
試験準備には欠かさないトップクラスのCisco 500-490試験学習ガイド練習問題最新版
今すぐ500-490問題を使おう500-490問題集PDFで合格しよう
Cisco 500-490試験に合格することは、キャリアの進歩と収益の可能性の増加につながる可能性のある重要な成果です。雇用主とクライアントに、個人がCisco Technologiesを使用してエンタープライズネットワークを設計および展開するために必要なスキルと知識を持っていることを示しています。
Cisco 500-490試験では、ネットワーク設計方法、ネットワーク自動化、ネットワークセキュリティ、仮想化、ワイヤレスネットワーク設計など、エンタープライズネットワークの設計に関連する幅広いトピックをカバーしています。この試験は、組織のビジネス要件を満たす複雑なネットワークソリューションを設計および実装する候補者の能力をテストするように設計されています。
質問 # 11
Which element of the Cisco SD-WAN architecture facilitates the functions of controller discovery and NAT traversal?
- A. vSmart controller
- B. vManage
- C. vEdge
- D. vBond orchestrator
正解:D
解説:
Explanation
The vBond orchestrator is an SD-WAN router responsible for authenticating and orchestrating connectivity between the vSmart controllers and SD-WAN routers. It is the sole device in the network that requires a public IP address for all SD-WAN devices to connect to it. The vBond orchestrator has three major functions:
Controller discovery: The vBond orchestrator acts as the initial point of contact for all SD-WAN components that join the network. It authenticates the devices using pre-installed credentials and assigns them to a vSmart controller. The vBond orchestrator also provides the IP addresses of the vSmart controllers and the vManage NMS to the SD-WAN routers.
NAT traversal: The vBond orchestrator facilitates the establishment of secure DTLS or TLS tunnels between the SD-WAN components that are behind NAT devices. The vBond orchestrator acts as a rendezvous point for the NATed devices and helps them exchange their public IP addresses and port numbers. The vBond orchestrator also performs NAT keepalive and hole punching to maintain the NAT bindings and prevent the NAT devices from timing out the sessions.
Certificate management: The vBond orchestrator acts as the certificate authority (CA) for the SD-WAN network. It generates and signs the certificates for the SD-WAN components and distributes them to the devices. The certificates are used to authenticate the devices and encrypt the control and data plane traffic.
References:
Cisco SD-WAN Architecture Overview
Cisco Catalyst SD-WAN Getting Started Guide
New Training: Identify Cisco SD-WAN Components
質問 # 12
Which three key differentiators that DNA Assurance provides that our competitors are unable match? (Choose three.)
- A. Apple Insights
- B. Support for Overlay Virtual Transport
- C. VXLAN support
- D. Network time travel
- E. On-premise and cloud-based analytics
- F. Proactive approach to guided remediation
正解:A、D、F
質問 # 13
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of Scalable Group Tags
- B. use of Endpoint Groups
- C. use of overlays
- D. use of Virtual Network IDs
- E. focus on user endpoints
- F. use of group policy
正解:C、D、F
解説:
https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKDCN-2489.pdf Slide 20 -Overlay -VNID
-Group Based Policy
https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2018/pdf/BRKDCN-2489.pdf
質問 # 14
Which component of the SD Access fabric is responsible for communicating with networks that are external to the fabric?
- A. control plane nodes
- B. edge nodes
- C. border-nodes
- D. intermediate nodes
正解:B
解説:
Explanation
https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/Campus/CVD-Software-Defined-Access-Design-G
質問 # 15
Which protocol runs between the vSmart controllers and between the vSmart controllers and the vEdge routers, and unifies all control plane functions under a single protocol umbrella?
- A. OSPF
- B. VRRP
- C. BGP
- D. IKE
- E. OMP
正解:E
解説:
Explanation
The protocol that runs between the vSmart controllers and between the vSmart controllers and the vEdge routers, and unifies all control plane functions under a single protocol umbrella is the Overlay Management Protocol (OMP)12. OMP is a proprietary protocol that is designed to enable the Cisco SD-WAN solution, which provides a software overlay that runs over standard network transport, including MPLS, broadband, and internet to deliver applications and services3. OMP provides the following services12:
Orchestration of overlay network communication, including connectivity among network sites, service chaining, and VPN or VRF topologies Distribution of service-level routing information and related location mappings Distribution of data plane security parameters Central control and distribution of routing policy OMP is an all-encompassing information management and distribution protocol that enables the overlay network by separating services from transport. Services provided in a typical VPN setting are usually located within a VPN domain, and they are protected so that they are not visible outside the VPN. In such a traditional architecture, it is a challenge to extend VPN domains and service connectivity. OMP addresses these scalability challenges by providing an efficient way to manage service traffic based on the location of logical transport end points. This method extends the data plane and control plane separation concept from within routers to across the network2.
References:
1: Routing Configuration Guide for vEdge Routers, Cisco SD-WAN Release 20.x - Unicast Overlay Routing 2: Introduction to Overlay Management Protocol in Viptela 3: Cisco SD-WAN vEdge vManage vSmart IBM
質問 # 16
Which two statements are true regarding SD-WAN demonstrations? (Choose two.)
- A. During a demo, you should consider the target audience and the desired outcome.
- B. Use demonstrations primarily for large opportunities and competitive situations.
- C. During a demo, you should demonstrate and discuss what the team considers important details.
- D. As a Cisco SD-WAN SE, you should you should spend your time learning about the technology rather than contributing to demo innovation.
- E. There is a big difference between demos that use a top down approach and demos that use a bottom up approach.
正解:A、E
解説:
Explanation
SD-WAN demonstrations are an effective way to showcase the benefits and features of Cisco SD-WAN solutions to potential customers. However, not all demos are created equal, and there are some best practices to follow to ensure a successful and engaging demo. Here are some explanations for why C and E are true statements regarding SD-WAN demonstrations:
C: During a demo, you should consider the target audience and the desired outcome. This is a true statement because different audiences may have different levels of technical knowledge, business needs, and expectations from the demo. For example, a demo for a C-level executive may focus more on the business outcomes and value proposition of SD-WAN, while a demo for a network engineer may dive deeper into the technical details and configuration options. Therefore, it is important to tailor the demo to the specific audience and the desired outcome, such as generating interest, building trust, or closing a deal.
E: There is a big difference between demos that use a top down approach and demos that use a bottom up approach. This is also a true statement because the two approaches have different advantages and disadvantages, and may suit different scenarios. A top down approach starts with the high-level overview of the SD-WAN solution, such as the architecture, components, benefits, and use cases, and then drills down into the specific features and functionalities. A bottom up approach starts with the low-level details of the SD-WAN solution, such as the configuration, troubleshooting, and testing, and then builds up to the big picture and value proposition. A top down approach may be more suitable for a non-technical or business-oriented audience, while a bottom up approach may be more suitable for a technical or hands-on audience.
References :=
Cisco SD-WAN Demonstration Guide
SD-WAN Best Practices | Kentik Blog
SD-WAN best practices for a successful implementation
SD-WAN best practices - VMware Blogs
質問 # 17
Which two options help you sell Cisco ISE? (Choose two.)
- A. Downplaying the value of pxGrid as compared to RESTful APIs
- B. Explaining ISE support for 3rd party network devices
- C. Showcasing the entire ISE feature set
- D. Discussing the importance of custom profiling
- E. Referring to TrustSec as being only supported on Cisco networks
正解:B、C
質問 # 18
What should you do if you are looking at a strategic win with a customer and the customer wants to examine Cisco ISE for longer than a few weeks?
- A. Give them our ISE YouTube videos.
- B. Provide them with a downloadable POV kit.
- C. Point them to our dCloud demo library.
- D. Set them up with a dCloud account.
- E. Set them up with an account on a Cisco UCS server that hosts ISE.
- F. Give them some of our flash files that can be played on any browser.
正解:B
解説:
If you are looking at a strategic win with a customer and the customer wants to examine Cisco ISE for longer than a few weeks, you should provide them with a downloadable POV kit. A POV kit is a proof of value kit that contains a pre-configured virtual machine of Cisco ISE with licenses, sample data, and documentation. A POV kit allows the customer to quickly and easily deploy and test Cisco ISE in their own environment, without requiring any hardware or installation. A POV kit can help the customer to evaluate the features and benefits of Cisco ISE,such as identity-based access control, device profiling, posture assessment, guest management, and threat mitigation12.
The other options are not suitable for a customer who wants to examine Cisco ISE for longer than a few weeks. Pointing them to our dCloud demo library, giving them our ISE YouTube videos, or giving them some of our flash files that can be played on any browser are good ways to introduce Cisco ISE to the customer, but they do not provide a hands-on experience or a realistic scenario of how Cisco ISE works in their network.
Setting them up with a dCloud account or an account on a Cisco UCS server that hosts ISE are also possible ways to provide a demo or a trial of Cisco ISE, but they may have limitations on the duration, availability, scalability, or customization of the environment. A POV kit gives the customer more flexibility and control over their evaluation of Cisco ISE.
References :=
* Solved: ISE PoV licenses - Cisco Community
* Cisco Endpoint Security Analytics (CESA) Built on Splunk Quickstart POV Kit & Deployment Guide - Cisco Community While scheduling a session you can choose to Extend the session longer than 5 days by checking this check box. An initial session scheduled shorter than 5 days can later be extended up to the 5-day total. To extend an active session longer than 5 days, submit a session extension request.
https://dcloud-cms.cisco.com/help/sched_demo#:~:text=An%20initial%20session%20scheduled%20shorter,subm kitshttps://community.cisco.com/t5/security-knowledge-base/product-proof-of-value-pov/ta-p/3633986/redirect_
質問 # 19
Which Cisco product were incorporated into Cisco ISE between ISE releases 2.0 and 2.3?
- A. Cisco WSA
- B. Cisco ASA
- C. Cisco ACS
- D. Cisco ESA
正解:C
質問 # 20
Which component of the SD-Access fabric is responsible for communicating with networks that are external to the fabric?
- A. border nodes
- B. control plane nodes
- C. edge nodes
- D. intermediate nodes
正解:A
解説:
= Border nodes are the component of the SD-Access fabric that is responsible for communicating with networks that are external to the fabric. Border nodes serve as the gateway between the fabric domain and the network outside of the fabric. Border nodes are responsible for network virtualization inter-working and SGT propagation from the fabric to the rest of the network1. Border nodes also perform LISP Proxy Tunnel Router (PxTR) functions, which convert policy and reachability information, such as SGT and VRF information, from one domain to another2. Border nodes can connect to internal networks, such as data center or WAN, or external networks, such as internet or cloud3.
Edge nodes, control plane nodes, and intermediate nodes are not responsible for communicating with networks that are external to the fabric. Edge nodes are the access-layer switches where all of the endpoints reside. Edge nodes detect clients and register them with the control plane nodes. Edge nodes also providean anycast L3 gateway for the connected endpoints and perform encapsulation and de-encapsulation of data traffic4. Control plane nodes are the devices that run a host tracking database to map location information. Control plane nodes receive endpoint ID map registrations from edge and/or border nodes and resolve lookup requests from edge and/or border nodes to locate destination endpoint IDs5. Intermediate nodes are the devices that provide underlay connectivity between edge nodes and border nodes. Intermediate nodes do not participate in the fabric overlay and do not have any fabric roles6.
References :=
* Role of Fabric Border Node & IS-IS protocol in Cisco SD-Access
* Software Defined Access Network Fabric Roles - Study CCNP
* Cisco SD-Access
* SD-Access Fabric Troubleshooting Guide - Cisco
* Cisco SD-Access Solution Design Guide (CVD) - Cisco
* Cisco SD-Access Solution Design Guide (CVD) - Cisco
* Cisco SD-Access Solution Design Guide (CVD) - Cisco
質問 # 21
Which two options help you sell Cisco ISE? (Choose two.)
- A. Downplaying the value of pxGrid as compared to RESTful APIs
- B. Explaining ISE support for 3rd party network devices
- C. Showcasing the entire ISE feature set
- D. Discussing the importance of custom profiling
- E. Referring to TrustSec as being only supported on Cisco networks
正解:B、C
解説:
Explanation
Cisco ISE is a comprehensive solution that enables enterprises to enforce consistent and secure access policies across wired, wireless, and VPN connections. It also provides visibility, control, and automation for the network devices, endpoints, users, and applications. To sell Cisco ISE effectively, it is important to highlight the benefits and features of the solution that address the customer's pain points and needs. Among the options given, two options help you sell Cisco ISE:
Showcasing the entire ISE feature set: ISE has a rich and diverse feature set that covers various use cases, such as device management, asset visibility, software-defined segmentation, software-defined access, guest and wireless access, BYOD, posture assessment, threat detection and response, and more1.
By showcasing the entire ISE feature set, you can demonstrate the value proposition and differentiation of ISE from other solutions, and how it can help the customer achieve their business and technical goals.
Explaining ISE support for 3rd party network devices: ISE is not limited to Cisco networks only. It can also support 3rd party network devices that comply with the standard protocols and interfaces, such as RADIUS, SNMP, TACACS+, 802.1X, MAB, CoA, and EAP2. By explaining ISE support for 3rd party network devices, you can show the customer that ISE is a flexible and interoperable solution that can work with their existing network infrastructure, and that they do not need to replace their non-Cisco devices to deploy ISE.
The other three options are not helpful for selling Cisco ISE:
Referring to TrustSec as being only supported on Cisco networks: TrustSec is a Cisco technology that enables software-defined segmentation based on security group tags (SGTs) and security group access control lists (SGACLs)3. TrustSec is not only supported on Cisco networks, but also on 3rd party network devices that can integrate with ISE through pxGrid, which is a platform for sharing contextual information across multiple security products4. By referring to TrustSec as being only supported on Cisco networks, you can create a false impression that ISE is a proprietary and closed solution that requires a complete Cisco network overhaul, which can discourage the customer from adopting ISE.
Discussing the importance of custom profiling: Profiling is a feature of ISE that allows it to identify and classify the endpoints on the network based on their attributes, such as MAC address, IP address, device type, operating system, etc.5. Custom profiling is the ability to create custom profiles and policies for the endpoints that are not recognized by the default ISE profiles. While custom profiling is an important feature of ISE, it is not a key selling point, because it is a complex and time-consuming process that requires a deep understanding of the endpoint attributes and behaviors, and it may not be relevant or applicable for all customers. By discussing the importance of custom profiling, you can confuse or overwhelm the customer with technical details that are not essential for their use case, and divert their attention from the core benefits and features of ISE.
Downplaying the value of pxGrid as compared to RESTful APIs: pxGrid is a platform that enables ISE to share contextual information, such as identity, location, posture, device type, etc., with other security products, such as firewalls, SIEMs, threat detection systems, etc.4. RESTful APIs are a standard way of communicating with web services, such as ISE, using HTTP methods, such as GET, POST, PUT, DELETE, etc... Both pxGrid and RESTful APIs are valuable for ISE, because they provide different capabilities and benefits. pxGrid allows ISE to exchange real-time and bidirectional information with other security products, and to enforce consistent policies across the network4. RESTful APIs allow ISE to be integrated with external applications and systems, such as portals, dashboards, workflows, etc., and to automate and customize the network operations. By downplaying the value of pxGrid as compared to RESTful APIs, you can misrepresent the functionality and potential of ISE, and miss the opportunity to showcase how ISE can enhance the security and efficiency of the network.
References:
Cisco Identity Services Engine (ISE) Use Cases1 : Cisco Identity Services Engine Network Component Compatibility, Release 2.72 : Cisco TrustSec3 : Cisco pxGrid4 : Cisco ISE Network Discovery5 : Cisco Identity Services Engine Administrator Guide, Release 2.7 - Configure Custom Profiling Policies [Cisco Identity Services Engine] - Cisco : Cisco Identity Services Engine API Reference Guide, Release 2.7 - Cisco ISE REST APIs [Cisco Identity Services Engine] - Cisco
質問 # 22
How would cisco ISE handle authentication for your printer that does not have a supplicant?
- A. ISE would authenticate the printer using web authentication.
- B. ISE would authenticate the printer using 8.2.1X authentication
- C. ISE would authenticate the printer using MAC RADIUS authentication
- D. ISE would authenticate the printer using MAB.
- E. ISE would not authenticate the printer as printers are not subject to ISE authentication.
正解:B
質問 # 23
Which Cisco product supports SD-Access and specifically built to address new challenges faced by enterprises?
- A. Catalyst 6807-XL w/ Sup6T and C6800 10G line cards
- B. Catalyst 9500
- C. CSRv virtual router
- D. ASR 1000-HX
- E. Nexus 7700 w/ Sup2E and M3 line cards
- F. ISR 4221
正解:B
解説:
The Cisco Catalyst 9500 Series Switches are specifically built to address the new challenges faced by enterprises, such as the need for increased bandwidth, security, and scalability. The Catalyst 9500 Series Switches are also designed to support Cisco SD-Access, which is a software-defined access fabric that simplifies network management and improves network security.
References: =
* Designing Cisco Enterprise Networks
(ENDESIGN): https://www.cisco.com/c/en/us/training-events/training-certifications/training/training-serv
* Cisco Catalyst 9500 Series
Switches: https://www.cisco.com/site/us/en/products/networking/switches/catalyst-9500-series-switches/in The Catalyst 9K platform has been built to address security risks posed by advanced persistent threats, operational complexities associated with IoT convergence, evolving mobility requirements and a need to take advantage of Cloud agility & consumption models.https://www.orbe.es/wp-content/uploads/2017/11/DNA_Bootcamp_SDA_CustomerLEO_Orbe.compress Slide 63
質問 # 24
Which two activities should occur during an SE's discovery process? (Choose two.)
- A. Referencing the PPDIOO model to effectively facilitate the discussion
- B. Establishing credibility with the customer
- C. Mapping Cisco innovation to customer 's needs
- D. Gathering information about the current state of the customer 's network environment
- E. Working with the customer to develop a reference architecture
正解:C、D
解説:
The discovery process is a critical phase in the sales cycle, where the SE gathers information about the customer's network environment, business goals, challenges, and needs. The discovery process helps the SE to understand the customer's pain points, identify opportunities, and propose solutions that align with the customer's objectives and address their problems. The discovery process also helps the SE to establish credibility, trust, and rapport with the customer, and to map Cisco innovation to the customer's needs.
Some of the activities that should occur during the SE's discovery process are:
* Gathering information about the current state of the customer's network environment. This includes collecting data about the network topology, devices, protocols, applications, performance, security, availability, scalability, and management. The SE can use various tools and methods to gather this information, such as interviews, questionnaires, surveys, audits, assessments, and network analysis tools. Gathering information about the current state helps the SE to understand the customer's existing network capabilities, limitations, and gaps, and to benchmark the network against best practices and industry standards12
* Mapping Cisco innovation to the customer's needs. This involves identifying how Cisco products, solutions, and services can help the customer achieve their desired outcomes, address their challenges, and overcome their pain points. The SE can use various tools and methods to map Cisco innovation to the customer's needs, such as value proposition, business case, return on investment (ROI) analysis, proof of value (POV), proof of concept (POC), and demonstrations. Mapping Cisco innovation to the customer's needs helps the SE to show the value and benefits of Cisco solutions, differentiate Cisco from competitors, and influence the customer's decision making34 References:
1: Cisco Discovery Service 2: Cisco Network Assessment Services 3: Cisco Catalyst SD-WAN Demos 4:
Cisco Business Critical Services
質問 # 25
Which three options focus of the current digital business era'? (Choose three.)
- A. centralized enterprise and web applications
- B. virtualized services
- C. connectivity
- D. automation
- E. loT scale
- F. Human scale
正解:B、D、E
質問 # 26
Which two Cisco ISE use cases typically involve the highest level of implementation complexity? (Choose two.)
- A. Device management
- B. Software-defined access
- C. Guest and wireless access
- D. Software-defined segmentation
- E. Asset visibility
正解:B、D
解説:
Explanation
Cisco ISE use cases can be classified into four categories: device management, asset visibility, software-defined segmentation, and software-defined access. Each of these use cases has a different level of implementation complexity, depending on the network size, topology, security requirements, and integration with other technologies. Among these use cases, software-defined segmentation and software-defined access typically involve the highest level of implementation complexity, because they require:
A thorough understanding of the network architecture and design principles, such as hierarchical, modular, and scalable design.
A comprehensive assessment of the network devices, endpoints, users, applications, and policies, and their interdependencies and interactions.
A careful planning and testing of the network segmentation and access policies, using tools such as Cisco TrustSec, Cisco DNA Center, Cisco SD-Access, and Cisco ISE .
A smooth and secure migration from the existing network to the software-defined network, with minimal disruption and downtime.
A continuous monitoring and optimization of the network performance, security, and compliance, using tools such as Cisco Stealthwatch, Cisco Tetration, and Cisco ISE .
References:
Cisco Identity Services Engine (ISE) Use Cases,
https://www.cisco.com/c/en/us/products/security/identity-services-engine/use-cases.html : Cisco Enterprise Network Architecture and Design,
https://www.cisco.com/c/en/us/solutions/design-zone/networking-design-guides/enterprise-networking-design.ht: Cisco ISE Network Discovery,
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide: Cisco TrustSec, https://www.cisco.com/c/en/us/solutions/enterprise-networks/trustsec/index.html : Cisco DNA Center, https://www.cisco.com/c/en/us/products/cloud-systems-management/dna-center/index.html :
Cisco SD-Access,
https://www.cisco.com/c/en/us/solutions/enterprise-networks/software-defined-access/index.html : Cisco ISE Software-Defined Access,
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide : Cisco SD-Access Migration Guide,
https://www.cisco.com/c/en/us/td/docs/solutions/CVD/Campus/sda-migration-guide.html : Cisco Stealthwatch, https://www.cisco.com/c/en/us/products/security/stealthwatch/index.html : Cisco Tetration,
https://www.cisco.com/c/en/us/products/data-center-analytics/tetration/index.html : Cisco ISE Monitoring and Troubleshooting,
https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/admin_guide/b_ise_admin_guide_26/b_ise_admin_guide
質問 # 27
Which feature is supported on the Cisco vEdge platform?
- A. single sign-on
- B. IPv6 transport (WAN)
- C. reporting
- D. license enforcement
- E. 2-factor authentication
- F. non-Ethernet interfaces
正解:B
解説:
https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/segmentation/vEdge-20-x/segmentation-boo The Cisco vEdge platform supports IPv6 transport (WAN) as one of its features. This means that the vEdge routers can use IPv6 addresses to establish secure control and data plane connections with other vEdge routers over the WAN network. The vEdge routers can also use IPv6 addresses to communicate with the vSmart controllers and the vManage network management system. The vEdge routers can also support IPv6 routing protocols, such as OSPFv3 and BGP, to exchange IPv6 routes with other routers in the network12.
The other features listed in the question are not supported on the Cisco vEdge platform. License enforcement is not applicable to the vEdge routers, as they do not require any license to operate. Reporting is a function of the vManage network management system, which collects and displays various statistics and analytics from the vEdge routers. Non-Ethernet interfaces, such as serial, T1/E1, or DSL, are not available on the vEdge routers, which only support Ethernet and cellular interfaces. Single sign-on and 2-factor authentication are not supportedon the vEdge routers, which use local or remote authentication methods, such as TACACS+, RADIUS, or LDAP3.
References:
1: Cisco SD-WAN vEdge Routers Data Sheet 2: Cisco SD-WAN Configuration Guide, Release 20.3 3: Cisco SD-WAN Command Reference, Release 20.3
質問 # 28
......
Cisco 500-490認定は、業界で高く評価され、ネットワークプロフェッショナルとしてのキャリアを進めるために役立ちます。この試験に合格することで、複雑な企業ネットワークの設計と実装に関する専門知識を証明し、今日の急速に変化するビジネス環境において重要なスキルを習得します。さらに、この認定資格は新しい仕事の機会を開拓し、収益性を高めることができます。
無料Field Engineer 500-490試験問題:https://www.jpntest.com/shiken/500-490-mondaishu
問題集練習試験問題学習ガイドは500-490試験で使える:https://drive.google.com/open?id=1oUHobIgOwRu44N-PiskbvmYZw4lMOd7d