
Valid 500-490 Practice Test Dumps with 100% Passing Guarantee [May-2024]
500-490 PDF Dumps Are Helpful To produce Your Dreams Correct QA's
NEW QUESTION # 11
Which two statements are true regarding Cisco ISE? (Choose two.)
- A. In two-nodes standalone ISE deployments, failover must be done manually.
- B. ISE supports IPv6 downloadable ACLs.
- C. ISE supports up to 100 Policy Services Nodes.
- D. It distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically.
- E. ISE can detected endpoints whose addresses have been translated via NAT.
- F. The number of logs that ISE can retain is determined by your disk space.
Answer: D,F
NEW QUESTION # 12
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of Virtual Network IDs
- B. focus on user endpoints
- C. use of group policy
- D. use of overlays
- E. use of Scalable Group Tags
- F. use of Endpoint Groups
Answer: A,B,D
NEW QUESTION # 13
Whichtwostatements regarding CiscoSD-WANvEdge routers canmitigate DoS attacks against the infrastructure? (Choose two.)
- A. By default, all incoming traffic is denied at the transport (WAN) side interfaces.
- B. The vEdge routers run on hardened Linux operating systems.
- C. Open Certificate Authority and automated enrollment feature.
- D. In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.
- E. Only authorized controllers are allowed to communicate back to the vEdg e router after the vEdge router establishes connection with the controllers.
Answer: D,E
NEW QUESTION # 14
What are three ways in which Cisco ISE learns information about devices? (Choose three.)
- A. user authentication to the ISE
- B. traffic generated by the device
- C. RADIUS attributes
- D. network servers the device has accessed
- E. SMTP agents
- F. RPC mechanism via HTTPS
Answer: A,B,C
Explanation:
Explanation
Cisco ISE learns information about devices by using various methods, such as network probes, user authentication, and endpoint identity groups. Three ways in which Cisco ISE learns information about devices are:
B: RADIUS attributes: Cisco ISE can use the RADIUS protocol to collect information about devices from network access devices (NADs), such as switches, routers, and wireless controllers. The NADs can send RADIUS accounting packets to Cisco ISE that contain attributes related to the device identity, such as MAC address, IP address, hostname, device type, and vendor. Cisco ISE can use these attributes to profile the device and assign it to an endpoint identity group12.
D: user authentication to the ISE: Cisco ISE can also learn information about devices by authenticating the users who access the network through the devices. Cisco ISE can use various authentication methods, such as 802.1X, MAC Authentication Bypass (MAB), web authentication, or certificate-based authentication, to verify the identity and credentials of the users. Cisco ISE can then associate the user identity with the device identity and apply the appropriate authorization policies based on the user role, device type, and network context34.
E: traffic generated by the device: Cisco ISE can also learn information about devices by analyzing the traffic generated by the devices on the network. Cisco ISE can use various network probes, such as DHCP, SNMP, HTTP, DNS, or NetFlow, to capture and inspect the packets sent by the devices. Cisco ISE can then extract information from the packet headers and payloads, such as device name, operating system, browser type, application name, or domain name, and use it to profile the device and assign it to an endpoint identity group56.
References :
Cisco ISE Profiling Services
Configuring Profiler Policies
Cisco ISE Authentication Services
Configuring Device Sensor for ISE Profiling
Cisco ISE Endpoint Profiling Policies
ISE Profiling Design Guide
NEW QUESTION # 15
WhichCiscoproduct supports SD-Access and specificallybuilt to address new challenges faced by enterprises?
- A. Nexus 7700 w/ Sup2E and M3 line cards
- B. ASR 1000-HX
- C. ISR 4221
- D. Catalyst 6807-XL w/ Sup6T and C6800 10G line cards
- E. Catalyst 9500
- F. CSRv virtual router
Answer: B
NEW QUESTION # 16
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of Scalable Group Tags
- B. use of Virtual Network IDs
- C. focus on user endpoints
- D. use of group policy
- E. use of overlays
- F. use of Endpoint Groups
Answer: A,E,F
Explanation:
Explanation
SD-Access and ACI Fabric are both solutions that provide software-defined networking for different domains.
SD-Access is designed for the campus and branch networks, while ACI Fabric is designed for the data center networks. However, they share some common features and concepts, such as:
Use of Scalable Group Tags: Both SD-Access and ACI Fabric use Scalable Group Tags (SGTs) to identify and classify the endpoints based on their attributes, such as user identity, device type, or application. SGTs are numerical labels that are assigned to the endpoints and carried in the packets, either in the header or in the metadata. SGTs enable granular and dynamic policy enforcement based on the endpoint identity and context, rather than the network topology and IP addresses12.
Use of overlays: Both SD-Access and ACI Fabric use overlays to create a network abstraction layer that decouples the network services and functions from the underlying physical infrastructure. Overlays enable network virtualization and segmentation, as they allow multiple logical networks to coexist on the same physical network. Overlays also simplify the network design and management, as they reduce the complexity and variability of the network elements and interfaces. SD-Access uses VXLAN as the overlay protocol, while ACI Fabric uses VXLAN with EVPN as the overlay protocol34.
Use of Endpoint Groups: Both SD-Access and ACI Fabric use Endpoint Groups (EPGs) to group the endpoints based on their policy requirements and network scope. EPGs are logical containers that define the allowed interactions between the endpoints, such as the protocols, ports, and quality of service.
EPGs also define the network boundaries that isolate the endpoints from each other, based on the security and compliance needs. EPGs are synonymous with Scalable Groups in SD-Access, and they can be mapped between SD-Access and ACI Fabric to enable end-to-end policy across the domains56.
References:
Cisco TrustSec Overview
Cisco TrustSec Configuration Guide, Cisco IOS XE Gibraltar 16.12.x - Scalable Group Tags [Cisco IOS XE 16] - Cisco Cisco SD-Access Architecture Overview Cisco Application Centric Infrastructure Fundamentals, Release 4.0(1) - ACI Fabric Fundamentals
[Cisco Application Policy Infrastructure Controller (APIC)] - Cisco
Cisco SD-Access (SDA) Integration with Cisco Application Centric Infrastructure (ACI) - Cisco Community Cisco Application Centric Infrastructure - Cisco Multidomain Integration At-a-Glance
NEW QUESTION # 17
Which two statements describes Cisco SD-Access? (Choose two.)
- A. an overlay for the wired infrastructure in which traffic is tunneled via a GRE tunnel to a mobility controller for policy and application visibility
- B. an automated encryption/decryption engine for highly secured transport requirements
- C. a collection of tools and applications that are a combination of loose and tight couping
- D. software-defined segmentation and policy enforcement based on user identity and groupmembership
- E. programmable overlays enabling network virtualization across the campus
Answer: D,E
NEW QUESTION # 18
What is the easiest way to enable SD-Access for all your remote sites after you have your campus SD-Access fabric up and running?
- A. Use a separate fabric domain for each site and use SD-WAN a s the underlay.
- B. Threat all the sites as one fabric domain and use SD-WAN as the underlay.
- C. Use a separate fabric domain for each site and use the traditional physical network as theunderlay.
- D. Threat all the sites as one fabric domain and use the traditional physical network as the underlay.
Answer: B
NEW QUESTION # 19
What are the three foundational elements required for the new operational paradigm? (Choose three.)
- A. assurance
- B. application QoS
- C. centralization
- D. policy-based automated provisioning of network
- E. multiple technologies at multiple OSI layers
- F. fabric
Answer: A,D,F
Explanation:
Explanation
The new operational paradigm is a way of designing, deploying, and managing networks that leverages the power of intent-based networking. Intent-based networking is a network architecture that aligns the network with the business goals and policies, and uses artificial intelligence and automation to translate the intent into network configurations and actions. The new operational paradigm requires three foundational elements:
Fabric: A fabric is a network topology that consists of interconnected nodes that provide a consistent and scalable way of delivering network services and functions. A fabric can span across multiple domains, such as campus, branch, data center, and cloud, and can support multiple protocols, such as IP, Ethernet, MPLS, and VXLAN. A fabric enables the network to operate as a single entity, rather than a collection of disparate devices and links. A fabric also simplifies the network design and management, as it reduces the complexity and variability of the network elements and interfaces.
Assurance: Assurance is the process of continuously monitoring, verifying, and optimizing the network performance and behavior, based on the defined intent and policies. Assurance uses telemetry, analytics, and machine learning to collect and process data from the network devices and applications, and to provide insights and recommendations for network optimization and troubleshooting. Assurance also enables the network to self-heal and self-optimize, by applying corrective actions and adjustments to the network configurations and policies, based on the feedback loop from the data and analytics.
Policy-based automated provisioning of network: Policy-based automated provisioning of network is the process of applying the intent and policies to the network devices and services, using automation and orchestration tools. Policy-based automated provisioning of network abstracts the network complexity and heterogeneity, and allows the network operators to define the network requirements and outcomes in a high-level and declarative way, rather than specifying the low-level and imperative commands and parameters. Policy-based automated provisioning of network also enables the network to be agile and adaptive, as it can dynamically adjust the network configurations and policies, based on the changing network conditions and business needs.
References:
Cisco Intent-Based Networking
Cisco Digital Network Architecture
Cisco Routed Optical Networking
Cisco Operational Insights: A New Way of Seeing Operations
NEW QUESTION # 20
What are three ways in which Cisco ISE learns information about devices? (Choose three.)
- A. traffic generated by the device
- B. RPC mechanism via HTTPS
- C. RADIUS attributes
- D. network servers the device has accessed
- E. SMTP agents
- F. user authentication to the ISE
Answer: A,B,C
NEW QUESTION # 21
Which two activities should occur during an SE's discovery process? (Choose two.)
- A. Gathering information about the current state of the customer 's network environment
- B. Working with the customer to develop a reference architecture
- C. Establishing credibility with the customer
- D. Referencing the PPDIOO model to effectively facilitate the discussion
- E. Mapping Cisco innovation to customer 's needs
Answer: A,E
Explanation:
Explanation
The discovery process is a critical phase in the sales cycle, where the SE gathers information about the customer's network environment, business goals, challenges, and needs. The discovery process helps the SE to understand the customer's pain points, identify opportunities, and propose solutions that align with the customer's objectives and address their problems. The discovery process also helps the SE to establish credibility, trust, and rapport with the customer, and to map Cisco innovation to the customer's needs.
Some of the activities that should occur during the SE's discovery process are:
Gathering information about the current state of the customer's network environment. This includes collecting data about the network topology, devices, protocols, applications, performance, security, availability, scalability, and management. The SE can use various tools and methods to gather this information, such as interviews, questionnaires, surveys, audits, assessments, and network analysis tools. Gathering information about the current state helps the SE to understand the customer's existing network capabilities, limitations, and gaps, and to benchmark the network against best practices and industry standards12 Mapping Cisco innovation to the customer's needs. This involves identifying how Cisco products, solutions, and services can help the customer achieve their desired outcomes, address their challenges, and overcome their pain points. The SE can use various tools and methods to map Cisco innovation to the customer's needs, such as value proposition, business case, return on investment (ROI) analysis, proof of value (POV), proof of concept (POC), and demonstrations. Mapping Cisco innovation to the customer's needs helps the SE to show the value and benefits of Cisco solutions, differentiate Cisco from competitors, and influence the customer's decision making34 References:
1: Cisco Discovery Service 2: Cisco Network Assessment Services 3: Cisco Catalyst SD-WAN Demos 4:
Cisco Business Critical Services
NEW QUESTION # 22
Which Cisco vEdge route offers 20 Gb of encrypted throughput?
- A. Cisco vEdge 5000
- B. Cisco vEdge 2000
- C. Cisco vEdge 1000
- D. Cisco vEdge 100
Answer: A
NEW QUESTION # 23
Which three options focus of the current digital business era? (Choose three.)
- A. IoT scale
- B. automation
- C. virtualized services
- D. connectivity
- E. Human scale
- F. centralized enterprise and web applications
Answer: A,B,C
NEW QUESTION # 24
Which three key differentiators that DNA Assurance provides that our competitors are unable match? (Choose three.)
- A. Proactive approach to guided remediation
- B. Support for Overlay Virtual Transport
- C. VXLAN support
- D. Apple Insights
- E. Network time travel
- F. On-premise and cloud-based analytics
Answer: A,D,E
Explanation:
Explanation
Cisco DNA Assurance provides three key differentiators that our competitors are unable to match:
Proactive approach to guided remediation: Cisco DNA Assurance uses AI and machine learning to analyze network data and provide insights on network performance, issues, and optimization. It also offers guided remediation options that automate the process of issue resolution and performance enhancement. This reduces manual troubleshooting operations and saves time and resources for network administrators12.
Apple Insights: Cisco DNA Assurance integrates with Apple devices and applications to provide enhanced visibility and analytics on the user experience and network performance. It also leverages the Fast Lane feature to prioritize critical iOS and macOS traffic over the wireless network. This improves the quality of service and collaboration for Apple users and applications13.
Network time travel: Cisco DNA Assurance allows network administrators to go back in time and view the network state and health at any given point. This enables them to identify the root cause of issues, compare network performance over time, and troubleshoot historical problems. This feature is unique to Cisco DNA Assurance and provides a powerful tool for network analysis and optimization1 .
References:
1: Cisco DNA Assurance: AI/ML guided IT operations (AIOps) At-a-Glance 2: Leveraging Cisco Intent-Based Networking DNA Assurance (DNAAS) 3: Cisco DNA Assurance Unlocking the Power of Data, page 39 : Cisco DNA Assurance Unlocking the Power of Data, page 74
NEW QUESTION # 25
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of Virtual Network IDs
- B. focus on user endpoints
- C. use of overlays
- D. use of group policy
- E. use of Scalable Group Tags
- F. use of Endpoint Groups
Answer: A,C,D
NEW QUESTION # 26
Which two options are primary functions of Cisco ISE? (Choose two.)
- A. providing information about every device that touches the network
- B. automatically enabling, disabling, or reducing allocated power to certain devices
- C. enforcing endpoint compliance with network security policies Q allocating resources
- D. providing VPN access for any type of device
- E. enabling WAN deployment over any type of connection
Answer: A,D
NEW QUESTION # 27
What are the three foundational elements required for the new operational paradigm'? (Choose three.)
- A. policy based automated provisioning of network of
- B. fabric
- C. assurance
- D. centralization
- E. application QoS
- F. multiple technologies at multiple OSI layers
Answer: A,C,E
NEW QUESTION # 28
Which Cisco product were incorporated into Cisco ISE between ISE releases 2.0 and 2.3?
- A. Cisco ASA
- B. Cisco ESA
- C. Cisco ACS
- D. Cisco WSA
Answer: C
Explanation:
Explanation
Cisco ISE incorporated Cisco ACS (Cisco Secure Access Control System) between ISE releases 2.0 and 2.3.
Cisco ACS was a network access policy platform that provided authentication, authorization, and accounting (AAA) services for network devices and users. Cisco ACS was discontinued in 2017 and replaced by Cisco ISE, which offers more advanced features and capabilities for identity-based network access control. Cisco ISE provides a migration tool that allows customers to migrate their data and configurations from Cisco ACS to Cisco ISE. The migration tool supports Cisco ACS versions 5.5, 5.6, 5.7, and 5.8 and Cisco ISE versions
2.0, 2.1, 2.2, and 2.3.
References:
Cisco Secure Access Control System End-of-Life Announcement [Cisco Secure Access Control System] Cisco Secure ACS to Cisco ISE Migration Tool [Cisco Identity Services Engine] Cisco Identity Services Engine Administrator Guide, Release 2.3 - Cisco Secure ACS to Cisco ISE Migration [Cisco Identity Services Engine] Cisco Identity Services Engine Administrator Guide, Release 2.3 - Manage Migration [Cisco Identity Services Engine]
[Cisco Identity Services Engine Migration Guide, Release 2.3 [Cisco Identity Services Engine]]
[Designing Cisco Enterprise Networks (ENDESIGN) Exam Topics [Cisco]]
[Cisco Validated Design Guides [Cisco]]
NEW QUESTION # 29
Which two activities should occur during an SE's demo process? (Choose two.)
- A. asking the customer to provide network drawings or white board the environment for you
- B. identifying which capabilities require demonstration
- C. leveraging a company such as Complete Communications to build a financial case.
- D. highlighting opportunities that although not currently within scope would result in lower operational costs and complexity
- E. determining whether the customer would like to drive deeper during a follow up
Answer: B,D
NEW QUESTION # 30
Which component of the SD-Access fabric is responsible for communicating with networks that are external to the fabric?
- A. edge nodes
- B. intermediate nodes
- C. border nodes
- D. control plane nodes
Answer: C
Explanation:
Explanation
= Border nodes are the component of the SD-Access fabric that is responsible for communicating with networks that are external to the fabric. Border nodes serve as the gateway between the fabric domain and the network outside of the fabric. Border nodes are responsible for network virtualization inter-working and SGT propagation from the fabric to the rest of the network1. Border nodes also perform LISP Proxy Tunnel Router (PxTR) functions, which convert policy and reachability information, such as SGT and VRF information, from one domain to another2. Border nodes can connect to internal networks, such as data center or WAN, or external networks, such as internet or cloud3.
Edge nodes, control plane nodes, and intermediate nodes are not responsible for communicating with networks that are external to the fabric. Edge nodes are the access-layer switches where all of the endpoints reside. Edge nodes detect clients and register them with the control plane nodes. Edge nodes also provide an anycast L3 gateway for the connected endpoints and perform encapsulation and de-encapsulation of data traffic4. Control plane nodes are the devices that run a host tracking database to map location information. Control plane nodes receive endpoint ID map registrations from edge and/or border nodes and resolve lookup requests from edge and/or border nodes to locate destination endpoint IDs5. Intermediate nodes are the devices that provide underlay connectivity between edge nodes and border nodes. Intermediate nodes do not participate in the fabric overlay and do not have any fabric roles6.
References :=
Role of Fabric Border Node & IS-IS protocol in Cisco SD-Access
Software Defined Access Network Fabric Roles - Study CCNP
Cisco SD-Access
SD-Access Fabric Troubleshooting Guide - Cisco
Cisco SD-Access Solution Design Guide (CVD) - Cisco
Cisco SD-Access Solution Design Guide (CVD) - Cisco
Cisco SD-Access Solution Design Guide (CVD) - Cisco
NEW QUESTION # 31
Which are two Cisco ISE that benefits our customers? (Choose two.)
- A. helps them stop and contain real-time threats
- B. provides network access control
- C. enables them to set traffic priorities across the network
- D. helps them accelerate application deployment and delivery
Answer: A,B
NEW QUESTION # 32
......
Cover 500-490 Exam Questions Make Sure You 100% Pass: https://www.actualcollection.com/500-490-exam-questions.html