Cisco 500-490 Certification Exam Sample Questions and Answers

Designing Enterprise Networks for Field Engineers Dumps, 500-490 Dumps, Cisco ENDESIGN PDF, 500-490 PDF, Designing Enterprise Networks for Field Engineers VCE, Cisco Designing Enterprise Networks for Field Engineers Questions PDF, Cisco Exam VCE, Cisco 500-490 VCE, Designing Enterprise Networks for Field Engineers Cheat SheetBefore you write the Cisco Designing Enterprise Networks for Field Engineers (500-490) certification exam, you may have certain doubts in your mind regarding the pattern of the test, the types of questions asked in it, the difficulty level of the questions and time required to complete the questions. These Advanced Enterprise Networks Architecture Specialization (ENDESIGN) sample questions and demo exam help you in removing these doubts and prepare you to take the test.

The best approach to pass your Cisco 500-490 exam is to challenge and improve your knowledge. To test your learning and identify improvement areas with actual exam format, we suggest you practice with Premium Cisco 500-490 Certification Practice Exam. The practice test is one of the most important elements of your Designing Cisco Enterprise Networks for Field Engineers (ENDESIGN) exam study strategy to discover your strengths and weaknesses, to improve your time management skills and to get an idea of the score you can expect.

Cisco 500-490 (ENDESIGN) Sample Questions:

01. A university's network team is about to have Cisco DNA Center build the routed underlay for its first SD-Access fabric, and wants to know what it has to supply beforehand and what changes about the way the campus forwards traffic.
Which two statements about the SD-Access underlay are correct?
(Choose two.)
a) The fabric underlay uses static routes only
b) LAN Automation extends the underlay outward from a seed device the team nominates, so the design has to name a switch Cisco DNA Center can already reach before the new closets are discovered
c) No spanning tree runs across the fabric, since the underlay is fully routed rather than switched at Layer 2
d) After LAN Automation discovers a switch, its underlay routing is still typed in by hand
e) The underlay is built from VLANs trunked between the switches, so spanning tree still blocks the loops it creates, as it does in the campus design the team runs today
 
02. At a port authority, the identity team hears that Cisco ISE is being proposed and worries about overlap with the directory it already maintains for every employee and contractor. They ask the Field Engineer whether ISE would become the place where accounts and passwords live.
How should the Field Engineer describe where ISE sits?
a) It becomes the master account store once it is deployed, and the existing directory is retired after the accounts have been migrated into it.
b) It replaces the firewall's identity rules, so no context needs to be shared with it.
c) It sits inline between the access layer and the core, inspecting each session as it passes.
d) It queries the directory the authority already keeps and adds the network access decision on top of it.
 
03. Part way through an Assurance demonstration for an airport's network operations manager, the Field Engineer has put one issue on screen with its likely root cause and the next steps it suggests. The manager asks whether the platform goes ahead and clears problems like that one itself, so her team can stop watching for them.
How should the Field Engineer answer?
a) Move on to the network health dashboard and let the question stand, then return to it after the demo if the manager raises it again
b) Show the suggested remediation, and be plain that applying it stays with the team
c) Describe the self-healing rollback that returns a device to its last working configuration without an engineer touching it
d) Promise that Assurance closes these issues on its own once the fabric is provisioned, and set the expectation of fewer tickets from the first week onward
 
04. A healthcare group already runs Cisco ISE across its main hospital and has just taken over three clinics, each with its own switches, its own wireless and its own small IT team. The board wants one answer to the question of who is on the network. The Field Engineer is writing the proposal for the clinics.
What should that proposal put forward?
a) Keeping the access control product each clinic already runs today and linking the two systems into one combined board report
b) A second administration node at the clinics for their own team
c) Bringing the clinics into the existing deployment, with policy service capacity added for their authentication load
d) A separate deployment at each clinic, leaving the local team at every site authoring its own access policy independently
 
05. At a pharmaceutical R&D site, the security team segments with firewall zones built from subnets, and researchers move between three buildings with laptops and instrument carts. A competing vendor proposes extending that zone model across the campus instead of adopting identity-based segmentation.
Which point best answers that proposal?
a) A group assigned at authentication travels with the device, so a researcher keeps the same access in every building, while a zone built from subnets only holds where the addressing holds
b) Zone rules are evaluated faster than group policy, so the campus would see lower latency between buildings
c) Firewall zones inspect more deeply than the access layer can, so moving the same rules onto the switches would lose that inspection
d) Identity-based segmentation replaces the firewall, so the perimeter zones, the address objects and the inspection rules can all be retired once the campus is tagged
 
06. A manufacturer's plant wireless is due to join the SD-Access fabric being built this year, and the network architect has asked how it will forward traffic afterward. She expects every wireless client's data traffic to tunnel back to a central wireless controller before reaching its destination, the way it does in the plant's current CAPWAP deployment.
How does traffic actually flow in a fabric-integrated wireless design?
a) Wireless cannot join an SD-Access fabric at all
b) Wireless control stays with the fabric WLC, but client data is switched locally at the fabric edge node instead of tunneling to the controller
c) Both control and data continue to tunnel to the central wireless controller exactly as before; fabric integration changes only how the wired side of the campus is automated and leaves the wireless data path exactly as it is today
d) Both control and data are switched at the fabric edge node, with the fabric WLC left with no role once fabric mode wireless is enabled
 
07. During discovery with a law firm, the office manager raises two complaints in the same breath: the branch's single MPLS circuit "feels full" during the afternoon, and separately, attorneys say a cloud-based document review platform is slow only in the afternoon at every one of the firm's five offices.
Which complaint should the Field Engineer treat as the stronger SD-WAN opportunity rather than a simple circuit upgrade?
a) Neither one, since both are normal afternoon network load
b) The single office's full MPLS circuit, since more bandwidth and a second local circuit at that one site would resolve the complaint fastest
c) The document platform being slow at every office points to a shared cloud application problem across the whole WAN, which is what SD-WAN's path selection and cloud on-ramp are built to address
d) Both complaints equally, since either one alone already justifies replacing every circuit at every office with broadband
 
08. An energy utility is rolling out TrustSec. Its newest campus switches can carry the tag in the frame on the links between them, but two older distribution switches and the data center firewall cannot. The security architect asks how a group tag assigned at login reaches the places where it is enforced.
Which two mechanisms should the Field Engineer describe?
(Choose two.)
a) Inline tagging, where the tag travels in the frame on links between devices that support it
b) A separate VLAN per group, read by the firewall
c) A Cisco DNA Center provisioning push that writes the tag into the running configuration of each switch ahead of the session
d) SXP, which sends the tag-to-IP bindings to devices that cannot carry the tag
e) An SNMP poll of each access switch, from which the firewall builds its own list of tags and addresses
 
09. An energy utility's substation branch has a handful of legacy protection relays connected to a small Layer 2 switch, which in turn uplinks to the branch's SD-Access fabric edge switch. The relays cannot run fabric software themselves, and the Layer 2 switch is on the compatibility list for the fabric's release.
How does Cisco DNA Center bring these relays into the fabric's policy model?
a) The relays are simply left outside the fabric's policy model
b) The Layer 2 switch is provisioned as an extended node, and the fabric edge switch above it performs the encapsulation and policy enforcement on the relays' behalf
c) The relays connect directly to Cisco ISE over the WAN for authentication, bypassing the Layer 2 switch and the fabric edge entirely, with no fabric role encapsulating or enforcing their traffic
d) The Layer 2 switch must be replaced with a fabric edge switch of its own before the relays can join the fabric; only a device running fabric edge software authenticates endpoints, encapsulates their traffic and enforces policy on their behalf
 
10. A law firm's fabric access switches connect attorney workstations and shared printers across the office. Which fabric role authenticates each endpoint, applies the first-hop VXLAN encapsulation and enforces its SGACL?
a) The border node, since every endpoint session exits through it
b) The control-plane node, since it authenticates the endpoint at connection time and also maintains the mapping database the edge nodes query for handling encapsulation and enforcement
c) The intermediate node performs that function
d) The edge node, since it authenticates the endpoint, encapsulates its traffic first and enforces its SGACL

Solutions:

Question: 01

Answer: b, c

Question: 02

Answer: d

Question: 03

Answer: b

Question: 04

Answer: c

Question: 05

Answer: a

Question: 06

Answer: b

Question: 07

Answer: c

Question: 08

Answer: a, d

Question: 09

Answer: b

Question: 10

Answer: d

Note: If you find any error in these Designing Cisco Enterprise Networks for Field Engineers (ENDESIGN) sample questions, you can update us by write an email on feedback@nwexam.com.

Rating: 5 / 5 (71 votes)