
最適な練習法にはCisco 500-490問題集で素晴らしい500-490試験問題PDF
更新された検証済みの合格させる500-490試験リアル問題と解答
CCDE認定は業界で高く評価されており、ネットワーク設計の卓越性のマークとして認識されています。これは、ネットワーク設計の原則を深く理解し、組織に戦略的な方向性を提供できる上級レベルのネットワークエンジニア向けに設計されています。この認定は、候補者の専門能力開発へのコミットメントと、業界の最新の技術とトレンドに最新の状態を維持することへの献身の証でもあります。
Cisco 500-490認定試験は、Cisco Technologiesを使用してエンタープライズネットワークを設計する専門知識を実証することに関心のあるIT専門家向けに設計されています。この試験は、Cisco Certified Network Professional(CCNP)Enterprise Trackの一部であり、自動化、仮想化、セキュリティなどの高度なネットワーク設計原則における候補者の知識とスキルをテストするように設計されています。
質問 # 21
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of Scalable Group Tags
- B. use of Endpoint Groups
- C. use of group policy
- D. focus on user endpoints
- E. use of Virtual Network IDs
- F. use of overlays
正解:C、E、F
質問 # 22
How would cisco ISE handle authentication for your printer that does not have a supplicant?
- A. ISE would authenticate the printer using MAB.
- B. ISE would authenticate the printer using MAC RADIUS authentication
- C. ISE would not authenticate the printer as printers are not subject to ISE authentication.
- D. ISE would authenticate the printer using web authentication.
- E. ISE would authenticate the printer using 8.2.1X authentication
正解:A
質問 # 23
Which two statements describes Cisco SD-Access? (Choose two.)
- A. software-defined segmentation and policy enforcement based on user identity and group membership
- B. an overlay for the wired infrastructure in which traffic is tunneled via a GRE tunnel to a mobility controller for policy and application visibility
- C. a collection of tools and applications that are a combination of loose and tight couping
- D. programmable overlays enabling network virtualization across the campus
- E. an automated encryption/decryption engine for highly secured transport requirements
正解:A、D
解説:
Cisco SD-Access is a solution within Cisco DNA, which is built on intent-based networking principles. Cisco SD-Access provides visibility-based, automated end-to-end segmentation to separate user, device, and application traffic without redesigning the underlying physical network1. Cisco SD-Access also enables programmable overlays that allow network virtualization across the campus,branch, data center, and cloud2. Cisco SD-Access has two main components: the fabric and the policy3.
The fabric is the network overlay that consists of interconnected nodes that provide a consistent and scalable way of delivering network services and functions. The fabric nodes are classified into four types: edge nodes, border nodes, control plane nodes, and intermediate nodes. The edge nodes are the access switches or wireless controllers that connect to the end devices. The border nodes are the routers or switches that connect the fabric to external networks, such as the Internet, WAN, or data center. The control plane nodes are the routers or switches that maintain the mapping between the endpoint identifiers and the network locators. The intermediate nodes are the routers or switches that provide transit services within the fabric3.
The policy is the network configuration that defines the network behavior and outcomes, based on the business intent and requirements. The policy is composed of three elements: the endpoint groups, the contracts, and the virtual networks. The endpoint groups are the logical containers that group the endpoints based on their attributes, such as user identity, device type, or application. The contracts are the rules that specify the allowed interactions between the endpoint groups, such as the protocols, ports, and quality of service. The virtual networks are the logical partitions that isolate the endpoint groups and contracts from each other, based on the network scope and security3.
Cisco SD-Access addresses the following challenges and benefits:
* It simplifies the network design and management, as it reduces the complexity and variability of the network elements and interfaces.
* It enhances the network security and compliance, as it enforces granular and dynamic policies based on the endpoint identity and context, rather than the network topology and IP addresses.
* It improves the network performance and user experience, as it optimizes the network path, load balancing, and traffic engineering based on the network conditions and application requirements.
* It enables the network agility and scalability, as it supports the rapid deployment and integration of new devices, applications, and services, without affecting the existing network operations.
References:
* Cisco Software-Defined Access - Cisco Software-Defined Access Solution Overview
* What Is Software-Defined Access? - SD-Access - Cisco
* Cisco SD-Access Architecture Overview
質問 # 24
Which two Cisco ISE use cases typically involve the highest level of implementation complexity? (Choose two.)
- A. Software defined access
- B. Software defined segmentation
- C. Guest and wireless access
- D. Asset visibility
- E. Device management
正解:C、E
質問 # 25
Which two statements are true regarding Cisco ISE? (Choose two.)
- A. The number of logs that ISE can retain is determined by your disk space.
- B. In two-node standalone ISE deployments, failover must be done manually.
- C. ISE can detected endpoints whose addresses have been translated via NAT.
- D. In distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically.
- E. ISE supports up to 100 Policy Services Nodes.
- F. ISE supports IPv6 downloadable ACLs.
正解:A、F
解説:
Cisco ISE is a security policy management platform that provides secure access to network resources. Cisco ISE functions as a policy decision point and enables enterprises to ensure compliance, enhance infrastructure security, and streamline service operations1. Two of the statements that are true regarding Cisco ISE are:
* ISE can detect endpoints whose addresses have been translated via NAT: Cisco ISE can discover,
* profile, and monitor the endpoint devices on the network, and classify them according to their associated policies and identity groups. Cisco ISE can leverage the pxGrid framework to share the contextual information with other security tools and platforms, and enhance the network visibility and security1. Cisco ISE can also detect endpoints whose addresses have been translated via NAT by using various methods, such as passive and active discovery, NMAP scanning, DHCP snooping, and RADIUS accounting234.
* The number of logs that ISE can retain is determined by your disk space: Cisco ISE provides a logging mechanism that is used for auditing, faultmanagement, and troubleshooting. The logging mechanism helps you to identify fault conditions in deployed services and troubleshoot issues efficiently. You can configure your Cisco ISE node to collect the logs in the local systems using a virtual loopback address5. The number of logs that ISE can retain is determined by your disk space, as well as the data purging settings that you can configure under Administration > System > Maintenance > Data Purging6. You can also configure Cisco ISE to send its logs to a remote system for greater retention history7.
The other statements are not true regarding Cisco ISE, because:
* In distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically: Cisco ISE supports high availability for the Administration persona, which provides centralized configuration and management of the distributed deployment. You can configure one primary Administration ISE node and one secondary Administration ISE node for high availability. However, the failover from primary to secondary Policy Administration Nodes does not happen automatically, unless you enable the automatic failover feature and configure a health check node to monitor the primary node's status8. Otherwise, you have to manually promote the secondary node to become the primary node in case of a failure9.
* In two-node standalone ISE deployments, failover must be done manually: Cisco ISE supports high availability for the Policy Service persona, which provides network access, posture, guest access, client provisioning, and profiling services. You can configure multiple Policy Service Nodes (PSNs) in a node group to provide session failover and load balancing for the endpoints. In a two-nodestandalone ISE deployment, where each node assumes all the personas, the failover for the Policy Service persona does not need to be done manually, as long as the network access devices are configured to use both nodes for RADIUS and TACACS services10.
* ISE supports IPv6 downloadable ACLs: Cisco ISE supports downloadable ACLs (DACLs), which are configured and implemented through authorization profiles. DACLs are used to enforce granular access control policies for the endpoints based on their identity and other attributes. However, Cisco ISE does not support IPv6 downloadable ACLs, as it only supports IPv4 ACLs for RADIUS and TACACS protocols1112.
References:
1: Cisco Content Hub - Cisco ISE Features 2: Cisco ISE Profiler Service Overview 3: ISE Deployment through NAT Boundaries - Cisco Community 4: Configure ISE 3.3 Native IPSec to Secure NAD (IOS-XE) Communication - Cisco 5: Logging [Cisco Identity Services Engine] - Cisco Systems 6: ISE maximum logging time / data retention - Cisco Community 7: Logs retention on ISE - Cisco Community 8: Cisco Identity Services Engine Administrator Guide, Release 2.4 9: Setting Up Cisco ISE in a Distributed Environment 10: Cisco Content Hub - Network Deployments in Cisco ISE 11: Cisco Identity Services Engine Administrator Guide, Release 2.2 12: Solved: ISE: support for IPv6 DACL's - Cisco Community
"There is no automatic failover for the Administration
persona."https://www.cisco.com/en/US/docs/security/ise/1.0/user_guide/ise10_dis_deploy.html...Newer platforms and ISE versions appear to support ipv6 dacl just fine now
質問 # 26
Which are two Cisco ISE that benefits our customers? (Choose two.)
- A. provides network access control
- B. helps t hem stop and contain real-time threats
- C. helps t hem accelerate application deployment and delivery
- D. enables them to set traffic priorities across the network
正解:A、B
解説:
Explanation
Cisco ISE benefits our customers by providing network access control and helping them stop and contain real-time threats. Network access control is the ability to enforce policies on who and what can access the network, based on the identity and context of users, devices, and applications. Cisco ISE allows customers to authenticate, authorize, and audit network access, as well as to segment and isolate network traffic based on security and compliance requirements. Cisco ISE also helps customers stop and contain real-time threats by leveraging intel from across the network and security ecosystem, and by automating threat response actions.
Cisco ISE can integrate with various security solutions, such as Cisco Stealthwatch, Cisco Firepower, and Cisco Umbrella, to detect and mitigate attacks on the network quickly and effectively. References:
Cisco Identity Services Engine (ISE) - Cisco1
Cisco Identity Services Engine (ISE) - Cisco2
Network Visibility and Segmentation (NVS) - Cisco3
Rapid Threat Containment - Cisco4
質問 # 27
Which three options focus of the current digital business era'? (Choose three.)
- A. automation
- B. Human scale
- C. connectivity
- D. loT scale
- E. virtualized services
- F. centralized enterprise and web applications
正解:A、D、E
質問 # 28
What is the easiest way to enable SD-Access for all your remote site after you have your campus SD-Access fabric up and running?
- A. Treat all the sites as one fabric domain and use SD-WAN as the underlay
- B. Treat all the sites as one fabric domain and use the traditional physical network as the underlay
- C. Use a separate fabric domain for each site and use the traditional physical network as the underlay
- D. Use a separate fabric domain for each site and use SD-WAN as the underlay
正解:A
質問 # 29
Which two statements are true regarding SD-WAN demonstrations? (Choose two.)
- A. During a demo, you should demonstrate and discuss what the team considers important details
- B. During a demo you should consider the target audience and the desired outcome
- C. There is a big difference between demos that use a top down approach and demos that use a bottom up approach
- D. Use demonstrations primarily for large opportunities and competitive situations
- E. As a Cisco SD-WAN SF, you should you should spend your time learning about the technology rather than contributing to demo innovation
正解:B、C
質問 # 30
What are three ways in which Cisco ISE learns information about devices? (Choose three.)
- A. traffic generated by the device
- B. network servers the device has accessed
- C. SMTP agents
- D. user authentication to the ISE
- E. RADIUS attributes
- F. RPC mechanism via HTTPS
正解:A、D、E
質問 # 31
What should you do if you are looking at a strategic win with a customer and the customer wants to examine Cisco ISE for longer than a few weeks?
- A. Provide them to our d Cloud demo library
- B. Give then, some of our flash files mat can be played on any browser
- C. Set them up with a d Cloud account
- D. Provide them with a downloadable POV kit
- E. Give them our ISE YouTube videos
- F. Set them up with an account on a Cisco UCS server that hosts ISE
正解:C
質問 # 32
Which two primary categories are displayed on the overall health page of the assurance component in the Cisco DNA Center? (Choose two.)
- A. Network
- B. Client
- C. Access-Distribution
- D. Wired
- E. Core
- F. Server
正解:A、B
解説:
Explanation
The overall health page of the assurance component in the Cisco DNA Center displays two primary categories: Client and Network1. The Client category shows the health score of all the wired and wireless clients connected to the network, along with the number of clients, the top issues affecting the clients, and the distribution of clients by type, OS, and SSID1. The Network category shows the health score of all the network devices, such as switches, routers, wireless controllers, and access points, along with the number of devices, the top issues affecting the devices, and the distribution of devices by site, family, and role1.
The other options are not primary categories on the overall health page. Server is not a category, but a type of client that can be filtered in the Client category1. Access-Distribution and Core are not categories, but roles of network devices that can be filtered in the Network category1. Wired is not a category, but a subcategory of the Client category that shows the health score of the wired clients only1.
References:
Cisco DNA Assurance User Guide, Release 1.3.1.0 - Monitor and Troubleshoot the Health of Your Network [Cisco DNA Center] Designing Cisco Enterprise Networks (ENDESIGN) Exam Topics [Cisco] Cisco Validated Design Guides [Cisco]
質問 # 33
What are three ways in Which Cisco ISE learns information about devices? (Choose three,)
- A. SMIP agents
- B. user authentication to the ISE
- C. traffic generated by the device
- D. network servers the device has accessed
- E. RADIUS attributes
- F. RPC mechanism via HTTPS
正解:C、D、E
質問 # 34
Which three ways are SD-Access and ACI Fabric similar? (Choose three.)
- A. use of Scalable Group Tags
- B. focus on user endpoints
- C. use of Virtual Network IDs
- D. use of group policy
- E. use of overlays
- F. use of Endpoint Groups
正解:A、E、F
解説:
Explanation
SD-Access and ACI Fabric are both solutions that provide software-defined networking for different domains.
SD-Access is designed for the campus and branch networks, while ACI Fabric is designed for the data center networks. However, they share some common features and concepts, such as:
Use of Scalable Group Tags: Both SD-Access and ACI Fabric use Scalable Group Tags (SGTs) to identify and classify the endpoints based on their attributes, such as user identity, device type, or application. SGTs are numerical labels that are assigned to the endpoints and carried in the packets, either in the header or in the metadata. SGTs enable granular and dynamic policy enforcement based on the endpoint identity and context, rather than the network topology and IP addresses12.
Use of overlays: Both SD-Access and ACI Fabric use overlays to create a network abstraction layer that decouples the network services and functions from the underlying physical infrastructure. Overlays enable network virtualization and segmentation, as they allow multiple logical networks to coexist on the same physical network. Overlays also simplify the network design and management, as they reduce the complexity and variability of the network elements and interfaces. SD-Access uses VXLAN as the overlay protocol, while ACI Fabric uses VXLAN with EVPN as the overlay protocol34.
Use of Endpoint Groups: Both SD-Access and ACI Fabric use Endpoint Groups (EPGs) to group the endpoints based on their policy requirements and network scope. EPGs are logical containers that define the allowed interactions between the endpoints, such as the protocols, ports, and quality of service.
EPGs also define the network boundaries that isolate the endpoints from each other, based on the security and compliance needs. EPGs are synonymous with Scalable Groups in SD-Access, and they can be mapped between SD-Access and ACI Fabric to enable end-to-end policy across the domains56.
References:
Cisco TrustSec Overview
Cisco TrustSec Configuration Guide, Cisco IOS XE Gibraltar 16.12.x - Scalable Group Tags [Cisco IOS XE 16] - Cisco Cisco SD-Access Architecture Overview Cisco Application Centric Infrastructure Fundamentals, Release 4.0(1) - ACI Fabric Fundamentals
[Cisco Application Policy Infrastructure Controller (APIC)] - Cisco
Cisco SD-Access (SDA) Integration with Cisco Application Centric Infrastructure (ACI) - Cisco Community Cisco Application Centric Infrastructure - Cisco Multidomain Integration At-a-Glance
質問 # 35
Which two activities should occur during an SE's discovery process? (Choose two.)
- A. Referencing the PPDIOO model to effectively facilitate the discussion
- B. Working with the customer to develop a reference architecture
- C. Establishing credibility with the customer
- D. Mapping Cisco innovation to customer 's needs
- E. Gathering information about the current state of the customer 's network environment
正解:D、E
質問 # 36
What are three ways in which Cisco ISE learns information about devices? (Choose three.)
- A. traffic generated by the device
- B. network servers the device has accessed
- C. SMTP agents
- D. user authentication to the ISE
- E. RADIUS attributes
- F. RPC mechanism via HTTPS
正解:A、D、E
解説:
Explanation
Cisco ISE learns information about devices by using various methods, such as network probes, user authentication, and endpoint identity groups. Three ways in which Cisco ISE learns information about devices are:
B: RADIUS attributes: Cisco ISE can use the RADIUS protocol to collect information about devices from network access devices (NADs), such as switches, routers, and wireless controllers. The NADs can send RADIUS accounting packets to Cisco ISE that contain attributes related to the device identity, such as MAC address, IP address, hostname, device type, and vendor. Cisco ISE can use these attributes to profile the device and assign it to an endpoint identity group12.
D: user authentication to the ISE: Cisco ISE can also learn information about devices by authenticating the users who access the network through the devices. Cisco ISE can use various authentication methods, such as 802.1X, MAC Authentication Bypass (MAB), web authentication, or certificate-based authentication, to verify the identity and credentials of the users. Cisco ISE can then associate the user identity with the device identity and apply the appropriate authorization policies based on the user role, device type, and network context34.
E: traffic generated by the device: Cisco ISE can also learn information about devices by analyzing the traffic generated by the devices on the network. Cisco ISE can use various network probes, such as DHCP, SNMP, HTTP, DNS, or NetFlow, to capture and inspect the packets sent by the devices. Cisco ISE can then extract information from the packet headers and payloads, such as device name, operating system, browser type, application name, or domain name, and use it to profile the device and assign it to an endpoint identity group56.
References :
Cisco ISE Profiling Services
Configuring Profiler Policies
Cisco ISE Authentication Services
Configuring Device Sensor for ISE Profiling
Cisco ISE Endpoint Profiling Policies
ISE Profiling Design Guide
質問 # 37
Which two primary categories are displayed on the overall health page of the assurance component in the Cisco DNA Center? (Choose two.)
- A. Network
- B. Client
- C. Access-Distribution
- D. Wired
- E. Core
- F. Server
正解:A、B
質問 # 38
How would Cisco ISE handle authentication for your printer that does not have a supplicant?
- A. ISE would authenticate the printer using MAC RADIUS authentication.
- B. ISE would authenticate the printer using 802.1X authentication.
- C. ISE would authenticate the printer using MAB.
- D. ISE would not authenticate the printer as printers are not subject to ISE authentication.
- E. ISE would authenticate the printer using web authentication.
正解:C
質問 # 39
Which are two Cisco ISE that benefits our customers? (Choose two.)
- A. provides network access control
- B. helps t hem accelerate application deployment and delivery
- C. helps them stop and contain real-time threats
- D. enables them to set traffic priorities across the network
正解:A、C
解説:
Cisco ISE benefits our customers by providing network access control and helping them stop and contain real-time threats. Network access control is the ability to enforce policies on who and what can access the network, based on the identity and context of users, devices, and applications. Cisco ISE allows customers to authenticate, authorize, and audit network access, as well as to segment and isolate network traffic based on security and compliance requirements. Cisco ISE also helps customers stop and contain real-time threats by leveraging intel from across the network and security ecosystem, and by automating threat response actions.
Cisco ISE can integrate with various security solutions, such as Cisco Stealthwatch, Cisco Firepower, and Cisco Umbrella, to detect and mitigate attacks on the network quickly and effectively. References:
* Cisco Identity Services Engine (ISE) - Cisco1
* Cisco Identity Services Engine (ISE) - Cisco2
* Network Visibility and Segmentation (NVS) - Cisco3
* Rapid Threat Containment - Cisco4
https://salesconnect.cisco.com/sc/s/learning-activity-from-plan?ltui__urlRecordId=a0c8c00000Kfw0AAAR<u Slide 3 - ISE is critical to your customer - * Visibility in to users, devices & applications * Access control and segmentation * Stop and contain threats in real-time
質問 # 40
Which two activities should occur during an SE's demo process? (Choose two.)
- A. highlighting opportunities that although not currently withinscope would result in lower operational costs and complexity
- B. determining whether the customer would like to dive deeper during a follow -up
- C. leveraging a company such as Complete Communications to build a financial case
- D. asking the customer to provide network drawings or white board the environment for you
- E. identifying which capabilities require demonstration
正解:A、B
質問 # 41
......
Cisco 500-490試験は、複雑な企業ネットワークソリューションの設計と実装を担当するネットワークデザイナーの知識とスキルを検証する認定試験です。この試験は、Cisco Certified Network Professional(CCNP)Enterprise認定トラックの一部であり、安全でスケーラブルで強靭な企業ネットワークを設計・実装する能力をテストするよう設計されています。
更新されたPDF(2024年最新)実際にあるCisco 500-490試験問題:https://www.goshiken.com/Cisco/500-490-mondaishu.html
問題集返金保証付きの500-490問題集公式問題集:https://drive.google.com/open?id=1V47Tzyth7PS7do1KCii9ovZJx7DTlSqZ