Weekend Special 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Cisco 500-490 Practice Exam with Questions & Answers

Questions 1

Which is a benefit of a cloud-based SD-WAN deployment?

Options:
A.

instant scale

B.

security never a n issue

C.

agility of change dependent only on your own internal IT processes

D.

controller availability never an issue

E.

might be required for compliance with industry standards

Cisco 500-490 Premium Access
Questions 2

What is the easiest way to enable SD-Access for all your remote sites after you have your campus SD-Access fabric up and running?

Options:
A.

Use a separate fabric domain for each site and use the traditional physical network as the underlay.

B.

Threat all the sites as one fabric domain and use the traditional physical network as the underlay.

C.

Threat all the sites as one fabric domain and use SD-WAN as the underlay.

D.

Use a separate fabric domain for each site and use SD-WAN a s the underlay.

Questions 3

Which two statements are true regarding Cisco ISE? (Choose two.)

Options:
A.

ISE plays a critical role in SD-Access.

B.

ISE can provide data about when a specific device connected to the network.

C.

The major business outcomes of ISE are enhanced user experience and secure VLAN segmentation.

D.

An ISE deployment requires only a Cisco ISE network access control appliance.

E.

Without integration with any other product, ISE can track the actual physical location of a wireless endpoint as it moves.

Questions 4

Which two statements regarding Cisco SD-WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two.)

Options:
A.

Open Certificate Authority and automated enrollment feature.

B.

By default, all incoming traffic is denied at the transport (WAN) side interfaces.

C.

Only authorized controllers are allowed to communicate back to the vEdge router after the vEdge router establishes connections with the controllers.

D.

In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.

E.

The vEdge routers run on hardened Linux operating systems.

Questions 5

Which two statements are true regarding SD-WAN demonstrations? (Choose two.)

Options:
A.

As a Cisco SD-WAN SE, you should you should spend your time learning about the technology rather than contributing to demo innovation.

B.

During a demo, you should demonstrate and discuss what the team considers important

details.

C.

During a demo, you should consider the target audience and the desired outcome.

D.

Use demonstrations primarily for large opportunities and competitive situations.

E.

There is a big difference between demos that use a top down approach and demos that use a bottom up approach.

Questions 6

Which two options help you sell Cisco ISE? (Choose two.)

Options:
A.

Showcasing the entire ISE feature set

B.

Referring to TrustSec as being only supported on Cisco networks

C.

Discussing the importance of custom profiling

D.

Explaining ISE support for 3rd party network devices

E.

Downplaying the value of pxGrid as compared to RESTful APIs

Questions 7

Which component of the SD-Access fabric is responsible for communicating with networks that are external to the fabric?

Options:
A.

border nodes

B.

edge nodes

C.

control plane nodes

D.

intermediate nodes

Questions 8

Which two statements are true regarding Cisco ISE? (Choose two.)

Options:
A.

In distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically.

B.

ISE can detected endpoints whose addresses have been translated via NAT.

C.

In two-node standalone ISE deployments, failover must be done manually.

D.

ISE supports IPv6 downloadable ACLs.

E.

ISE supports up to 100 Policy Services Nodes.

F.

The number of logs that ISE can retain is determined by your disk space.

Questions 9

What are three ways in which Cisco ISE learns information about devices? (Choose three.)

Options:
A.

user authentication to the ISE

B.

SMTP agents

C.

RPC mechanism via HTTPS

D.

traffic generated by the device

E.

network servers the device has accessed

F.

RADIUS attributes

Questions 10

Which three ways are SD-Access and ACI Fabric similar? (Choose three.)

Options:
A.

use of overlays

B.

use of Virtual Network IDs

C.

focus on user endpoints

D.

use of group policy

E.

use of Endpoint Groups

F.

use of Scalable Group Tags

Exam Code: 500-490
Certification Provider: Cisco
Exam Name: Designing Cisco Enterprise Networks exam
Last Update: Mar 23, 2025
Questions: 35
PDF + Testing Engine
$174.99
$61.25
Testing Engine
$134.99
$47.25
PDF (Q&A)
$114.99
$40.25