
Updated Dec-2024 Test Engine to Practice 500-490 Test Questions
500-490 Real Exam Questions Test Engine Dumps Training With 37 Questions
Cisco 500-490 exam covers a range of topics that are essential for designing and implementing enterprise networks. Candidates are tested on their knowledge of network design principles, including designing for high availability, scalability, and performance. They are also tested on their ability to design wireless networks, including planning and implementing wireless access points, controllers, and management systems.
Cisco 500-490 certification exam is an essential credential for IT professionals who are looking to specialize in designing Cisco enterprise networks. By passing 500-490 exam, candidates can demonstrate their expertise in designing and implementing complex network infrastructures using Cisco technologies, which can help them advance their careers and increase their earning potential.
Cisco 500-490 exam covers a range of topics related to enterprise network design, including network infrastructure design, security, wireless, and automation. Candidates are expected to have a deep understanding of network protocols and technologies, as well as the ability to design and implement complex network solutions.
NEW QUESTION # 14
Which two statements describes Cisco SD-Access? (Choose two.)
- A. a collection of tools and applications that are a combination of loose and tight couping
- B. an overlay for the wired infrastructure in which traffic is tunneled via a GRE tunnel to a mobility controller for policy and application visibility
- C. software-defined segmentation and policy enforcement based on user identity and group membership
- D. an automated encryption/decryption engine for highly secured transport requirements
- E. programmable overlays enabling network virtualization across the campus
Answer: C,E
Explanation:
Cisco SD-Access is a solution within Cisco DNA, which is built on intent-based networking principles. Cisco SD-Access provides visibility-based, automated end-to-end segmentation to separate user, device, and application traffic without redesigning the underlying physical network1. Cisco SD-Access also enables programmable overlays that allow network virtualization across the campus,branch, data center, and cloud2. Cisco SD-Access has two main components: the fabric and the policy3.
The fabric is the network overlay that consists of interconnected nodes that provide a consistent and scalable way of delivering network services and functions. The fabric nodes are classified into four types: edge nodes, border nodes, control plane nodes, and intermediate nodes. The edge nodes are the access switches or wireless controllers that connect to the end devices. The border nodes are the routers or switches that connect the fabric to external networks, such as the Internet, WAN, or data center. The control plane nodes are the routers or switches that maintain the mapping between the endpoint identifiers and the network locators. The intermediate nodes are the routers or switches that provide transit services within the fabric3.
The policy is the network configuration that defines the network behavior and outcomes, based on the business intent and requirements. The policy is composed of three elements: the endpoint groups, the contracts, and the virtual networks. The endpoint groups are the logical containers that group the endpoints based on their attributes, such as user identity, device type, or application. The contracts are the rules that specify the allowed interactions between the endpoint groups, such as the protocols, ports, and quality of service. The virtual networks are the logical partitions that isolate the endpoint groups and contracts from each other, based on the network scope and security3.
Cisco SD-Access addresses the following challenges and benefits:
* It simplifies the network design and management, as it reduces the complexity and variability of the network elements and interfaces.
* It enhances the network security and compliance, as it enforces granular and dynamic policies based on the endpoint identity and context, rather than the network topology and IP addresses.
* It improves the network performance and user experience, as it optimizes the network path, load balancing, and traffic engineering based on the network conditions and application requirements.
* It enables the network agility and scalability, as it supports the rapid deployment and integration of new devices, applications, and services, without affecting the existing network operations.
References:
* Cisco Software-Defined Access - Cisco Software-Defined Access Solution Overview
* What Is Software-Defined Access? - SD-Access - Cisco
* Cisco SD-Access Architecture Overview
NEW QUESTION # 15
Which element of the Cisco SD-WAN architecture facilitates the functions of controller discovery and NAT traversal?
- A. vManage
- B. vSmart controller
- C. vBond orchestrator
- D. vEdge
Answer: C
NEW QUESTION # 16
Which is a function of lite Proactive Insights feature of Cisco DNA Center Assurance'?
- A. enabling you to quickly view all of the contextual information related to the end application
- B. enabling you to see the complete path of packets from the client to the end application
- C. pointing out where the most serious issues are happening in the network
- D. generating synthetic traffic to perform tests that raise awareness of potential network issues
Answer: B
NEW QUESTION # 17
Which are two Cisco recommendations that demonstrates SDA? (Choose two.)
- A. Be sure you explain the major technologies such as VXLAN and LISP in depth.
- B. Use the CLI to perform as much of the configuration as possible.
- C. Focus on business benefit s.
- D. Show the customer how to integrate ISE into DNA Center at the end of the demo.
- E. Keep the demo at a high level.
Answer: D,E
Explanation:
When demonstrating Cisco Software-Defined Access (SDA), it's essential to tailor the presentation to highlight the strategic benefits and overall architecture without overwhelming the audience with excessive technical details. Two key recommendations for a successful SDA demonstration are:
* Keep the demo at a high level (Option B):It's crucial to keep the demonstration focused on the overarching concepts and benefits rather than delving into the intricate technical details. This approach ensures that the audience, which may include decision-makers and non-technical stakeholders, can easily grasp the value and advantages of SDA. By presenting at a high level, you can effectivelycommunicate how SDA simplifies network management, enhances security, and supports digital transformation initiatives.
* Show the customer how to integrate ISE into DNA Center at the end of the demo (Option E):
Integrating Cisco Identity Services Engine (ISE) with Cisco DNA Center is a pivotal aspect of the SDA solution. Demonstrating this integration towards the end of the presentation allows you to showcase the seamless interoperability and added security benefits that ISE brings to the SDA environment. This part of the demo highlights how ISE enhances network access control, policy enforcement, and overall security management within the SDA framework.
References:
* Cisco Software-Defined Access Solution Overview
* Cisco DNA Center and ISE Integration Guide
NEW QUESTION # 18
How would cisco ISE handle authentication for your printer that does not have a supplicant?
- A. ISE would authenticate the printer using MAC RADIUS authentication
- B. ISE would not authenticate the printer as printers are not subject to ISE authentication.
- C. ISE would authenticate the printer using 8.2.1X authentication
- D. ISE would authenticate the printer using web authentication.
- E. ISE would authenticate the printer using MAB.
Answer: C
NEW QUESTION # 19
Which two activities should occur during an SE's discovery process? (Choose two.)
- A. Working with the customer to develop a reference architecture
- B. Gathering information about the current state of the customer 's network environment
- C. Mapping Cisco innovation to customer 's needs
- D. Referencing the PPDIOO model to effectively facilitate the discussion
- E. Establishing credibility with the customer
Answer: B,C
NEW QUESTION # 20
Which two primary categories are displayed on the overall health page of the assurance component in the Cisco DNA Center? (Choose two.)
- A. Server
- B. Core
- C. Access-Distribution
- D. Wired
- E. Network
- F. Client
Answer: E,F
Explanation:
Explanation
The overall health page of the assurance component in the Cisco DNA Center displays two primary categories: Client and Network1. The Client category shows the health score of all the wired and wireless clients connected to the network, along with the number of clients, the top issues affecting the clients, and the distribution of clients by type, OS, and SSID1. The Network category shows the health score of all the network devices, such as switches, routers, wireless controllers, and access points, along with the number of devices, the top issues affecting the devices, and the distribution of devices by site, family, and role1.
The other options are not primary categories on the overall health page. Server is not a category, but a type of client that can be filtered in the Client category1. Access-Distribution and Core are not categories, but roles of network devices that can be filtered in the Network category1. Wired is not a category, but a subcategory of the Client category that shows the health score of the wired clients only1.
References:
Cisco DNA Assurance User Guide, Release 1.3.1.0 - Monitor and Troubleshoot the Health of Your Network [Cisco DNA Center] Designing Cisco Enterprise Networks (ENDESIGN) Exam Topics [Cisco] Cisco Validated Design Guides [Cisco]
NEW QUESTION # 21
What is the easiest way to enable SD-Access for all your remote sites after you have your campus SD-Access fabric up and running?
- A. Use a separate fabric domain for each site and use the traditional physical network as the underlay.
- B. Use a separate fabric domain for each site and use SD-WAN a s the underlay.
- C. Threat all the sites as one fabric domain and use SD-WAN as the underlay.
- D. Threat all the sites as one fabric domain and use the traditional physical network as the underlay.
Answer: D
Explanation:
SD-Access - High Level Branch Design-Software Defined Access @
0:34https://salesconnect.cisco.com/sc/s/learning-activity-from-plan?ltui__urlRecordId=a0c8c00000O0wmZAAR
https://www.ciscolive.com/c/dam/r/ciscolive/apjc/docs/2020/pdf/BRKCRS-3493.pdf
NEW QUESTION # 22
Which two statements are true regarding SD-WAN demonstrations? (Choose two.)
- A. As a Cisco SD-WAN SE, you should you should spend your time learning about the technology rather than contributing to demo innovation.
- B. During a demo, you should demonstrate and discuss what the team considers important details.
- C. There is a big difference between demos that use a top down approach and demos that use a bottom up approach.
- D. Use demonstrations primarily for large opportunities and competitive situations.
- E. During a demo, you should consider the target audience and the desired outcome.
Answer: C,E
Explanation:
Explanation
SD-WAN demonstrations are an effective way to showcase the benefits and features of Cisco SD-WAN solutions to potential customers. However, not all demos are created equal, and there are some best practices to follow to ensure a successful and engaging demo. Here are some explanations for why C and E are true statements regarding SD-WAN demonstrations:
C: During a demo, you should consider the target audience and the desired outcome. This is a true statement because different audiences may have different levels of technical knowledge, business needs, and expectations from the demo. For example, a demo for a C-level executive may focus more on the business outcomes and value proposition of SD-WAN, while a demo for a network engineer may dive deeper into the technical details and configuration options. Therefore, it is important to tailor the demo to the specific audience and the desired outcome, such as generating interest, building trust, or closing a deal.
E: There is a big difference between demos that use a top down approach and demos that use a bottom up approach. This is also a true statement because the two approaches have different advantages and disadvantages, and may suit different scenarios. A top down approach starts with the high-level overview of the SD-WAN solution, such as the architecture, components, benefits, and use cases, and then drills down into the specific features and functionalities. A bottom up approach starts with the low-level details of the SD-WAN solution, such as the configuration, troubleshooting, and testing, and then builds up to the big picture and value proposition. A top down approach may be more suitable for a non-technical or business-oriented audience, while a bottom up approach may be more suitable for a technical or hands-on audience.
References :=
Cisco SD-WAN Demonstration Guide
SD-WAN Best Practices | Kentik Blog
SD-WAN best practices for a successful implementation
SD-WAN best practices - VMware Blogs
NEW QUESTION # 23
What statement is true regarding the current time in Enterprise Networking history?
- A. pace of change
- B. advent of cloud computing
- C. pervasive use of mobile devices
- D. advent of loT
Answer: A
NEW QUESTION # 24
Which two statements regarding Cisco SD-WAN vEdge routers can mitigate DoS attacks against the infrastructure? (Choose two.)
- A. Open Certificate Authority and automated enrollment feature.
- B. The vEdge routers run on hardened Linux operating systems.
- C. By default, all incoming traffic is denied at the transport (WAN) side interfaces.
- D. In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.
- E. Only authorized controllers are allowed to communicate back to the vEdge router after the vEdge router establishes connections with the controllers.
Answer: D,E
Explanation:
* https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKRST-2377.pdf
NEW QUESTION # 25
Which two statements describes Cisco SD-Access? (Choose Two.)
- A. a collection of tools and applications that are a combination of loose and tight coupling
- B. software-defined segmentation and policy enforcement based on user identity and group membership
- C. an overlay for the wired infrastructure in which traffic is tunneled via a GRF tunnel lo a mobility controller for policy and application visibility.
- D. an automated encryption/decryption engine for highly secured transport requirements
- E. programmable overlays enabling network virtualization across the campus
Answer: B,E
NEW QUESTION # 26
Which two statements are true regarding Cisco ISE? (Choose two.)
- A. In two-node standalone ISE deployments, failover must be done manually.
- B. ISE supports up to 100 Policy Services Nodes.
- C. The number of logs that ISE can retain is determined by your disk space.
- D. ISE can detected endpoints whose addresses have been translated via NAT.
- E. In distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically.
- F. ISE supports IPv6 downloadable ACLs.
Answer: C,D
Explanation:
Explanation
Cisco ISE is a security policy management platform that provides secure access to network resources. Cisco ISE functions as a policy decision point and enables enterprises to ensure compliance, enhance infrastructure security, and streamline service operations1. Two of the statements that are true regarding Cisco ISE are:
ISE can detect endpoints whose addresses have been translated via NAT: Cisco ISE can discover, profile, and monitor the endpoint devices on the network, and classify them according to their associated policies and identity groups. Cisco ISE can leverage the pxGrid framework to share the contextual information with other security tools and platforms, and enhance the network visibility and security1. Cisco ISE can also detect endpoints whose addresses have been translated via NAT by using various methods, such as passive and active discovery, NMAP scanning, DHCP snooping, and RADIUS accounting234.
The number of logs that ISE can retain is determined by your disk space: Cisco ISE provides a logging mechanism that is used for auditing, fault management, and troubleshooting. The logging mechanism helps you to identify fault conditions in deployed services and troubleshoot issues efficiently. You can configure your Cisco ISE node to collect the logs in the local systems using a virtual loopback address5. The number of logs that ISE can retain is determined by your disk space, as well as the data purging settings that you can configure under Administration > System > Maintenance > Data Purging6. You can also configure Cisco ISE to send its logs to a remote system for greater retention history7.
The other statements are not true regarding Cisco ISE, because:
In distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically: Cisco ISE supports high availability for the Administration persona, which provides centralized configuration and management of the distributed deployment. You can configure one primary Administration ISE node and one secondary Administration ISE node for high availability. However, the failover from primary to secondary Policy Administration Nodes does not happen automatically, unless you enable the automatic failover feature and configure a health check node to monitor the primary node's status8. Otherwise, you have to manually promote the secondary node to become the primary node in case of a failure9.
In two-node standalone ISE deployments, failover must be done manually: Cisco ISE supports high availability for the Policy Service persona, which provides network access, posture, guest access, client provisioning, and profiling services. You can configure multiple Policy Service Nodes (PSNs) in a node group to provide session failover and load balancing for the endpoints. In a two-node standalone ISE deployment, where each node assumes all the personas, the failover for the Policy Service persona does not need to be done manually, as long as the network access devices are configured to use both nodes for RADIUS and TACACS services10.
ISE supports IPv6 downloadable ACLs: Cisco ISE supports downloadable ACLs (DACLs), which are configured and implemented through authorization profiles. DACLs are used to enforce granular access control policies for the endpoints based on their identity and other attributes. However, Cisco ISE does not support IPv6 downloadable ACLs, as it only supports IPv4 ACLs for RADIUS and TACACS protocols1112.
References:
1: Cisco Content Hub - Cisco ISE Features 2: Cisco ISE Profiler Service Overview 3: ISE Deployment through NAT Boundaries - Cisco Community 4: Configure ISE 3.3 Native IPSec to Secure NAD (IOS-XE) Communication - Cisco 5: Logging [Cisco Identity Services Engine] - Cisco Systems 6: ISE maximum logging time / data retention - Cisco Community 7: Logs retention on ISE - Cisco Community 8: Cisco Identity Services Engine Administrator Guide, Release 2.4 9: Setting Up Cisco ISE in a Distributed Environment 10: Cisco Content Hub - Network Deployments in Cisco ISE 11: Cisco Identity Services Engine Administrator Guide, Release 2.2 12: Solved: ISE: support for IPv6 DACL's - Cisco Community
NEW QUESTION # 27
What statement is true regarding the current time in Enterprise Networking history?
- A. pace of change
- B. advent of cloud computing
- C. pervasive use of mobile devices
- D. advent of loT
Answer: A
Explanation:
The current time in enterprise networking history is characterized by the rapid pace of change in the network technologies, architectures, and services. Some of the factors that contribute to this change are:
* The increasing demand for network performance, scalability, reliability, security, and agility from the business and end users.
* The emergence of new network paradigms, such as software-defined networking (SDN), network function virtualization (NFV), cloud networking, and intent-based networking (IBN).
* The proliferation of network devices, applications, and data sources, such as the Internet of Things (IoT), mobile devices, cloud services, big data, and artificial intelligence (AI).
* The evolution of network standards, protocols, and best practices, such as IPv6, 5G, Wi-Fi 6, Ethernet, and network automation.
These factors create new opportunities and challenges for enterprise network designers, engineers, and administrators, who need to keep up with the latest trends and innovations, and adapt their network solutions to the changing business and technical requirements.
References:
Cisco Enterprise Network Architecture and Design,
https://www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/enterprise-networking-design.ht Enterprise Networking Explained: Types, Concepts & Trends,
https://www.bmc.com/blogs/enterprise-networking/2 : What is enterprise networking?,
https://www.cloudflare.com/learning/network-layer/enterprise-networking/3 : Enterprise WAN - A Brief History,https://blogs.juniper.net/en-us/enterprise-cloud-and-transformation/enterprise-wan-a-brief-history4
NEW QUESTION # 28
Which Cisco product were incorporated into Cisco ISE between ISE releases 2.0 and 2.3?
- A. Cisco ASA
- B. Cisco ESA
- C. Cisco WSA
- D. Cisco ACS
Answer: D
Explanation:
Cisco ISE incorporated Cisco ACS (Cisco Secure Access Control System) between ISE releases 2.0 and 2.3.
Cisco ACS was a network access policy platform that provided authentication, authorization, and accounting (AAA) services for network devices and users. Cisco ACS was discontinued in 2017 and replaced by Cisco ISE, which offers more advanced features and capabilities for identity-based network access control. Cisco ISE provides a migration tool that allows customers to migrate their data and configurations from Cisco ACS to Cisco ISE. The migration tool supports Cisco ACS versions 5.5, 5.6, 5.7, and 5.8 and Cisco ISE versions
2.0, 2.1, 2.2, and 2.3.
References:
* Cisco Secure Access Control System End-of-Life Announcement [Cisco Secure Access Control System]
* Cisco Secure ACS to Cisco ISE Migration Tool [Cisco Identity Services Engine]
* Cisco Identity Services Engine Administrator Guide, Release 2.3 - Cisco Secure ACS to Cisco ISE Migration [Cisco Identity Services Engine]
* Cisco Identity Services Engine Administrator Guide, Release 2.3 - Manage Migration [Cisco Identity Services Engine]
* [Cisco Identity Services Engine Migration Guide, Release 2.3 [Cisco Identity Services Engine]]
* [Designing Cisco Enterprise Networks (ENDESIGN) Exam Topics [Cisco]]
* [Cisco Validated Design Guides [Cisco]]
ISE 2.3 includes the final suite of capabilities designed to reach feature parity with Cisco Secure Access Control System (ACS), allowing all existing ACS customers to migrate their deployment to ISE. New features include TACACS+-based device administration for IPv6, import and export capabilities for TACACS+-based command sets, policy export scheduling, IP range support in all octets, and more. See the ACS vs ISE Comparison for feature comparisons with every release of ISE
NEW QUESTION # 29
Which are the three focus areas for reinventing the WAN? (Choose three.)
- A. Cloud First
- B. Application Quality of Experience
- C. Operations
- D. Centralized device authentication
- E. Execution
- F. Secure Elastic Connectivity
Answer: A,B,F
Explanation:
The three focus areas for reinventing the WAN are:
* Secure Elastic Connectivity: This refers to the ability to provide secure and flexible connectivity to any application, anywhere, and anytime. Secure elastic connectivity enables the network to adapt to the changing business needs and user demands, while maintaining security and performance. Secure elastic connectivity leverages SD-WAN technologies, such as Cloud OnRamp, SASE, and ThousandEyes, to optimize the network path, encrypt the traffic, and monitor the end-to-end visibility across the WAN12.
* Application Quality of Experience: This refers to the ability to ensure optimal and consistent user experience for any application, regardless of the network conditions. Application quality of experience uses SD-WAN technologies, such as vAnalytics, to measure and improve the application performance, availability, and reliability across the WAN3. Application quality of experience also uses intelligent policies and real-time analytics to prioritize the critical applications and steer the traffic to the best-performing path4.
* Cloud First: This refers to the ability to embrace the cloud as the primary platform for delivering applications and services to the users. Cloud first enables the network to support the multicloud strategy and accelerate the cloud adoption. Cloud first leverages SD-WAN technologies, such as Cloud OnRamp, to simplify and automate the connectivity to the public cloud, SaaS, and cloud interconnect
* providers4. Cloud first also enables the network to operate as a cloud-native WAN overlay, using software-defined automation and orchestration tools5.
References:
* Cisco SD-WAN Architecture Overview
* SD-WAN and SASE: The new landscape of networking
* Under the vAnalytics Hood: Enabling Total Network Visibility, Total Network Control
* SD-WAN Capabilities - The New Landscape of Networking
* Software-defined WAN (SD-WAN): the new landscape of networking
The 4 Focus areas for reinventing the WAN are:
* Secure Elastic Connectivity
* Cloud First
* Application Quality of Experience
* Agile Operations
https://salesconnect.cisco.com/sc/s/learning-activity-from-plan?ltui__urlRecordId=a0c8c00000P3hKMAAZ<u
NEW QUESTION # 30
What are three ways in which Cisco ISE learns information about devices? (Choose three.)
- A. RADIUS attributes
- B. network servers the device has accessed
- C. RPC mechanism via HTTPS
- D. traffic generated by the device
- E. user authentication to the ISE
- F. SMTP agents
Answer: A,D,E
Explanation:
Explanation
Cisco ISE learns information about devices by using various methods, such as network probes, user authentication, and endpoint identity groups. Three ways in which Cisco ISE learns information about devices are:
B: RADIUS attributes: Cisco ISE can use the RADIUS protocol to collect information about devices from network access devices (NADs), such as switches, routers, and wireless controllers. The NADs can send RADIUS accounting packets to Cisco ISE that contain attributes related to the device identity, such as MAC address, IP address, hostname, device type, and vendor. Cisco ISE can use these attributes to profile the device and assign it to an endpoint identity group12.
D: user authentication to the ISE: Cisco ISE can also learn information about devices by authenticating the users who access the network through the devices. Cisco ISE can use various authentication methods, such as 802.1X, MAC Authentication Bypass (MAB), web authentication, or certificate-based authentication, to verify the identity and credentials of the users. Cisco ISE can then associate the user identity with the device identity and apply the appropriate authorization policies based on the user role, device type, and network context34.
E: traffic generated by the device: Cisco ISE can also learn information about devices by analyzing the traffic generated by the devices on the network. Cisco ISE can use various network probes, such as DHCP, SNMP, HTTP, DNS, or NetFlow, to capture and inspect the packets sent by the devices. Cisco ISE can then extract information from the packet headers and payloads, such as device name, operating system, browser type, application name, or domain name, and use it to profile the device and assign it to an endpoint identity group56.
References :
Cisco ISE Profiling Services
Configuring Profiler Policies
Cisco ISE Authentication Services
Configuring Device Sensor for ISE Profiling
Cisco ISE Endpoint Profiling Policies
ISE Profiling Design Guide
NEW QUESTION # 31
Which are the three focus areas for reinventing the WAN? (Choose three.)
- A. Cloud Fast
- B. Application Quality of Experience
- C. Centralized device authentication
- D. Operations
- E. Execution
- F. Secure Elastic Connectivity
Answer: C,E,F
NEW QUESTION # 32
Which two primary categories are displayed on the overall health page of the assurance component in the Cisco DNA Center? (Choose two.)
- A. Server
- B. Core
- C. Access-Distribution
- D. Wired
- E. Network
- F. Client
Answer: E,F
NEW QUESTION # 33
Which two statements are true regarding Cisco ISE? (Choose two.)
- A. The major business outcomes of ISE are enhanced user experience and secure VLAN segmentation.
- B. ISE can provide data about when a specific device connected to the network.
- C. Without integration with any other product, ISE can track the actual physical location of a wireless endpoint as it moves.
- D. An ISE deployment requires only a Cisco ISE network access control appliance.
- E. ISE plays a critical role in SD-Access.
Answer: B,E
Explanation:
Cisco ISE is a policy decision point that enables enterprises to ensure compliance, enhance infrastructure security, and streamline service operations. Some features and benefits of Cisco ISE include1:
* Zero trust across the network: ISE allows only trusted users and devices access to resources on your network. It also uses intel to automatically identify, classify and profile devices.
* Policy and lifecycle management: ISE simplifies the delivery of consistent, highly secure access control across wired, wireless, and VPN connections. It also allows users to add and manage their own devices through self-service portals.
* Remote management and deployment: ISE supports cloud-based deployment and management, as well as integration with other Cisco products and third-party solutions.
* Site survivability: ISE provides local authentication and authorization services for remote sites, even when the connection to the central ISE server is lost.
* Visibility of all devices and their users: ISE can provide data about when a specific device connected to the network, what type of device it is, who is using it, what applications are running on it, and where it is located.
Among these features, two statements are true regarding Cisco ISE:
* ISE plays a critical role in SD-Access: SD-Access is a network architecture that uses software-defined networking (SDN) principles to create a secure, scalable, and consistent network fabric. ISE is the policy engine that defines and enforces the network segmentation and access policies for SD-Access2.
* ISE can provide data about when a specific device connected to the network: ISE uses a number of probes to collect attributes for all endpoints on the network, and pass them to the Profiler analyzer, where the known endpoints are classified according to their associated policies and identity groups. ISE can also provide historical data about the endpoint connections, such as the time, duration, location, and user of the connection3.
The other three statements are false regarding Cisco ISE:
* The major business outcomes of ISE are enhanced user experience and secure VLAN segmentation: ISE provides more than just user experience and VLAN segmentation. It also delivers business outcomes such as improved network performance, reduced operational costs, increased security, and simplified compliance4.
* An ISE deployment requires only a Cisco ISE network access control appliance: ISE can be deployed on different platforms, such as physical appliances, virtual machines, or cloud services. An ISE deployment also requires other components, such as network devices, endpoints, and external identity sources5.
* Without integration with any other product, ISE can track the actual physical location of a wireless endpoint as it moves: ISE can provide the location information of an endpoint based on the network device that it is connected to, such as the switch port or the wireless access point. However, to track the actual physical location of a wireless endpoint as it moves, ISE needs to integrate with other products, such as Cisco DNA Center, Cisco Connected Mobile Experiences (CMX), or Cisco Wireless LAN Controller (WLC)6.
References:
Cisco Content Hub - Cisco ISE Features1 : Cisco SD-Access Solution Design Guide (CVD) - Cisco2 : Cisco ISE Network Discovery3 : Cisco Identity Services Engine (ISE) - Cisco4 : Cisco Identity Services Engine Hardware Installation Guide,Release 2.7 - Cisco ISE Deployment [Cisco Identity Services Engine] - Cisco5 :
Cisco Identity Services Engine Administrator Guide, Release 2.7 - Configure Location Mapping [Cisco Identity Services Engine] - Cisco6 Slide 5 &
7https://salesconnect.cisco.com/sc/s/learning-activity-from-plan?ltui__urlRecordId=a0c8c00000Kfw0EAAR<u
NEW QUESTION # 34
Which two statements are true regarding Cisco ISE? (Choose two.)
- A. In two-node standalone ISE deployments, failover must be done manually.
- B. ISE supports up to 100 Policy Services Nodes.
- C. The number of logs that ISE can retain is determined by your disk space.
- D. In distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically.
- E. ISE can detected endpoints whose addresses have been translated via NAT.
- F. ISE supports IPv6 downloadable ACLs.
Answer: C,F
Explanation:
Cisco ISE is a security policy management platform that provides secure access to network resources. Cisco ISE functions as a policy decision point and enables enterprises to ensure compliance, enhance infrastructure security, and streamline service operations1. Two of the statements that are true regarding Cisco ISE are:
* ISE can detect endpoints whose addresses have been translated via NAT: Cisco ISE can discover,
* profile, and monitor the endpoint devices on the network, and classify them according to their associated policies and identity groups. Cisco ISE can leverage the pxGrid framework to share the contextual information with other security tools and platforms, and enhance the network visibility and security1. Cisco ISE can also detect endpoints whose addresses have been translated via NAT by using various methods, such as passive and active discovery, NMAP scanning, DHCP snooping, and RADIUS accounting234.
* The number of logs that ISE can retain is determined by your disk space: Cisco ISE provides a logging mechanism that is used for auditing, faultmanagement, and troubleshooting. The logging mechanism helps you to identify fault conditions in deployed services and troubleshoot issues efficiently. You can configure your Cisco ISE node to collect the logs in the local systems using a virtual loopback address5. The number of logs that ISE can retain is determined by your disk space, as well as the data purging settings that you can configure under Administration > System > Maintenance > Data Purging6. You can also configure Cisco ISE to send its logs to a remote system for greater retention history7.
The other statements are not true regarding Cisco ISE, because:
* In distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically: Cisco ISE supports high availability for the Administration persona, which provides centralized configuration and management of the distributed deployment. You can configure one primary Administration ISE node and one secondary Administration ISE node for high availability. However, the failover from primary to secondary Policy Administration Nodes does not happen automatically, unless you enable the automatic failover feature and configure a health check node to monitor the primary node's status8. Otherwise, you have to manually promote the secondary node to become the primary node in case of a failure9.
* In two-node standalone ISE deployments, failover must be done manually: Cisco ISE supports high availability for the Policy Service persona, which provides network access, posture, guest access, client provisioning, and profiling services. You can configure multiple Policy Service Nodes (PSNs) in a node group to provide session failover and load balancing for the endpoints. In a two-nodestandalone ISE deployment, where each node assumes all the personas, the failover for the Policy Service persona does not need to be done manually, as long as the network access devices are configured to use both nodes for RADIUS and TACACS services10.
* ISE supports IPv6 downloadable ACLs: Cisco ISE supports downloadable ACLs (DACLs), which are configured and implemented through authorization profiles. DACLs are used to enforce granular access control policies for the endpoints based on their identity and other attributes. However, Cisco ISE does not support IPv6 downloadable ACLs, as it only supports IPv4 ACLs for RADIUS and TACACS protocols1112.
References:
1: Cisco Content Hub - Cisco ISE Features 2: Cisco ISE Profiler Service Overview 3: ISE Deployment through NAT Boundaries - Cisco Community 4: Configure ISE 3.3 Native IPSec to Secure NAD (IOS-XE) Communication - Cisco 5: Logging [Cisco Identity Services Engine] - Cisco Systems 6: ISE maximum logging time / data retention - Cisco Community 7: Logs retention on ISE - Cisco Community 8: Cisco Identity Services Engine Administrator Guide, Release 2.4 9: Setting Up Cisco ISE in a Distributed Environment 10: Cisco Content Hub - Network Deployments in Cisco ISE 11: Cisco Identity Services Engine Administrator Guide, Release 2.2 12: Solved: ISE: support for IPv6 DACL's - Cisco Community
"There is no automatic failover for the Administration
persona."https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html...Newer platforms and ISE versions appear to support ipv6 dacl just fine now
NEW QUESTION # 35
......
500-490 Actual Questions Answers PDF 100% Cover Real Exam Questions: https://www.actualcollection.com/500-490-exam-questions.html