Skip to content

500-220 Practice Questions

Prepare for 500-220 with more than an answer.

274 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$300 USD
Level
Specialist
Valid for
3 years
Domains covered on the exam 4
  1. Cisco Meraki Cloud Management15%
  2. Design30%
  3. Implementation25%
  4. Monitoring and Troubleshooting30%
  1. 1

    A museum is using Meraki MV72 outdoor cameras to monitor its sculpture garden. The security director wants to receive an alert whenever a person enters a specific restricted area around a valuable statue but wants to ignore motion from swaying trees. How should the security administrator configure the MV72 camera to meet this requirement?

    Show answer details

    Correct answer: C

    Meraki MV cameras have built-in analytics, including person and vehicle detection. By combining a motion alert zone with the 'person detection' filter, the system will only generate an alert when the analytics engine identifies the motion within the specified zone as being caused by a person. This effectively ignores irrelevant motion from things like weather, animals, or swaying trees.

  2. 2

    A systems administrator is tasked with deploying a new application to all company-owned Android devices using Systems Manager. The application is an internally developed APK file and is not available on the Google Play Store. What is the correct method to distribute this application?

    Show answer details

    Correct answer: C

    Systems Manager provides a mechanism for hosting and distributing private or custom applications. The administrator can navigate to the Apps page, choose to add a new app, and select the option to upload an APK file. Once uploaded, Systems Manager hosts the file and can push it to targeted devices or make it available for on-demand installation through the Meraki app.

  3. 3

    During a scheduled firmware upgrade for a network of MS switches, an administrator notices that one switch failed to upgrade and is now showing as offline. The administrator needs to get the switch back online with the correct firmware as quickly as possible. The switch is in a remote, unstaffed location. What is the most effective troubleshooting step that can be performed from the Meraki Dashboard?

    Show answer details

    Correct answer: D

    If a device fails to upgrade and goes offline, it may be due to an issue with the new firmware. The Dashboard provides a 'Firmware Upgrades' page where an administrator can see the upgrade history and initiate a rollback for the entire network to the previously running, stable firmware version. When the offline switch re-establishes cloud connectivity, it will see the network-wide rollback command, download the old firmware, and should come back online.

  4. 4

    A network architect is designing a high-availability solution for an organization's primary internet edge using two MX100 appliances. The goal is to ensure seamless failover for all LAN clients with minimal downtime if the primary MX fails. Which Meraki feature should be implemented?

    Show answer details

    Correct answer: B

    The VRRP (Virtual Router Redundancy Protocol) Warm Spare feature is specifically designed for MX appliance redundancy. Two identical MXs are configured in an HA pair. The primary MX handles all traffic while the spare remains in a passive state, receiving configuration updates and monitoring the primary's health. If the primary fails, the spare MX takes over the virtual IP address and begins processing traffic, providing near-seamless failover for LAN clients.

  5. 5

    A user reports being unable to connect to the corporate wireless network. The network uses 802.1X with a RADIUS server for authentication. A network engineer checks the RADIUS server logs and sees no authentication requests from the user's client. In the Meraki Dashboard, the engineer inspects the client's event log and sees repeated '802.1X auth failed' messages. What is the most likely cause of this issue?

    Show answer details

    Correct answer: B

    The key evidence is that the RADIUS server logs show no authentication requests. The Meraki client event log shows '802.1X auth failed'. This combination indicates that the client is attempting to authenticate, the AP is trying to forward the request to the RADIUS server, but the server is not receiving it. This points to a connectivity problem between the AP and the RADIUS server, such as a firewall blocking the RADIUS ports or the server being down.

  6. 6

    A financial services firm is deploying Meraki MS390 switches and needs to enforce strict, identity-based access control for all wired connections. The security policy requires that devices are authenticated via EAP-TLS using machine certificates, and if a device fails authentication, it must be placed into a quarantine VLAN for remediation. Which configuration item is the most critical component for dynamically assigning the quarantine VLAN to non-compliant devices?

    Show answer details

    Correct answer: C

    The RADIUS server is responsible for the authentication decision. For dynamic VLAN assignment, the server sends specific RADIUS attributes (like Tunnel-Private-Group-ID) in the Access-Accept or Access-Reject message to instruct the switch which VLAN to place the client in. If authentication fails, the RADIUS server can be configured to send back an Access-Accept message that still assigns the device to the specified quarantine VLAN, effectively isolating it.

  7. 7

    A global logistics company is using Meraki SD-WAN with dual-uplink MX450s at each of their 50 distribution centers. They are experiencing poor quality for their custom inventory management application, which uses UDP port 7711. The application requires low latency. The primary link is a high-bandwidth MPLS circuit, and the secondary is a lower-cost business internet connection. Which two actions should be taken to optimize this application's performance? (Select TWO)

    Show answer details

    Correct answer: B, C

    A flow preference policy (part of SD-WAN & traffic shaping) allows the administrator to specify how traffic should be handled. By choosing 'Best for latency', the MX will dynamically send the application's traffic over the link that currently has the lowest latency, which is the key requirement.

    To use the 'Best for latency' flow preference, a custom performance class must first be created that defines the criteria for what constitutes good performance. For this application, a class that specifically measures latency (and ignores jitter or loss) would be the most appropriate.

  8. 8

    True or False: In a Meraki Co-Termination licensing model, adding a new 3-year license to an organization that has 1 year of remaining license time will result in a new, weighted average co-termination date for all devices in the organization.

    Show answer details

    Correct answer: A

    This is the fundamental principle of the Co-Termination model. The Dashboard calculates a weighted average of all active licenses to determine a single expiration date for every device in the organization. Adding a new license with a different duration will always trigger this recalculation.

  9. 9

    A university is deploying a high-density Wi-Fi network using MR56 access points in a large lecture hall that seats 500 students. The primary goal is to provide stable, high-performance connectivity for students simultaneously streaming educational videos and accessing online resources. The network architect must mitigate co-channel interference and optimize client load distribution. Which combination of RF profile settings is most effective for this scenario?

    Show answer details

    Correct answer: C

    In high-density environments, the key is to reduce the cell size of each AP to minimize co-channel interference and distribute clients more evenly across more APs. This is achieved by lowering the transmit power. Band steering pushes capable clients to the less congested 5 GHz band. Using narrower channel widths (20/40 MHz) provides more non-overlapping channels, which is crucial for reducing interference when many APs are in close proximity.

  10. 10

    A network administrator at a hospital is troubleshooting an issue where a specific medical imaging device, connected via an Ethernet port on an MS225 switch, intermittently loses connectivity to the central server. The device has a static IP address. The administrator suspects a physical layer issue but needs to confirm before dispatching a technician. The following diagram shows the troubleshooting tools available in the Meraki Dashboard. Which tool should the administrator use first to remotely diagnose the problem?

    graph TD subgraph Meraki Dashboard Tools A[Packet Capture] B[Event Log] C[Cable Test] D[Ping Tool] E[ARP Table] end Switch[MS225 Switch] -->|Port 12| Device[Imaging Device] Switch --> Server[Central Server]

    Show answer details

    Correct answer: B

    Given the suspicion of a physical layer issue (intermittent connectivity), the Cable Test tool is the most direct and appropriate first step. This tool can remotely diagnose the health of the Ethernet cable connected to a switch port, reporting on issues like cable length, shorts, or open pairs, without needing physical presence. This will quickly validate or invalidate the physical layer hypothesis.

Create an account to continue.