
[Aug-2024] 500-490 Braindumps – 500-490 Questions to Get Better Grades
500-490 Exam Dumps - Try Best 500-490 Exam Questions - Pass4sures
NEW QUESTION # 12
Which are two Cisco ISE that benefits our customers ? (Choose two.)
- A. helps them stop and contain real time threats
- B. provides network access controller
- C. enables them to set traffic priorities across the network
- D. helps them accelerate application deployment and delivery
Answer: A,B
NEW QUESTION # 13
Which two statements describes Cisco SD-Access? (Choose two.)
- A. an overlay for the wired infrastructure in which traffic is tunneled via a GRE tunnel to a mobility controller for policy and application visibility
- B. an automated encryption/decryption engine for highly secured transport requirements
- C. software-defined segmentation and policy enforcement based on user identity and group membership
- D. programmable overlays enabling network virtualization across the campus
- E. a collection of tools and applications that are a combination of loose and tight couping
Answer: C,D
Explanation:
Explanation
Cisco SD-Access is a solution within Cisco DNA, which is built on intent-based networking principles. Cisco SD-Access provides visibility-based, automated end-to-end segmentation to separate user, device, and application traffic without redesigning the underlying physical network1. Cisco SD-Access also enables programmable overlays that allow network virtualization across the campus, branch, data center, and cloud2. Cisco SD-Access has two main components: the fabric and the policy3.
The fabric is the network overlay that consists of interconnected nodes that provide a consistent and scalable way of delivering network services and functions. The fabric nodes are classified into four types: edge nodes, border nodes, control plane nodes, and intermediate nodes. The edge nodes are the access switches or wireless controllers that connect to the end devices. The border nodes are the routers or switches that connect the fabric to external networks, such as the Internet, WAN, or data center. The control plane nodes are the routers or switches that maintain the mapping between the endpoint identifiers and the network locators. The intermediate nodes are the routers or switches that provide transit services within the fabric3.
The policy is the network configuration that defines the network behavior and outcomes, based on the business intent and requirements. The policy is composed of three elements: the endpoint groups, the contracts, and the virtual networks. The endpoint groups are the logical containers that group the endpoints based on their attributes, such as user identity, device type, or application. The contracts are the rules that specify the allowed interactions between the endpoint groups, such as the protocols, ports, and quality of service. The virtual networks are the logical partitions that isolate the endpoint groups and contracts from each other, based on the network scope and security3.
Cisco SD-Access addresses the following challenges and benefits:
It simplifies the network design and management, as it reduces the complexity and variability of the network elements and interfaces.
It enhances the network security and compliance, as it enforces granular and dynamic policies based on the endpoint identity and context, rather than the network topology and IP addresses.
It improves the network performance and user experience, as it optimizes the network path, load balancing, and traffic engineering based on the network conditions and application requirements.
It enables the network agility and scalability, as it supports the rapid deployment and integration of new devices, applications, and services, without affecting the existing network operations.
References:
Cisco Software-Defined Access - Cisco Software-Defined Access Solution Overview What Is Software-Defined Access? - SD-Access - Cisco Cisco SD-Access Architecture Overview
NEW QUESTION # 14
Winch two primary categories are displayed on the overall health page of the assurance component in the Cisco DNA Center? (Choose two.)
- A. Server
- B. Client
- C. Network
- D. Wired
- E. Access-Distribution
- F. Core
Answer: B,C
NEW QUESTION # 15
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of Scalable Group Tags
- B. use of Endpoint Groups
- C. use of group policy
- D. use of Virtual Network IDs
- E. focus on user endpoints
- F. use of overlays
Answer: A,B,F
Explanation:
Explanation
SD-Access and ACI Fabric are both solutions that provide software-defined networking for different domains.
SD-Access is designed for the campus and branch networks, while ACI Fabric is designed for the data center networks. However, they share some common features and concepts, such as:
Use of Scalable Group Tags: Both SD-Access and ACI Fabric use Scalable Group Tags (SGTs) to identify and classify the endpoints based on their attributes, such as user identity, device type, or application. SGTs are numerical labels that are assigned to the endpoints and carried in the packets, either in the header or in the metadata. SGTs enable granular and dynamic policy enforcement based on the endpoint identity and context, rather than the network topology and IP addresses12.
Use of overlays: Both SD-Access and ACI Fabric use overlays to create a network abstraction layer that decouples the network services and functions from the underlying physical infrastructure. Overlays enable network virtualization and segmentation, as they allow multiple logical networks to coexist on the same physical network. Overlays also simplify the network design and management, as they reduce the complexity and variability of the network elements and interfaces. SD-Access uses VXLAN as the overlay protocol, while ACI Fabric uses VXLAN with EVPN as the overlay protocol34.
Use of Endpoint Groups: Both SD-Access and ACI Fabric use Endpoint Groups (EPGs) to group the endpoints based on their policy requirements and network scope. EPGs are logical containers that define the allowed interactions between the endpoints, such as the protocols, ports, and quality of service.
EPGs also define the network boundaries that isolate the endpoints from each other, based on the security and compliance needs. EPGs are synonymous with Scalable Groups in SD-Access, and they can be mapped between SD-Access and ACI Fabric to enable end-to-end policy across the domains56.
References:
Cisco TrustSec Overview
Cisco TrustSec Configuration Guide, Cisco IOS XE Gibraltar 16.12.x - Scalable Group Tags [Cisco IOS XE 16] - Cisco Cisco SD-Access Architecture Overview Cisco Application Centric Infrastructure Fundamentals, Release 4.0(1) - ACI Fabric Fundamentals
[Cisco Application Policy Infrastructure Controller (APIC)] - Cisco
Cisco SD-Access (SDA) Integration with Cisco Application Centric Infrastructure (ACI) - Cisco Community Cisco Application Centric Infrastructure - Cisco Multidomain Integration At-a-Glance
NEW QUESTION # 16
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of Virtual Network IDs
- B. use of Scalable Group Tags
- C. use of group policy
- D. focus on user endpoints
- E. use of Endpoint Groups
- F. use of overlays
Answer: A,C,F
NEW QUESTION # 17
Which two activities should occur during an SE's discovery process? (Choose two.)
- A. Establishing credibility with the customer
- B. Mapping Cisco innovation to customer's needs
- C. Working with the customer to develop a reference architecture
- D. Referencing the PPDIOO model to effectively facilitate the discussion
- E. Gathering information about the current state of the customer's network environment
Answer: A,E
NEW QUESTION # 18
Which two activities should occur during an SE's discovery process? (Choose two.)
- A. Gathering information about the current state of the customer 's network environment
- B. Working with the customer to develop a reference architecture
- C. Referencing the PPDIOO model to effectively facilitate the discussion
- D. Establishing credibility with the customer
- E. Mapping Cisco innovation to customer 's needs
Answer: A,E
Explanation:
Explanation
The discovery process is a critical phase in the sales cycle, where the SE gathers information about the customer's network environment, business goals, challenges, and needs. The discovery process helps the SE to understand the customer's pain points, identify opportunities, and propose solutions that align with the customer's objectives and address their problems. The discovery process also helps the SE to establish credibility, trust, and rapport with the customer, and to map Cisco innovation to the customer's needs.
Some of the activities that should occur during the SE's discovery process are:
Gathering information about the current state of the customer's network environment. This includes collecting data about the network topology, devices, protocols, applications, performance, security, availability, scalability, and management. The SE can use various tools and methods to gather this information, such as interviews, questionnaires, surveys, audits, assessments, and network analysis tools. Gathering information about the current state helps the SE to understand the customer's existing network capabilities, limitations, and gaps, and to benchmark the network against best practices and industry standards12 Mapping Cisco innovation to the customer's needs. This involves identifying how Cisco products, solutions, and services can help the customer achieve their desired outcomes, address their challenges, and overcome their pain points. The SE can use various tools and methods to map Cisco innovation to the customer's needs, such as value proposition, business case, return on investment (ROI) analysis, proof of value (POV), proof of concept (POC), and demonstrations. Mapping Cisco innovation to the customer's needs helps the SE to show the value and benefits of Cisco solutions, differentiate Cisco from competitors, and influence the customer's decision making34 References:
1: Cisco Discovery Service 2: Cisco Network Assessment Services 3: Cisco Catalyst SD-WAN Demos 4:
Cisco Business Critical Services
NEW QUESTION # 19
How would Cisco ISE handle authentication for your printer that does not have a supplicant?
- A. ISE would authenticate the printer using MAB.
- B. ISE would authenticate the printer using MAC RADIUS authentication.
- C. ISE would authenticate the printer using 802.1X authentication.
- D. ISE would authenticate the printer using web authentication.
- E. ISE would not authenticate the printer as printers are not subject to ISE authentication.
Answer: A
Explanation:
Explanation
Cisco ISE can handle authentication for printers that do not have a supplicant using MAB (MAC Authentication Bypass). MAB is a method of authenticating devices based on their MAC address. MAB is useful for devices that do not support 802.1X or other authentication protocols, such as printers, cameras, or IoT devices. MAB works as follows:
The device sends an Ethernet frame with its MAC address as the source address.
The switch sends a RADIUS Access-Request message to ISE with the MAC address as the username and password.
ISE checks the MAC address against a database of known devices or an identity source sequence.
If the MAC address is found and authorized, ISE sends a RADIUS Access-Accept message to the switch with the appropriate authorization profile.
The switch applies the authorization profile to the device and grants it access to the network.
MAB is less secure than 802.1X, as MAC addresses can be spoofed or cloned. Therefore, MAB should be used with caution and combined with other security measures, such as profiling, posture, or endpoint protection. MAB should also be restricted to specific ports or VLANs that are isolated from the rest of the network.
References:
Cisco Identity Services Engine Administrator Guide, Release 2.7 - Configure MAC Authentication Bypass [Cisco Identity Services Engine] Cisco Identity Services Engine Administrator Guide, Release 2.7 - Manage Authentication Policies
[Cisco Identity Services Engine]
Cisco Identity Services Engine Administrator Guide, Release 2.7 - Manage Authorization Policies
[Cisco Identity Services Engine]
Cisco Identity Services Engine Administrator Guide, Release 2.7 - Manage Identity Source Sequences
[Cisco Identity Services Engine]
Cisco Identity Services Engine API Reference Guide, Release 2.7 - Authentication [Cisco Identity Services Engine] Designing Cisco Enterprise Networks (ENDESIGN) Exam Topics [Cisco] Cisco Validated Design Guides [Cisco]
NEW QUESTION # 20
Which two statements are true regarding SD-WAN demonstrations? (Choose two.)
- A. During a demo, you should demonstrate and discuss what the team considers important details
- B. Use demonstrations primarily for large opportunities and competitive situations
- C. As a Cisco SD-WAN SF, you should you should spend your time learning about the technology rather than contributing to demo innovation
- D. During a demo you should consider the target audience and the desired outcome
- E. There is a big difference between demos that use a top down approach and demos that use a bottom up approach
Answer: B,C
NEW QUESTION # 21
Which Cisco vEdge router offers 20 Gb of encrypted throughput?
- A. Cisco vEdge 5000
- B. Cisco vEdge 2000
- C. Cisco vEdge 1000
- D. Cisco vEdge 100
Answer: A
Explanation:
Explanation
According to the Cisco SD-WAN vEdge Routers Data Sheet1, the Cisco vEdge 5000 router is the only model that offers 20 Gbps of encrypted throughput. The vEdge 5000 router delivers highly secure site-to-site data connectivity to large enterprises, offers interface modularity, and supports up to 4 Network Interface Modules (NIMs)2. The other models of vEdge routers have lower encrypted throughput capacities, as shown in Table 6 of the Ordering Guide for SD-WAN3. The vEdge 1000 router has a maximum encrypted throughput of 1 Gbps, the vEdge 2000 router has a maximum encrypted throughput of 5 Gbps, and the vEdge 100 router has a maximum encrypted throughput of 100 Mbps3.
References:
1: Cisco SD-WAN vEdge Routers Data Sheet 2: vEdge 5000 Router 3: Ordering Guide for SD-WAN
NEW QUESTION # 22
Which element of the Cisco SD-WAN architecture facilitates the functions of controller discovery and NAT traversal?
- A. vManage
- B. vEdge
- C. vSmart controller
- D. vBond orchestrator
Answer: D
Explanation:
Explanation
The vBond orchestrator is an SD-WAN router responsible for authenticating and orchestrating connectivity between the vSmart controllers and SD-WAN routers. It is the sole device in the network that requires a public IP address for all SD-WAN devices to connect to it. The vBond orchestrator has three major functions:
Controller discovery: The vBond orchestrator acts as the initial point of contact for all SD-WAN components that join the network. It authenticates the devices using pre-installed credentials and assigns them to a vSmart controller. The vBond orchestrator also provides the IP addresses of the vSmart controllers and the vManage NMS to the SD-WAN routers.
NAT traversal: The vBond orchestrator facilitates the establishment of secure DTLS or TLS tunnels between the SD-WAN components that are behind NAT devices. The vBond orchestrator acts as a rendezvous point for the NATed devices and helps them exchange their public IP addresses and port numbers. The vBond orchestrator also performs NAT keepalive and hole punching to maintain the NAT bindings and prevent the NAT devices from timing out the sessions.
Certificate management: The vBond orchestrator acts as the certificate authority (CA) for the SD-WAN network. It generates and signs the certificates for the SD-WAN components and distributes them to the devices. The certificates are used to authenticate the devices and encrypt the control and data plane traffic.
References:
Cisco SD-WAN Architecture Overview
Cisco Catalyst SD-WAN Getting Started Guide
New Training: Identify Cisco SD-WAN Components
NEW QUESTION # 23
Which protocol runs between the vSmart controllers and between the vSmart controllers and the vEdge routers, and unifies all control plane functions under a single: protocol umbrella1?
- A. VRRP
- B. IKE
- C. OSPF
- D. BGP
Answer: A
NEW QUESTION # 24
Which two activities should occur during an SE's discovery process? (Choose two.)
- A. Referencing the PPDIOO model to effectively facilitate the discussion
- B. Gathering information about the current state of the customer's network environment
- C. Mapping Cisco innovation to customer's needs
- D. Working with the customer to develop a reference architecture
- E. Establishing credibility with the customer
Answer: A,C
NEW QUESTION # 25
Which three key differentiators that DNA Assurance provides that our competitors are unable match? (Choose three.)
- A. Apple Insights
- B. VXLAN support
- C. Support for Overlay Virtual Transport
- D. On-premise and cloud-based analytics
- E. Network time travel
- F. Proactive approach to guided remediation
Answer: A,E,F
Explanation:
Explanation
Cisco DNA Assurance provides three key differentiators that our competitors are unable to match:
Proactive approach to guided remediation: Cisco DNA Assurance uses AI and machine learning to analyze network data and provide insights on network performance, issues, and optimization. It also offers guided remediation options that automate the process of issue resolution and performance enhancement. This reduces manual troubleshooting operations and saves time and resources for network administrators12.
Apple Insights: Cisco DNA Assurance integrates with Apple devices and applications to provide enhanced visibility and analytics on the user experience and network performance. It also leverages the Fast Lane feature to prioritize critical iOS and macOS traffic over the wireless network. This improves the quality of service and collaboration for Apple users and applications13.
Network time travel: Cisco DNA Assurance allows network administrators to go back in time and view the network state and health at any given point. This enables them to identify the root cause of issues, compare network performance over time, and troubleshoot historical problems. This feature is unique to Cisco DNA Assurance and provides a powerful tool for network analysis and optimization1 .
References:
1: Cisco DNA Assurance: AI/ML guided IT operations (AIOps) At-a-Glance 2: Leveraging Cisco Intent-Based Networking DNA Assurance (DNAAS) 3: Cisco DNA Assurance Unlocking the Power of Data, page 39 : Cisco DNA Assurance Unlocking the Power of Data, page 74
NEW QUESTION # 26
What should you do if you are looking at a strategic win with a customer and the customer wants to examine Cisco ISE for longer than a few weeks?
- A. Give then, some of our flash files mat can be played on any browser
- B. Set them up with a d Cloud account
- C. Provide them to our d Cloud demo library
- D. Provide them with a downloadable POV kit
- E. Set them up with an account on a Cisco UCS server that hosts ISE
- F. Give them our ISE YouTube videos
Answer: E
NEW QUESTION # 27
What are three ways in Which Cisco ISE learns information about devices? (Choose three,)
- A. network servers the device has accessed
- B. SMIP agents
- C. RADIUS attributes
- D. traffic generated by the device
- E. RPC mechanism via HTTPS
- F. user authentication to the ISE
Answer: A,C,D
NEW QUESTION # 28
Which two activities should occur during an SE's demo process? (Choose two.)
- A. asking the customer to provide network drawings or white board the environment for you
- B. determining whether the customer would like to dive deeper during a follow -up
- C. highlighting opportunities that although not currently withinscope would result in lower operational costs and complexity
- D. leveraging a company such as Complete Communications to build a financial case
- E. identifying which capabilities require demonstration
Answer: B,C
NEW QUESTION # 29
......
Verified 500-490 exam dumps Q&As with Correct 37 Questions and Answers: https://www.pass4sures.top/Field-Engineer/500-490-testking-braindumps.html
Get New 500-490 Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=18f1eT0STfdA69LHNU08VwBk22O41uEFd