations? (Choose two.)
- A. During a demo you should consider the target audience and the desired outcome
- B. During a demo, you should demonstrate and discuss what the team considers important details
- C. There is a big difference between demos that use a top down approach and demos that use a bottom up approach
- D. Use demonstrations primarily for large opportunities and competitive situations
- E. As a Cisco SD-WAN SF, you should you should spend your time learning about the technology rather than contributing to demo innovation
Answer: D,E
NEW QUESTION # 30
Which option will help build your customers platform during the discovery phase?
- A. detailed design
- B. PO
- C. business case
- D. high-level design
- E. POV report
Answer: C
Explanation:
Explanation
= A business case is an option that will help build your customers platform during the discovery phase. A business case is a document that outlines the rationale, objectives, benefits, costs, risks, and alternatives of a proposed project or solution. A business case helps to justify the investment and align the stakeholders on the value proposition of the project or solution12.
During the discovery phase, the goal is to understand the problem that needs to be solved, the user needs and context, the constraints and opportunities, and the underlying policy intent. A business case can help to achieve this goal by providing a clear and concise summary of the problem statement, the desired outcomes, the potential solutions, and the evaluation criteria34. A business case can also help to communicate the vision and scope of the project or solution to the customers and other stakeholders, and to secure their buy-in and support56.
A business case is not the same as a POV report, a detailed design, a high-level design, or a PO. A POV report is a document that summarizes the findings and recommendations from a proof of value (POV) exercise, which is a short-term trial of a solution to demonstrate its feasibility and benefits7. A detailed design is a document that specifies the technical and functional requirements, architecture, and configuration of a solution8. A high-level design is a document that provides an overview of the solution, such as the main components, interfaces, and interactions9. A PO is a purchase order, which is a document that authorizes a purchase transaction between a buyer and a seller.
References :=
What is a business case? Definition and examples
Business Case - Project Management Knowledge
How the discovery phase works - Service Manual - GOV.UK
Discovery Phase - Service Design - The Beginner's Guide
How to Write a Business Case 4 Steps to a Perfect Business Case Template How to Write a Business Case: 4 Steps to a Perfect Business Case Template What is a Proof of Value (POV)?
What is a Detailed Design Document (DDD)?
What is a High-Level Design Document?
[What is a Purchase Order (PO)?]
NEW QUESTION # 31
Which two activities should occur during an SE's demo process? (Choose two.)
- A. determining whether the customer would like to dive deeper during a follow -up
- B. highlighting opportunities that although not currently within scope would result in lower operational costs and complexity
- C. identifying which capabilities require demonstration
- D. asking the customer to provide network drawings or white board the environment for you
- E. leveraging a company such as Complete Communications to build a financial case
Answer: A,C
Explanation:
Explanation
According to the Cisco Design Zone website1, an SE's demo process should include the following activities:
Identifying which capabilities require demonstration: The SE should understand the customer's business objectives, pain points, and technical requirements, and map them to the relevant Cisco solutions and capabilities. The SE should also prioritize the most important and impactful features and benefits that address the customer's needs and challenges, and plan the demo accordingly. The SE should avoid showing irrelevant or unnecessary features that may confuse or distract the customer12.
Determining whether the customer would like to dive deeper during a follow-up: The SE should use the demo as an opportunity to engage the customer in a dialogue, solicit feedback, and gauge the customer's interest and satisfaction. The SE should also identify any gaps or questions that the customer may have, and offer to provide more information or a deeper dive during a follow-up session. The SE should also ask for the customer's permission to schedule a follow-up meeting or call, and confirm the next steps and actions13.
The other activities are not recommended or necessary during an SE's demo process, because:
Highlighting opportunities that although not currently within scope would result in lower operational costs and complexity: The SE should focus on the customer's current scope and needs, and not try to upsell or cross-sell other solutions or services that are not relevant or requested by the customer. The SE should also respect the customer's budget and timeline, and not introduce additional costs or complexity that may jeopardize the deal or the relationship1 .
Asking the customer to provide network drawings or white board the environment for you: The SE should prepare for the demo by doing the necessary research and discovery before the meeting, and not rely on the customer to provide the information or draw the network for them. The SE should also demonstrate their expertise and credibility by showing their knowledge of the customer's environment and challenges, and not ask the customer to do their work for them1 .
Leveraging a company such as Complete Communications to build a financial case: The SE should not outsource or delegate the financial analysis or justification of the solution to a third-party company, as this may undermine the SE's role and value, and create a dependency or risk for the deal. The SE should also use the Cisco tools and resources available to them, such as the Business Value Calculator, to build a financial case and show the return on investment and total cost of ownership of the solution1 .
References:
1: Cisco Design Zone 2: [Cisco Demo Best Practices], page 3 3: [Cisco Demo Best Practices], page 6 : [Cisco Demo Best Practices], page 4 : [Cisco Demo Best Practices], page 2 : [Cisco Demo Best Practices], page 5
NEW QUESTION # 32
Which two statements regarding Cisco SD WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two)
- A. In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.
- B. Open Certificate Authority and automated enrollment feature
- C. Only authorized controllers are allowed to communicate back to the vEdge router after the vEdge router establishes connections with the controllers
- D. By default, all incoming traffic is denied art the transport (WAN) side interfaces,
- E. The vEdge routers run on hardened Linux operating systems
Answer: C,E
NEW QUESTION # 33
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of group policy
- B. use of Endpoint Groups
- C. use of Virtual Network IDs
- D. focus on user endpoints
- E. use of overlays
- F. use of Scalable Group Tags
Answer: B,E,F
Explanation:
Explanation
SD-Access and ACI Fabric are both solutions that provide software-defined networking for different domains.
SD-Access is designed for the campus and branch networks, while ACI Fabric is designed for the data center networks. However, they share some common features and concepts, such as:
Use of Scalable Group Tags: Both SD-Access and ACI Fabric use Scalable Group Tags (SGTs) to identify and classify the endpoints based on their attributes, such as user identity, device type, or application. SGTs are numerical labels that are assigned to the endpoints and carried in the packets, either in the header or in the metadata. SGTs enable granular and dynamic policy enforcement based on the endpoint identity and context, rather than the network topology and IP addresses12.
Use of overlays: Both SD-Access and ACI Fabric use overlays to create a network abstraction layer that decouples the network services and functions from the underlying physical infrastructure. Overlays enable network virtualization and segmentation, as they allow multiple logical networks to coexist on the same physical network. Overlays also simplify the network design and management, as they reduce the complexity and variability of the network elements and interfaces. SD-Access uses VXLAN as the overlay protocol, while ACI Fabric uses VXLAN with EVPN as the overlay protocol34.
Use of Endpoint Groups: Both SD-Access and ACI Fabric use Endpoint Groups (EPGs) to group the endpoints based on their policy requirements and network scope. EPGs are logical containers that define the allowed interactions between the endpoints, such as the protocols, ports, and quality of service.
EPGs also define the network boundaries that isolate the endpoints from each other, based on the security and compliance needs. EPGs are synonymous with Scalable Groups in SD-Access, and they can be mapped between SD-Access and ACI Fabric to enable end-to-end policy across the domains56.
References:
Cisco TrustSec Overview
Cisco TrustSec Configuration Guide, Cisco IOS XE Gibraltar 16.12.x - Scalable Group Tags [Cisco IOS XE 16] - Cisco Cisco SD-Access Architecture Overview Cisco Application Centric Infrastructure Fundamentals, Release 4.0(1) - ACI Fabric Fundamentals
[Cisco Application Policy Infrastructure Controller (APIC)] - Cisco
Cisco SD-Access (SDA) Integration with Cisco Application Centric Infrastructure (ACI) - Cisco Community Cisco Application Centric Infrastructure - Cisco Multidomain Integration At-a-Glance
NEW QUESTION # 34
Which are two Cisco recommendations that demonstrates SDA? (Choose two.)
- A. Be sure you explain the major technologies such as VXLAN and LISP in depth
- B. Show lite customer how to integrate ISL into DMA Center at the end of the demo
- C. Use the CLI to perform as much of the configuration as possible
- D. Focus on business benefits
- E. Keep the demo at a high level
Answer: D,E
NEW QUESTION # 35
How would cisco ISE handle authentication for your printer that does not have a supplicant?
- A. ISE would authenticate the printer using MAC RADIUS authentication
- B. ISE would authenticate the printer using 8.2.1X authentication
- C. ISE would authenticate the printer using web authentication.
- D. ISE would authenticate the printer using MAB.
- E. ISE would not authenticate the printer as printers are not subject to ISE authentication.
Answer: B
NEW QUESTION # 36
......
500-490 Exam PDF [2024] Tests Free Updated Today with Correct 37 Questions: https://www.examcost.com/500-490-practice-exam.html
Cisco 500-490 Exam Preparation Guide and PDF Download: https://drive.google.com/open?id=1sgGDqLIPPgASBgRwZujh5DSyJzNeWajX

