500-470 Practice Questions
Prepare for 500-470 with more than an answer.
- Exam fee
- $300 USD
- Level
- Specialist
- Valid for
- No expiration
Domains covered on the exam 3
- SD-Access34%
- SD-WAN32%
- ISE (Identity Services Engine)34%
- 1
During the 'Defend' phase of an ISE sales engagement, the customer's security architect, who is familiar with a competitor's NAC solution, questions the value of Cisco TrustSec. They argue that traditional VLANs and ACLs provide adequate segmentation. What is the most compelling business outcome a systems engineer can use to defend the value of TrustSec over legacy segmentation methods?
Show answer details
Correct answer: B
The key business value of TrustSec is operational simplification and scalability. With VLANs/ACLs, security policy is tied to IP addresses. If a user moves or an IP address changes, ACLs must be manually updated across numerous devices, which is complex, error-prone, and slow. TrustSec uses logical group tags (SGTs), so policy is defined based on user/device roles (e.g., 'Doctors can access Patient-Records'). This policy is independent of location or IP address and is managed centrally in ISE. This radically simplifies administration, enables faster security changes, and reduces the risk of misconfiguration.
- 2
A manufacturing company is deploying Cisco SD-WAN and needs to ensure that traffic from its critical factory floor systems (SCADA) is always sent over the highly reliable, low-latency MPLS path, while all other non-critical traffic can use the commodity internet links. Which two policy types are required to accomplish this? (Select TWO)
Show answer details
Correct answer: A, D
A centralized control policy (specifically a topology policy or VPN membership policy) is often used to define which paths are preferred or available for certain traffic types across the entire fabric. It sets the high-level routing intent from the vSmart controller.
A centralized data policy is the enforcement mechanism that inspects the actual data packets. It would be configured to match the specific SCADA application traffic (based on IP, port, or DSCP) and then set an action to steer it exclusively to the TLOC (path) associated with the MPLS circuit (e.g., color 'mpls').
- 3
What is the primary function of the LISP (Locator/ID Separation Protocol) control plane in an SD-Access fabric?
Show answer details
Correct answer: C
LISP is the core control plane protocol for the SD-Access fabric. Its primary job is to resolve the location of endpoints. It separates an endpoint's identity (EID - its IP or MAC address) from its location (RLOC - the IP address of the fabric edge switch it's connected to). The control plane nodes maintain this EID-to-RLOC mapping database, allowing endpoints to move anywhere in the fabric while keeping their IP address, enabling seamless mobility.
- 4
A customer wants to deploy Cisco ISE for guest wireless access. They require a simple, self-service portal where visitors can register using their email address and receive credentials via email. Which ISE persona and portal type are required to build this solution?
Show answer details
Correct answer: B
The Policy Service Node (PSN) is the ISE persona that hosts the guest portals and interacts with end-users. For the described workflow, a 'Self-Registered Guest Portal' must be configured. This portal type allows guests to create their own accounts, which can then be configured to send the generated credentials to the email address they provided during registration.
- 5
An enterprise has two WAN transports at its branch: a high-cost, low-latency MPLS link and a low-cost, high-bandwidth DIA Internet link. The business requirement is to send real-time voice traffic exclusively over the MPLS link unless its performance degrades beyond a strict threshold, while sending bulk data traffic primarily over the DIA link. Which Cisco SD-WAN policy is the most precise and efficient tool to implement this specific outcome?
graph TD subgraph Branch Voice[Voice Traffic] Data[Bulk Data] vEdge[vEdge Router] end subgraph DataCenter Hub[Hub Router] end Voice --> vEdge Data --> vEdge vEdge -- MPLS_Link[MPLS - Low Latency] --> Hub vEdge -- DIA_Link[DIA - High Bandwidth] --> HubShow answer details
Correct answer: C
Application-Aware Routing (AAR) is the specific Cisco SD-WAN feature designed for this use case. It allows an administrator to define an SLA class with thresholds for latency, jitter, and loss. The AAR policy then steers specific applications (like voice) to paths that meet the SLA (like MPLS). If the preferred path fails to meet the SLA, the policy automatically and dynamically reroutes the traffic to a compliant secondary path. This is more precise than a data policy for performance-based routing.
- 6
A systems engineer is in the 'Design' phase for a large enterprise SD-WAN deployment. The customer's primary requirement is to ensure that real-time voice traffic for their cloud-based UCaaS platform is never impacted by bulk data transfers, such as nightly backups. Which Cisco SD-WAN policy configuration is the most direct and effective method to achieve this traffic prioritization and guarantee performance?
Show answer details
Correct answer: C
The most effective method is to use a centralized data policy with a QoS map. This allows the administrator to classify the UCaaS application traffic (e.g., using DSCP markings), assign it to a high-priority forwarding class (like EF), and allocate a specific percentage of bandwidth, ensuring it is always serviced before lower-priority traffic like backups. While AAR steers traffic, it doesn't guarantee bandwidth on the chosen path. Localized policies are less scalable for fabric-wide QoS, and a Cflowd policy is for monitoring, not enforcement.
- 7
A university is implementing an SD-Access fabric and requires a method to automatically assign specific network access policies to thousands of student-owned devices (BYOD) upon connection. The security team wants to ensure that devices are placed into a 'Limited Access' segment until they are fully registered and scanned for compliance. Which two components are essential for automating this initial device onboarding and placement process? (Select TWO)
Show answer details
Correct answer: B, C
ISE Profiling is crucial for identifying what the device is (e.g., a Windows laptop, an iPhone) as soon as it connects. Based on this profile, an ISE Authorization Policy can redirect the device to the BYOD onboarding portal for registration.
The Authorization Policy is the enforcement mechanism. It contains rules that match on conditions (like the device profile or authentication status) and assigns a result, such as redirecting the user's web traffic to the BYOD portal to start the registration process.
- 8
During the 'Defend' stage of a sales cycle, a competitor claims their campus networking solution is superior to Cisco SD-Access because it uses a simpler, controller-less architecture. What is the strongest counter-argument a Cisco systems engineer can make to defend the value of the controller-based architecture of Cisco DNA Center?
Show answer details
Correct answer: C
The core value of a controller like Cisco DNA Center is its ability to act as a single source of truth for the entire network fabric. This centralization is what enables powerful capabilities like intent-based networking, automated provisioning of devices and services (e.g., VLANs, VRFs), consistent application of security policies (via ISE integration), and deep network visibility through Assurance. A controller-less architecture cannot provide this level of cohesive management and intelligence at scale.
- 9
True or False: In a Cisco SD-Access environment, Security Group Tags (SGTs) are assigned by Cisco DNA Center, but the enforcement of policies based on those tags (SGACLs) is performed by the Identity Services Engine (ISE).
Show answer details
Correct answer: B
This statement is false. The roles are reversed. The Identity Services Engine (ISE) is responsible for assigning the Security Group Tag (SGT) to a user or device based on authorization policies. Cisco DNA Center consumes these SGTs and uses them to build and push the corresponding Security Group Access Control Lists (SGACLs) to the fabric edge nodes for enforcement.
- 10
A financial services company is migrating to an SD-Access fabric. A key design requirement is to provide Layer 2 adjacency for a legacy application server cluster that uses a proprietary heartbeat mechanism, which cannot be routed. The servers are connected to different fabric edge switches. Which SD-Access feature must be configured in the overlay to meet this requirement?
Show answer details
Correct answer: B
SD-Access uses a routed access design by default. To extend a Layer 2 broadcast domain across different edge nodes, a Layer 2 Virtual Network Identifier (L2 VNID) must be explicitly configured and stretched across the fabric. This creates a VXLAN-based L2 overlay, allowing devices in the same VLAN (and thus the same L2 VNID) to communicate as if they were on the same physical switch, which is necessary for non-routable heartbeat mechanisms.
