Cisco 500-470 Certification Exam Sample Questions and Answers

Cisco Enterprise Networks SDA, SDWAN and ISE Exam for System Engineers Dumps, 500-470 Dumps, Cisco ENSDENG PDF, 500-470 PDF, Cisco Enterprise Networks SDA, SDWAN and ISE Exam for System Engineers VCE, Cisco Cisco Enterprise Networks SDA, SDWAN and ISE Exam for System Engineers Questions PDF, Cisco Exam VCE, Cisco 500-470 VCE, Cisco Enterprise Networks SDA, SDWAN and ISE Exam for System Engineers Cheat SheetBefore you write the Cisco Enterprise Networks SDA, SDWAN and ISE Exam for System Engineers (500-470) certification exam, you may have certain doubts in your mind regarding the pattern of the test, the types of questions asked in it, the difficulty level of the questions and time required to complete the questions. These Advanced Enterprise Networks Architecture Specialization (ENSDENG) sample questions and demo exam help you in removing these doubts and prepare you to take the test.

The best approach to pass your Cisco 500-470 exam is to challenge and improve your knowledge. To test your learning and identify improvement areas with actual exam format, we suggest you practice with Premium Cisco 500-470 Certification Practice Exam. The practice test is one of the most important elements of your Cisco Enterprise Networks SDA, SDWAN and ISE Exam for System Engineers (ENSDENG) exam study strategy to discover your strengths and weaknesses, to improve your time management skills and to get an idea of the score you can expect.

Cisco 500-470 (ENSDENG) Sample Questions:

01. During Discovery at a hospital campus, the CIO raises two segmentation problems. Infusion pumps and imaging systems share access VLANs with staff PCs in every building, and auditors want them isolated wherever they are plugged in. Separately, clinical traffic must be kept apart from guest traffic on the WAN links from the remote clinics to the data center.
Which problem is the SD-Access buying trigger, and why?
a) The first, because the fabric segments endpoints by group at the access edge wherever they attach
b) Neither, because isolating device classes is a firewall zoning call, not a fabric one
c) The second, because virtual networks in the fabric keep the branch traffic classes apart on the links to the data center
d) Both, because one fabric stretched across the campus and the clinic links carries every segment end to end
 
02. A city council already runs Stealthwatch for network behavior analytics and Firepower at its Internet edge. Its security manager accepts that ISE shares context with both over pxGrid, and asks the partner System Engineer for something concrete: what will those two products be able to do after ISE is attached that they cannot do today?
What does the System Engineer tell the security manager?
a) Stealthwatch can profile every endpoint from its flow records in place of ISE's probes, and Firepower can host the guest portal
b) Stealthwatch can authenticate endpoints at the access port on ISE's behalf, and Firepower can assign the SGT each user carries
c) Stealthwatch can have ISE quarantine a suspect endpoint, and Firepower can enforce rules written by group
d) Both can be managed from Cisco DNA Center once ISE is integrated with it, and both can push authorization policy to the council's switches
 
03. The network manager of a national research institute tells the partner SE that the institute's Catalyst access switches already support 802.1X and the wireless controllers do too, so buying ISE would pay twice for the same thing.
How should the SE respond to this objection?
a) The switches cannot run 802.1X at all without ISE; the EAP exchange with the endpoint terminates on the RADIUS server
b) The switch only enforces the 802.1X outcome; ISE makes the decision from user identity, device profile and posture, and applies one policy across switches, wireless and VPN
c) ISE adds TACACS+ device administration, which is the piece the switches' own 802.1X support leaves out
d) ISE replaces the switch's 802.1X role with an agent on each endpoint, so switches, wireless controllers and VPN gateways need no port, SSID or tunnel configuration
 
04. An airport authority runs a centralized wireless design today: every client's traffic is tunneled from the access points to a wireless controller in the data center before it reaches the network. The SD-Access proposal calls for a fabric WLC and fabric-mode APs, and the wireless team asks whether passenger and staff traffic will still hairpin through the controller once wireless joins the fabric.
How does the partner SE describe what changes?
a) Client data still tunnels to the WLC while the controller applies the SGT before forwarding each flow into the fabric
b) The WLC takes the fabric border role so every wireless client flow is encapsulated and policed on the controller itself
c) The APs bridge client traffic locally into the closet VLAN, so the fabric design no longer needs a wireless controller at all
d) The WLC keeps AP and client control while client data is switched into the fabric at the edge node
 
05. In an SD-WAN engagement with a pharmaceutical company, the partner SE installs a scoped proof of value at two sites so that the customer can watch application-aware routing act on its own traffic before it decides.
To which phase of the 4D methodology does this activity belong?
a) Design, because the two POV sites establish the controller placement and the transports that the final architecture will use
b) Demonstrate, because a POV proves the capability on the customer's own traffic before the decision is made
c) Defend, because the POV results are what the SE uses against the competitor's claims
d) Discovery, because the POV surfaces use cases and triggers the customer had not yet voiced
 
06. A junior colleague is drafting the proposal for a community college's ISE opportunity and asks the partner System Engineer what has to be known before the proposal can be sized. The college has three campuses with a mix of switch and wireless controller generations, a student directory and a small data center.
Which two questions must be answered before the ISE proposal is sized?
(Choose two.)
a) How many ISE appliances the college's data center rack can hold before the deployment is designed
b) How many named user accounts are in the college's directory, counting students, faculty, staff and contractors, so that the subscription matches the number of accounts that will authenticate
c) How many endpoints, including headless devices such as printers and cameras, connect concurrently across the three campuses, since the subscription is consumed per active endpoint
d) Which vManage subscription tier the college already owns, so that the ISE subscription tier can be matched to it
e) Which existing switches and wireless controllers can act as RADIUS network access devices
 
07. During discovery at a hospital campus, the network manager says the "printer VLAN" now holds about 200 MAC addresses and nobody can say which of them are printers. Some are believed to be infusion pumps, and staff have been plugging personal devices into printer ports. None of these devices can log in with a username.
Which Cisco ISE capability addresses this challenge directly?
a) Profiling that classifies each headless device from its DHCP, CDP and HTTP attributes, with MAB authorizing it by its identified type rather than by the VLAN it was plugged into
b) Guest access with a hotspot portal on the printer ports, so anything that cannot log in accepts the AUP and is placed on a visitor segment
c) 802.1X with certificates on every device on that VLAN, so an infusion pump is admitted only after it presents a corporate credential
d) Posture assessment of the printers and pumps, so each is checked for current firmware, patches and agent version before ISE allows it onto the network
 
08. The CIO of a logistics firm with sixty depots tells the SE two things: the depots' MPLS circuits are saturated at month end, and since dispatch and HR moved to SaaS, users say those applications are slow while the on-site file server is fine. The carrier has offered a cheaper bandwidth upgrade on the same circuits.
Which statement explains why this is a Cisco SD-WAN opportunity rather than a circuit upgrade?
a) The saturation means each depot needs a second MPLS circuit that vManage load-balances against the first, doubling the capacity
b) The saturation means the depots need packet duplication across tunnels so that month-end transfers survive loss on the MPLS circuits
c) The SaaS move means depot traffic should break out to the Internet locally and be steered per application, which added MPLS bandwidth on the same path cannot provide
d) The SaaS move means the depots need a campus fabric so that dispatch and HR users are segmented from each other before traffic leaves the site
 
09. In a discovery meeting at a university, the IT director says, "We already do 802.1X. Every student and staff member authenticates when they join the wireless network." The System Engineer notes that the statement covers wireless only. The campus also has thousands of wired ports in offices, labs and residence halls, and a remote-access VPN.
Which follow-up question best sizes the Cisco ISE opportunity?
a) How are wired ports in offices, labs and residence halls and the remote-access VPN authenticated today, and what decides the access each of those users gets?
b) How many named user accounts exist in the directory, so that the subscription can be sized on the students, staff and contractors who will authenticate?
c) Which wireless controller model and software release runs the current 802.1X, and does it support the Device Sensor and inline SGT features that the design would depend on?
d) Would the university replace the wireless RADIUS server with ISE first, so the opportunity begins with the part of the network that already works?
 
10. The finance director of a pharmaceutical company is building the budget lines for a Cisco ISE proposal. The design shows a primary and secondary PAN, two PSNs and a pxGrid node, and the customer has not yet chosen between appliances and virtual machines.
Which two statements should the System Engineer make about how those decisions affect what the company pays?
(Choose two.)
a) Each PSN added for redundancy doubles the endpoint subscription, since both nodes authorize the same endpoints
b) The endpoint subscription is sized on the endpoints ISE authorizes, so adding a PSN or a pxGrid node for redundancy does not raise the endpoint count it is based on
c) A higher tier is needed once the endpoint count grows
d) The subscription is a recurring operating cost renewed at term end, kept separate from any one-time purchase of appliance hardware
e) Licenses are counted per named user, so the staff directory gives the count

Solutions:

Question: 01

Answer: a

Question: 02

Answer: c

Question: 03

Answer: b

Question: 04

Answer: d

Question: 05

Answer: b

Question: 06

Answer: c, e

Question: 07

Answer: a

Question: 08

Answer: c

Question: 09

Answer: a

Question: 10

Answer: b, d

Note: If you find any error in these Cisco Enterprise Networks SDA, SDWAN and ISE Exam for System Engineers (ENSDENG) sample questions, you can update us by write an email on feedback@nwexam.com.

Rating: 5 / 5 (71 votes)