Skip to content

500-490 Practice Questions

Prepare for 500-490 with more than an answer.

224 questions in the full set20 sample questionsUpdated Aug 11, 2025
Exam fee
$300 USD
Level
Specialist
Valid for
3 years
Domains covered on the exam 11
  1. SD-Access Discovery6%
  2. SD-Access Design12%
  3. SDA Demonstration8%
  4. SDA Defend8%
  5. SD-WAN: Discover8%
  6. SD-WAN: Design12%
  7. SD-WAN: Demonstration12%
  8. ISE: Discover6%
  9. ISE: Design12%
  10. ISE: Demonstration6%
  11. ISE: Defend12%
  1. 1

    Which two pieces of information are most critical to gather during the SD-Access discovery phase to ensure a successful physical underlay network design? (Select TWO)

    Show answer details

    Correct answer: A, C

    The underlay must provide resilient layer 3 connectivity from every edge node back to the border and control plane nodes. Understanding the physical layout, including cable paths and locations of wiring closets, is essential for designing a robust routed access layer and ensuring there are redundant paths.

    Hardware compatibility is paramount. The underlay devices must support the necessary features (like VXLAN and a modern routing protocol) and have sufficient resources to function as fabric nodes. An inventory of existing hardware is a mandatory first step.

  2. 2

    A customer needs to design an ISE policy to onboard corporate-owned laptops. The requirements are:

    1. The device must be a member of the corporate Active Directory domain.
    2. The device must have up-to-date antivirus software.
    3. If compliant, the device gets full access; otherwise, it is redirected to a remediation portal.

    Which three ISE components are required to build this policy? (Select THREE)

    Show answer details

    Correct answer: A, B, C

    This component directly addresses the antivirus requirement. The posture policy uses an agent on the endpoint to assess its compliance with predefined rules, such as checking for specific AV products and ensuring definitions are current.

    This is the first step. The device's identity must be verified. Using 802.1X (PEAP or EAP-TLS) against Active Directory confirms the machine is a trusted, domain-joined asset.

    This is where the logic is enforced. After authentication and posture assessment, the Authorization Policy makes the final decision. It will have rules like 'IF (PostureStatus == Compliant) THEN PERMIT (Full_Access_Profile)' and 'IF (PostureStatus == NonCompliant) THEN PERMIT (Remediation_Profile)'. The remediation profile contains the URL redirect attribute.

  3. 3

    During the Defend phase of an ISE sales engagement, a customer's security team argues that their existing endpoint protection platform (EPP) already provides device context, making ISE's profiling capabilities redundant. How should a field engineer respond to defend the unique value of ISE's role in the security architecture?

    Show answer details

    Correct answer: A

    This is the strongest, most collaborative defense. Instead of arguing which tool is better, it positions ISE as the essential integration layer. The response acknowledges the value of the customer's existing tools (EPP) and shows how ISE enhances their investment. ISE, through pxGrid, can subscribe to the rich context from the EPP and then translate that information into network enforcement (like changing a VLAN or applying an SGT). This demonstrates ISE's unique role as the policy enforcement point that bridges the gap between endpoint security and network infrastructure.

  4. 4

    A university is deploying an SD-Access fabric. The IT department wants to provide a basic level of internet access for student-owned devices in dormitories without requiring full 802.1X authentication, but they still want to apply a unique security policy to this group of users. Which SD-Access feature is designed for this specific use case?

    Show answer details

    Correct answer: A

    This combination directly meets the requirements. 'Open' authentication mode allows devices to connect to the network without passing 802.1X or MAB. However, by associating a default SGT (e.g., 'Dorm_User') with these ports, every device that connects is automatically tagged with that SGT. This allows the security team to write TrustSec policies in ISE (e.g., 'Dorm_User' cannot access 'Admin_Servers') that apply to all these devices, providing policy-based segmentation without requiring explicit authentication.

  5. 5

    A customer is presented with the following diagram illustrating their proposed SD-WAN topology for connecting to IaaS providers. They are concerned about the single point of failure if the 'Transit VPC/VNet' goes down. How should the field engineer defend this design?

    graph TD subgraph On-Prem Branch1[Branch 1] Branch2[Branch 2] DC[Data Center] end subgraph Cloud TVPC[Transit VPC / VNet] subgraph AWS AWS_VPC1[AWS VPC 1] end subgraph Azure Azure_VNet1[Azure VNet 1] end end Branch1 -->|IPsec| TVPC Branch2 -->|IPsec| TVPC DC -->|IPsec| TVPC TVPC --- AWS_VPC1 TVPC --- Azure_VNet1
    Show answer details

    Correct answer: A

    This is the standard and correct defense for this architecture. The diagram is a logical representation. In practice, the 'Transit VPC/VNet' is not a single device. The Cloud OnRamp for IaaS solution automates the deployment of redundant Cisco Catalyst 8000V routers across multiple Availability Zones (AZs) within the cloud provider's region. This provides high availability against an AZ failure. All on-prem sites build tunnels to both 8000V instances, ensuring seamless failover.

  6. 6

    During the Defend phase for a Cisco ISE deployment, a competitor claims their NAC solution offers simpler licensing and is 'good enough' for basic guest and BYOD. The customer is concerned about the perceived complexity and cost of ISE. Which argument most effectively defends the value of ISE in an enterprise environment?

    Show answer details

    Correct answer: B

    The most effective defense is to elevate the conversation beyond a simple NAC feature comparison. While TCO and scalability are valid points, the core value of ISE lies in its role as a central policy engine for the entire security architecture. Highlighting its integration with SD-Access (TrustSec) and the broader security ecosystem via pxGrid demonstrates that ISE is a strategic investment that enables advanced security capabilities like zero-trust and micro-segmentation, which a basic NAC solution cannot provide.

  7. 7

    A financial services client requires a highly resilient SD-WAN design for their data centers. They have two data centers, each with dual internet circuits from different providers. The primary business requirement is to ensure that critical trading application traffic is never dropped and maintains path quality, even during a single circuit failure at either data center. Which design approach best meets this requirement?

    Show answer details

    Correct answer: D

    A dual-region design provides the highest level of resiliency. By placing each data center in its own region, you create independent failure domains for the data plane and control plane within each region. This ensures that a failure event in one data center (or its associated region) does not impact the other. Centralized policies can then be crafted to steer traffic to the preferred regional hub based on SLA, with seamless failover to the secondary region's hub if the primary becomes unreachable or path quality degrades. This architecture isolates failures and provides robust business continuity.

  8. 8

    A prospective customer is evaluating Cisco SD-Access against a solution from a competitor that uses a controller-based overlay but relies on traditional VLANs and ACLs for segmentation. The customer believes the competitor's approach is simpler to implement. Which two points should a field engineer emphasize to defend the superiority of the SD-Access segmentation model? (Select TWO)

    Show answer details

    Correct answer: B, D

    This is a core value proposition. SGTs are based on identity and role, not network location. This means a single policy can be created (e.g., 'IoT devices cannot talk to Finance Servers') and it will be enforced everywhere in the fabric without needing to update hundreds of location-specific ACLs.

    This addresses the customer's concern about simplicity. While the underlying technology is more advanced, the operational management is far simpler. A visual policy matrix in a central controller is much easier to understand, manage, and audit than spreadsheets of disparate ACLs applied to various interfaces across the network.

  9. 9

    A university is designing a large-scale SD-Access network to support students, faculty, staff, and IoT devices across a multi-building campus. They need to ensure that the control plane remains stable and that endpoint registration/de-registration events do not overwhelm the LISP Map-Server. Which design choice is critical for achieving this goal?

    Show answer details

    Correct answer: A

    In a large-scale, dynamic environment like a university campus, endpoints connect and disconnect frequently. LISP EID-Notify messages allow an Edge node to immediately inform the Control Plane node (Map-Server) when an endpoint disconnects. This prevents the Map-Server from having to wait for the registration timer to expire, purging the stale entry quickly and keeping the database clean and efficient. Properly tuning the registration interval is also important, but EID-Notify is the key mechanism for handling dynamic endpoint churn at scale.

  10. 10

    During a demonstration of Cisco SD-WAN, a customer asks to see how the solution can guarantee performance for their critical SaaS applications like Microsoft 365 and Salesforce, which are accessed directly from branch offices. Which vManage feature is the most direct and effective way to demonstrate this capability?

    Show answer details

    Correct answer: C

    Cloud OnRamp for SaaS is the specific feature designed for this exact use case. It moves beyond simple path selection based on latency/jitter. It continuously measures the performance of all possible paths from each branch to the SaaS provider's front door and calculates a Quality of Experience (vQoE) score. Demonstrating this feature shows an intelligent, automated solution that actively finds and maintains the optimal path for critical SaaS applications, directly addressing the customer's requirement.

Create an account to continue.