Valid 500-220 Exam Dumps Ensure you a HIGH SCORE (2024)
Pass 500-220 Exam with Latest Questions
Cisco 500-220 exam is a computer-based test that consists of multiple-choice questions. 500-220 exam is timed, and candidates have 90 minutes to complete it. 500-220 exam is available in English and Japanese languages. To pass the exam, candidates need to score at least 70% of the total marks.
NEW QUESTION # 26
Which design requirement is met by implementing syslog versus SNMP?
- A. when proactive alerts for critical events must be generated
- B. when organization-wide information must be collected
- C. when automation capabilities are needed
- D. when information such as flows and client connectivity must be gathered
Answer: D
Explanation:
Explanation
Implementing syslog versus SNMP can meet the design requirement of gathering information such as flows and client connectivity. Syslog can collect and report various types of events, such as VPN connectivity, uplink connectivity, DHCP leases, firewall rules, IDS alerts, and security events. Syslog can also provide detailed information about the flows and client connectivity on the network devices, such as source and destination IP addresses, ports, protocols, bytes transferred, etc. SNMP, on the other hand, can collect and report various statistics and information about the network devices, such as CPU utilization, interface status, memory usage, etc. However, SNMP does not provide as much information about the flows and client connectivity as syslog does.
NEW QUESTION # 27
What are two ways peers interact with ports that Auto VPN uses? (Choose two.)
- A. For IPsec tunneling, peers use UDP ports 500 and 4500.
- B. For IPsec tunneling, peers use high UDP ports within the 32768 to 61000 range.
- C. Peers contact the VPN registry at TCP port 9350.
- D. For IPsec tunneling, peers use high TCP ports within the 32768 to 61000 range.
- E. Peers contact the VPN registry at UDP port 9350.
Answer: D,E
Explanation:
Reference:
_Configuration_and_Troubleshooting
NEW QUESTION # 28
What are two methods of targeting and applying management profiles to System Manager clients? (Choose two.)
- A. by defining the scope
- B. by using dynamic IP tags
- C. by defining a range of serial numbers
- D. by using Wi-Fi tags
- E. by using device tags
Answer: A,E
Explanation:
Explanation
The correct answer is B and D. These are the two methods of targeting and applying management profiles to System Manager clients, according to the [System Manager: Getting Started] article. The article explains that:
Defining the scope: This method allows you to target devices based on their network, tag, or owner. You can define the scope of a profile from the Systems Manager > Manage > Settings page or from the Systems Manager > Monitor > Overview page.
Using device tags: This method allows you to target devices based on their attributes, such as OS, model, location, or user. You can use device tags to create dynamic groups of devices that share common characteristics. You can apply device tags from the Systems Manager > Monitor > Devices page or from the Systems Manager > Manage > Tags page.
NEW QUESTION # 29
Where should a network admin navigate to investigate wireless mesh information between Meraki APs?
- A. Wireless > Monitor > Access Points > AP > RF
- B. Wireless > Configure > Radio Settings
- C. Wireless > Monitor > Wireless Health
- D. Wireless > Monitor > RF Spectrum
Answer: A
Explanation:
Explanation
See Monitoring Mesh section Mesh monitoring tools are located at the bottom of every AP detail page, which can be accessed by navigating to Wireless > Monitor > Access Points, then clicking on an Access Point.
https://documentation.meraki.com/MR/Wi-Fi_Basics_and_Best_Practices/Wireless_Mesh_Networking
NEW QUESTION # 30
Refer to the exhibit.
What are two outcomes reflected in the Web App Health application? (Choose two.)
- A. Network #2 could not load Google because of a local client misconfiguration.
- B. Network #1 could not load Google because of a remote server issue.
- C. Network #2 had better application performance than Network #1.
- D. Neither network recorded any server-side performance issues.
- E. Users on both networks may be experiencing issues when attempting to reach Google.
Answer: D,E
NEW QUESTION # 31
Drag and drop the descriptions from the left onto the corresponding MX operation mode on the right.
Answer:
Explanation:
Explanation
Routed Mode:
This mode is the default mode of operation
This mode is generally also the default gateway for devices on the LAN
Client traffic to the internet has the source IP rewritten to match the WAN IP of the appliance DHCP services can be configured on the MX appliance Passthrough Mode:
The MX appliance acts as a layer 2 bridge
VLANs cannot be configured
No address translation is provided
This mode is not recommended at the network perimeter
This question is related to the topic of MX Addressing and VLANs in the Cisco Meraki documentation. You can find more information about this topic in the MX Addressing and VLANs article or the General MX Best Practices page.
NEW QUESTION # 32
A customer wants to use Microsoft Azure to host corporate application servers.
Which feature does the customer get by using a vMX appliance rather than connecting directly to Azure by VPN?
- A. intrusion prevention
- B. SD-WAN
- C. next-generation firewall
- D. malware protection
Answer: B
Explanation:
Explanation
https://documentation.meraki.com/MX/MX_Installation_Guides/vMX_Setup_Guide_for_Microsoft_Azure
NEW QUESTION # 33
What are two organization permission types? (Choose two.)
- A. Write-only
- B. Full
- C. Write
- D. Read-only
- E. Monitor-only
Answer: B,D
Explanation:
Reference:
Managing_Dashboard_Administrators_and_Permissions
NEW QUESTION # 34
When wireless SSIDs are configured in Dashboard, which setting on the Access Control page affects the ability of a 2.4 GHz only client device from associating to the WLAN for the first time?
- A. Content filtering
- B. 802.11r
- C. Bridge mode
- D. Dual band operating with Band Steering
Answer: D
Explanation:
Explanation
When band steering is enabled on an SSID, APs will stop advertising that SSID in 2.4GHz beacons. Since
2.4GHz-only clients that rely on a passive scan will not "see" that SSID in beacons, they might not be able to join this SSID unless they do an active scan or have been pre-configured with the SSID name and security settings (for example, a pre-shared key).
https://documentation.meraki.com/MR/Radio_Settings/Band_Steering
NEW QUESTION # 35
For which two reasons can an organization become "Out of License"? (Choose two.)
- A. more hardware devices than device licenses
- B. licenses that are in the wrong network
- C. licenses that do not match the serial numbers in the organization
- D. MR licenses that do not match the MR models in the organization
- E. expired device license
Answer: A,E
NEW QUESTION # 36
Refer to the exhibit.
Which IDS/IPS mode is the MX Security Appliance configured for?
- A. quarantine
- B. blocking
- C. prevention
- D. detection
Answer: C
Explanation:
Explanation
You can enable intrusion prevention by setting the Mode drop-down to Prevention under Security & SD-WAN
> Configure > Threat protection > Intrusion detection and prevention. Traffic will be automatically blocked by best effort if it is detected as malicious based on the detection ruleset specified above.
https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Threat_Protection
NEW QUESTION # 37
What is a feature of distributed Layer 3 roaming?
- A. All wireless client traffic is tunneled.
- B. An MX Security Appliance is not required as a concentrator.
- C. All wireless client traffic can be split-tunneled.
- D. An MX Security Appliance is required as a concentrator.
Answer: B
Explanation:
Explanation
https://documentation.meraki.com/Architectures_and_Best_Practices/Cisco_Meraki_Best_Practice_Design/Best This is a feature of distributed Layer 3 roaming, which maintains layer 3 connections for end devices as they roam across layer 3 boundaries without a concentrator1. The first access point that a device connects to will become the anchor access point1.
NEW QUESTION # 38
Drag and drop the settings from the left into the boxes on the right to indicate if the setting will be cloned or not cloned using the Cisco Meraki MS switch cloning feature.
Answer:
Explanation:
NEW QUESTION # 39
How does a Meraki device behave if cloud connectivity is temporarily lost?
- A. The offline device tries to form a connection with a local backup sever.
- B. The offline device continues to run with its last known configuration until cloud connectivity is restored.
- C. The offline device stops passing traffic.
- D. The offline device reboots every 5 minutes until connection is restored.
Answer: B
Explanation:
Explanation
What happens if a network loses connectivity to the Meraki cloud?
Because of Meraki's out of band architecture, most end users are not affected if Meraki wireless APs, switches, or security appliances cannot communicate with Meraki's cloud services (e.g., because of a temporary WAN failure):
* Users can access the local network (printers, file shares, etc.)
* If WAN connectivity is available, users can access the Internet
* Network policies (firewall rules, QoS, etc.) continue to be enforced
* Users can authenticate via 802.1X/RADIUS and can roam wirelessly between access points
* Users can initiate and renew DHCP leases
* Established VPN tunnels continue to operate
* Local configuration tools are available (e.g., device IP configuration
https://meraki.cisco.com/lib/pdf/meraki_datasheet_cloud_management.pdf
NEW QUESTION # 40
A Cisco Meraki MX security appliance is trying to route a packet to the destination IP address of
172.18.24.12. Which routes contained in its routing table does it select?
- A. static route 172.16.0.0/12
- B. non-Meraki VPN route 172.18.24.0/24
- C. Auto VPN route 172.18.0.0/16
- D. directly connected 172.18.16.0/20
Answer: B
Explanation:
Explanation
Route Priority
Each type of route configured on the MX has a specific priority in comparison with other types of routes. The priority is as follows:
Directly Connected
Client VPN
Static Routes
AutoVPN Routes
Non-Meraki VPN Peers
BGP learned Routes
NAT*
https://documentation.meraki.com/MX/Networks_and_Routing/MX_Routing_Behavior
NEW QUESTION # 41
Which Cisco Meraki product must be deployed in addition to Systems Manager so that Systems Manager Sentry enrollment can be used?
- A. MS Switch
- B. MV Smart Camera
- C. Meraki Insight
- D. MR Access Point
Answer: D
NEW QUESTION # 42
......
500-220 Exam Practice Questions prepared by Cisco Professionals: https://www.exams4collection.com/500-220-latest-braindumps.html
Use Valid New 500-220 Questions - Top choice Help You Gain Success: https://drive.google.com/open?id=1Pn-ZZHagAhAk2EDgYD10kE7C_op0t-4P
