Passing Cisco 500-220 Exam Using 2023 Practice Tests
500-220 Study Guide Brilliant 500-220 Exam Dumps PDF
NEW QUESTION # 16
Refer to the exhibit.
Which design recommendation should be considered?
- A. A 25-percent throughput loss occurs for every hop. Cisco Meraki best practice recommends a 2-hop maximum.
- B. A 25-percent throughput loss occurs for every hop. Cisco Meraki best practice recommends a 1-hop maximum.
- C. A 50-percent throughput loss occurs for every hop. Cisco Meraki best practice recommends a 1-hop maximum.
- D. A 50-percent throughput loss occurs for every hop. Cisco Meraki best practice recommends a 2-hop maximum.
Answer: B
NEW QUESTION # 17
What are two methods of targeting and applying management profiles to System Manager clients? (Choose two.)
- A. by using Wi-Fi tags
- B. by using dynamic IP tags
- C. by using device tags
- D. by defining the scope
- E. by defining a range of serial numbers
Answer: C,D
Explanation:
Explanation
The correct answer is B and D. These are the two methods of targeting and applying management profiles to System Manager clients, according to the [System Manager: Getting Started] article. The article explains that:
Defining the scope: This method allows you to target devices based on their network, tag, or owner. You can define the scope of a profile from the Systems Manager > Manage > Settings page or from the Systems Manager > Monitor > Overview page.
Using device tags: This method allows you to target devices based on their attributes, such as OS, model, location, or user. You can use device tags to create dynamic groups of devices that share common characteristics. You can apply device tags from the Systems Manager > Monitor > Devices page or from the Systems Manager > Manage > Tags page.
NEW QUESTION # 18
Which Meraki Dashboard menu section is accessed to enable Sentry enrollment on an SSID?
- A. Wireless > Configure > SSIDs
- B. Wireless > Configure > Firewall & Traffic Shaping
- C. Wireless > Configure > Access Control
- D. Wireless > Configure > Splash page
Answer: C
NEW QUESTION # 19
What is the best practice Systems Manager enrollment method when deploying corporate-owned iOS devices?
- A. DEP
- B. Apple Configurator
- C. Sentry enrollment
- D. manual
Answer: B
NEW QUESTION # 20
Which Meraki Dashboard menu section is accessed to enable Sentry enrollment on an SSID?
- A. Wireless > Configure > SSIDs
- B. Wireless > Configure > Firewall & Traffic Shaping
- C. Wireless > Configure > Access Control
- D. Wireless > Configure > Splash page
Answer: C
Explanation:
Explanation
SM Sentry enrollment can be enabled on any MR network via the Splash page section of the Wireless > Configure > Access control page.
https://documentation.meraki.com/MR/MR_Splash_Page/Systems_Manager_Sentry_Enrollment
NEW QUESTION # 21
Which Cisco Meraki best practice method preserves complete historical network event logs?
- A. Configuring a syslog server for the network.
- B. Configuring the preserved event number to maximize logging.
- C. Configuring Dashboard logging to preserve only certain event types.
- D. Configuring the preserved event period to unlimited.
Answer: A
Explanation:
Explanation
Configuring a syslog server for the network is the Cisco Meraki best practice method to preserve complete historical network event logs. A syslog server can be configured to store messages for reporting purposes from MX Security Appliances, MR Access Points, and MS switches1. The syslog server can collect various types of events, such as VPN connectivity, uplink connectivity, DHCP leases, firewall rules, IDS alerts, and security events2. The syslog server can also help with troubleshooting and monitoring the network performance and security.
NEW QUESTION # 22
Which two primary metrics does Meraki Insight use to calculate the Application Performance Score? (Choose two.)
- A. Maximum Jitter
- B. Per-flow Goodput
- C. Maximum Latency
- D. Total Bandwidth Usage
- E. Application Response Time
Answer: B,E
NEW QUESTION # 23
For which two reasons can an organization become "Out of License"? (Choose two.)
- A. licenses that are in the wrong network
- B. more hardware devices than device licenses
- C. MR licenses that do not match the MR models in the organization
- D. expired device license
- E. licenses that do not match the serial numbers in the organization
Answer: B,D
Explanation:
More hardware devices than device licenses: An organization needs to have enough device licenses to cover all the hardware devices in its network. A device license is consumed by each device that is added to the network. If the number of devices exceeds the number of licenses, the organization will be out of license and will lose access to some features and support until it purchases more licenses or removes some devices4.
Expired device license: A device license has an expiration date that depends on the license term purchased by the organization. If a device license expires, it will no longer be valid and will not count towards the license limit. The organization will need to renew the expired license or purchase a new one to avoid being out of license4.
NEW QUESTION # 24
Which three verbs of request are available in the Cisco Meraki API? (Choose three.)
- A. ADD
- B. POST
- C. PUT
- D. PATCH
- E. SET
- F. GET
Answer: B,C,F
Explanation:
Explanation
Verbs in the API follow the usual REST conventions:
GET returns the value of a resource or a list of resources, depending on whether an identifier is specified.
POST adds a new resource
PUT updates a resource
DELETE removes a resource
https://documentation.meraki.com/General_Administration/Other_Topics/Cisco_Meraki_Dashboard_API
NEW QUESTION # 25
Refer to the exhibit.
For an AP that displays this alert, which network access control method must be in use?
- A. preshared key
- B. splash page with my RADIUS server
- C. WPA2-enterprise with my RADIUS server
- D. MAC-based access control with RADIUS server
Answer: C
Explanation:
Explanation
This is because the alert mentions 802.1X failure, which is a network access control method that is used with WPA2-enterprise and RADIUS servers1.
This question is related to the topic of Wireless Access Points Quick Start in the Cisco Meraki documentation.
You can find more information about this topic in the Wireless Access Points Quick Start article or the Using the Cisco Meraki Device Local Status Page page.
NEW QUESTION # 26
A new application needs to be pushed to all iOS devices. Some devices report "NotNow" in the event log and do not install the application.
What does the "NotNow" event indicate?
- A. The device cannot connect to Cisco Meraki servers.
- B. The device cannot connect to Apple servers.
- C. The device is locked with a passcode.
- D. The application requires the most recent iOS version.
Answer: C
Explanation:
Explanation
The error message "NotNow" is seen in the Event Log on an iOS device's details page when an action cannot be performed because the device is locked with a passcode. These actions include pushing managed apps, installing profiles, and other actions. When this occurs the device will attempt to re-connect with the MDM server as soon as the device is unlocked in order to retry the action.
https://documentation.meraki.com/SM/Monitoring_and_Reporting/Status_of_%22NotNow%22_in_Systems_Ma
NEW QUESTION # 27
Refer to the exhibit.
Assuming this MX has established a full tunnel with its VPN peer, how will the MX route the WebEx traffic?
- A. WebEx traffic will be load-balanced between both active WAN links.
- B. WebEx traffic will prefer WAN 2 as long as it meets the thresholds in the "Conf" performance class.
- C. WebEx traffic will prefer WAN 2 as long as it is up.
- D. WebEx traffic will prefer WAN 1 as it is the primary uplink.
Answer: B
Explanation:
Explanation
Assuming this MX has established a full tunnel with its VPN peer, the MX will route the WebEx traffic based on the SD-WAN policy configured in the exhibit. The SD-WAN policy has two performance classes: Conf and Default. The Conf performance class matches the traffic with destination port 9000, which is used by WebEx for VoIP and video RTP3. The Conf performance class has a preferred uplink of WAN 2 and a failover uplink of WAN 1. It also has thresholds for latency, jitter, and loss that determine when to switch from the preferred uplink to the failover uplink. Therefore, the WebEx traffic will prefer WAN 2 as long as it meets the thresholds in the Conf performance class. If WAN 2 exceeds the thresholds or goes down, the WebEx traffic will switch to WAN 1 as the failover uplink.
NEW QUESTION # 28
What are two ways peers interact with ports that Auto VPN uses? (Choose two.)
- A. For IPsec tunneling, peers use high TCP ports within the 32768 to 61000 range.
- B. For IPsec tunneling, peers use high UDP ports within the 32768 to 61000 range.
- C. Peers contact the VPN registry at TCP port 9350.
- D. Peers contact the VPN registry at UDP port 9350.
- E. For IPsec tunneling, peers use UDP ports 500 and 4500.
Answer: A,D
Explanation:
Reference:
_Configuration_and_Troubleshooting
NEW QUESTION # 29
Drag and drop the steps from the left into the sequence on the right to manage device control, according to Cisco Meraki best practice.
Answer:
Explanation:
NEW QUESTION # 30
Refer to the exhibit.
This Dashboard organization uses Co-Termination licensing model.
What happens when an additional seven APs are claimed on this network without adding licenses?
- A. All APs stop functioning in 30 days.
- B. All APs immediately stop functioning.
- C. All network devices stop functioning in 30 days.
- D. One AP Immediately stops functioning.
Answer: C
NEW QUESTION # 31
Which information do the MXs in a High Availability pair share?
- A. stateful firewall database
- B. DHCP association database
- C. spanning-tree state
- D. time synchronization state
Answer: C
NEW QUESTION # 32
What are two roles of the network and device tags in a Dashboard? (Choose two.)
- A. Device tags can be assigned to MR APs to influence the gateway selection for repeaters in a mesh wireless network.
- B. Network tags can be used to simplify the assignment of network-level permissions in an Organization with many networks.
- C. Network tags can be used to assign networks to separate Auto VPN domains in an Organization with many networks.
- D. Tags enable administrators to configure a combination of network and device specific tags to create summary reports filtered for specific devices across multiple networks.
- E. Device tags can be used to simplify the assignment of device-level permissions in an Organization with many administrators.
Answer: A,D
Explanation:
Reference:
Organization_Menu/Manage_Tags
NEW QUESTION # 33
A customer requires a hub-and-spoke Auto VPN deployment with two NAT-mode hubs with dual uplink connections and 50 remote sites with a single uplink connection.
How many tunnels does each hub need to support?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
Explanation:
Explanation
https://documentation.meraki.com/Architectures_and_Best_Practices/Auto_VPN_Hub_Deployment_Recommen This is the number of tunnels that each hub needs to support in a hub-and-spoke Auto VPN deployment with two NAT-mode hubs with dual uplink connections and 50 remote sites with a single uplink connection. This can be calculated by using the formula for the hub tunnel count in a hub-and-spoke topology1:
Hub Tunnel Count = (H x (H - 1) / 2 x L1) + (H x S x L1 x L2)
Where H is the number of hubs, S is the number of spokes, L1 is the number of uplinks for the hubs, and L2 is the number of uplinks for the spokes. In this case, H = 2, S = 50, L1 = 2, and L2 = 1. Therefore, Hub Tunnel Count = (2 x (2 - 1) / 2 x 2) + (2 x 50 x 2 x 1) Hub Tunnel Count = (2 x 1 / 2 x 2) + (200 x 2) Hub Tunnel Count = (2 / 2 x 2) + (400) Hub Tunnel Count = (1 x 2) + (400) Hub Tunnel Count = 2 + 400 Hub Tunnel Count = 402 This question is related to the topic of Auto VPN Hub Deployment Recommendations in the Cisco Meraki documentation. You can find more information about this topic in the Auto VPN Hub Deployment Recommendations article or the Meraki Auto VPN General Best Practices page.
NEW QUESTION # 34
The WAN connection of a Cisco Meraki MX security appliance is congested, and the MX appliance is buffering the traffic from LAN ports going to the WAN ports. High, normal, and low priority queue buffers are all full. Which proportion of the normal traffic is forwarded compared to the other queues?
- A. 2/7 packets
- B. 4/10 packets
- C. 5/15 packets
- D. 2/10 packets
Answer: A
Explanation:
Explanation
https://documentation.meraki.com/MX/Firewall_and_Traffic_Shaping/SD-WAN_and_Traffic_Shaping
NEW QUESTION # 35
What occurs when a configuration change is made to an MX network that is bound to a configuration template?
- A. The configuration change in the bound network is combined with the template configuration inside the template.
- B. The template configuration overrides the configuration change in the bound network.
- C. The configuration change in the bound network overrides the template configuration.
- D. The more restrictive configuration is preferred.
Answer: C
Explanation:
Explanation
https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/Best
NEW QUESTION # 36
Air Marshal has contained a malicious SSID.
What are two effects on connectivity? (Choose two.)
- A. Currently associated clients stay connected.
- B. Currently associated clients are affected by restrictive traffic shaping rules.
- C. Currently associated clients are disconnected.
- D. New clients cannot connect.
- E. New clients can connect.
Answer: C,D
Explanation:
Explanation
When a rogue access point is contained, clients will be unable to connect to the rogue AP. Additionally, any currently associated clients will lose their connection to the rogue AP.
https://documentation.meraki.com/MR/Monitoring_and_Reporting/Air_Marshal
NEW QUESTION # 37
Which information is used to calculate whether a WAN link has high usage?
- A. data under Security & SD WAN > Appliance Status > Uplink > Live Data
- B. total number of devices that are actively passing traffic
- C. value under Security & SD WAN > SD WAN & Traffic Shaping > Uplink Configuration
- D. total historical throughput of an uplink
Answer: C
NEW QUESTION # 38
Refer to the exhibit.
The VPN concentrator is experiencing issues. Which action should be taken to ensure a stable environment?
- A. Remove the connection from Internet 1.
- B. Physically disconnect all LAN ports.
- C. Add a deny any/any firewall rule to the end of the firewall rules.
- D. Configure the MX appliance to Routed mode on the Addressing & VLANS page.
Answer: B
NEW QUESTION # 39
Which two Systems Manager Live tools are available only for Apple Macs and Windows PCs and cannot be used on iOS or Android mobile devices? (Choose two.)
- A. Send notification
- B. OS updates
- C. Remote Desktop
- D. Selective wipe
- E. Screenshot
Answer: C,D
NEW QUESTION # 40
......
Free 500-220 Test Questions Real Practice Test Questions: https://examschief.vce4plus.com/Cisco/500-220-valid-vce-dumps.html