Engineering Cisco Meraki Solutions (ECMS) 500-220 — Questions and Answers
Question 1: What is the recommended Meraki architecture for providing high-availability at a data center hub site with no single point of failure?
- Active-active clustering of four MX appliances
- Dual ISP connections to a single MX
- Single high-powered MX with RAID storage
- Warm Spare (VRRP) with two MX appliances sharing a virtual IP (Correct answer)
Correct answer: Warm Spare (VRRP) with two MX appliances sharing a virtual IP
Meraki Warm Spare uses VRRP to deploy two MX appliances where one is active and one is standby; if the active unit fails, the standby takes over the virtual IP within seconds.
Question 2: What does the Meraki MX 'Flow' data, visible in the traffic analytics section, represent?
- Switch VLAN trunk statistics
- VPN tunnel negotiation logs
- Detailed per-application and per-destination traffic flows through the MX (Correct answer)
- CPU and memory utilization of the MX appliance
Correct answer: Detailed per-application and per-destination traffic flows through the MX
Traffic analytics on the Meraki MX uses deep packet inspection to display per-application, per-client, and per-destination traffic flows, enabling visibility into bandwidth consumption.
Question 3: What is the purpose of Meraki's 'Band Steering' feature on MR access points?
- It blocks single-band 2.4 GHz-only clients from connecting
- It encourages dual-band clients to connect to the 5 GHz band instead of 2.4 GHz (Correct answer)
- It combines 2.4 and 5 GHz into a single virtual band
- It physically steers the antenna beam toward clients
Correct answer: It encourages dual-band clients to connect to the 5 GHz band instead of 2.4 GHz
Band steering uses 802.11k/v mechanisms to encourage capable clients to associate with the less congested 5 GHz radio instead of 2.4 GHz.
Question 4: On a Meraki MR access point, what is the purpose of the 'Minimum Bitrate' setting in an RF profile?
- It sets the lowest data rate at which the AP will transmit, helping exclude distant or weak clients (Correct answer)
- It sets the minimum RSSI threshold for new client associations
- It defines the minimum WPA2 encryption key length
- It caps the maximum throughput per client
Correct answer: It sets the lowest data rate at which the AP will transmit, helping exclude distant or weak clients
Setting a minimum bitrate excludes clients at very low data rates from the cell, which reduces airtime consumption by legacy or distant devices.
Question 5: Which Meraki MS feature allows Power over Ethernet (PoE) budgets to be monitored and managed per port from the dashboard?
- PoE is not manageable on Meraki switches
- PoE scheduling and per-port power monitoring (Correct answer)
- Manual PoE toggle via SNMP
- LLDP-MED negotiation only
Correct answer: PoE scheduling and per-port power monitoring
Meraki MS dashboard provides per-port PoE power consumption monitoring and allows administrators to enable/disable PoE and schedule power cycling on individual ports.
Question 6: How are VLANs configured on Meraki MS switch ports in the dashboard?
- As access or trunk ports with VLAN IDs defined in the Switch > Configure > Switch ports section (Correct answer)
- Via SNMP push from the NMS
- Only through the local console CLI
- Using LLDP neighbor discovery to auto-assign VLANs
Correct answer: As access or trunk ports with VLAN IDs defined in the Switch > Configure > Switch ports section
VLAN configuration on Meraki MS switches is done through the dashboard under Switch > Configure > Switch ports, where each port can be set to access or trunk mode with specific VLANs.
Question 7: What happens to a device's network access when it violates a Systems Manager compliance policy and SM Sentry is configured on the associated MR SSID?
- The device is immediately wiped remotely to prevent data leakage
- The administrator receives an email alert but no automatic enforcement action is taken
- The device is disassociated from the corporate SSID or moved to a restricted SSID until compliance is restored (Correct answer)
- The device's VPN certificate is revoked and the MX blocks all VPN traffic from that device
Correct answer: The device is disassociated from the corporate SSID or moved to a restricted SSID until compliance is restored
With SM Sentry enforcement, a non-compliant device is automatically disassociated from the corporate SSID or quarantined to a restricted SSID, preventing access to corporate resources until the compliance issue is resolved.
Question 8: In Meraki SD-WAN design, what is 'WAN load balancing' and how does it differ from failover?
- Load balancing uses BGP to distribute traffic; failover uses STP
- Load balancing and failover are identical features with different names
- Load balancing requires a third-party appliance in addition to the MX
- Load balancing distributes active traffic across both WAN links simultaneously, while failover only uses the secondary link when the primary fails (Correct answer)
Correct answer: Load balancing distributes active traffic across both WAN links simultaneously, while failover only uses the secondary link when the primary fails
WAN load balancing actively distributes flow-level traffic across both uplinks to maximize available bandwidth, while failover keeps the secondary link idle until the primary fails.
Question 9: In Meraki switching, what is the purpose of configuring a 'Native VLAN' on a trunk port?
- It assigns the highest STP priority to the native VLAN
- It prevents the native VLAN from being pruned from the trunk
- It defines the VLAN that carries untagged frames received or sent on the trunk link (Correct answer)
- It is the VLAN used for switch management traffic only
Correct answer: It defines the VLAN that carries untagged frames received or sent on the trunk link
The native VLAN on a trunk port carries untagged Ethernet frames; frames received without a VLAN tag are placed into the native VLAN, and frames sent on the native VLAN are transmitted untagged.
Question 10: What is the maximum number of WAN uplinks supported on Meraki MX appliances for SD-WAN link bonding?
- 2 (Correct answer)
- 4
- 8
- 1
Correct answer: 2
Meraki MX appliances support up to two WAN uplinks for active-active load balancing or active-passive failover.
Question 11: What is the maximum number of SSIDs that can be configured per Meraki MR access point?
- 15 (Correct answer)
- 4
- 8
- 32
Correct answer: 15
Meraki MR access points support up to 15 SSIDs per AP, though best practice recommends limiting active SSIDs to reduce overhead.
Question 12: Which MX deployment mode places the appliance in the path of all traffic as the primary gateway?
- Routed mode (Correct answer)
- VPN concentrator mode
- Tap mode
- Passthrough mode
Correct answer: Routed mode
In routed mode, the MX acts as the default gateway and all traffic flows through it for inspection and policy enforcement.
Question 13: How does Meraki Systems Manager integrate with Meraki MX appliances to provide VPN access for enrolled devices?
- SM provisions an SD-WAN policy that routes device traffic through the Meraki cloud before reaching the MX
- SM pushes a Client VPN profile with MX credentials to enrolled devices, enabling automatic IKEv2 or L2TP/IPsec VPN connection (Correct answer)
- SM installs a proprietary Meraki VPN agent on the device that uses proprietary encryption to the MX
- SM configures a site-to-site AutoVPN tunnel between the device and the nearest MX using BGP routing
Correct answer: SM pushes a Client VPN profile with MX credentials to enrolled devices, enabling automatic IKEv2 or L2TP/IPsec VPN connection
Systems Manager can push a Client VPN profile to enrolled devices containing the MX's Client VPN hostname, pre-shared key or certificate, and user credentials, enabling automatic and seamless VPN establishment.
Question 14: When designing a Meraki network for 500 branch sites, what architectural approach does Cisco recommend for efficient management?
- Create one network per device for maximum isolation
- Manually configure each branch via CLI backup scripts
- Deploy a separate on-premises controller for branches
- Use a template network (configuration template) applied to all branch networks (Correct answer)
Correct answer: Use a template network (configuration template) applied to all branch networks
Meraki configuration templates allow administrators to define a master configuration applied to multiple branch networks, ensuring consistency and dramatically simplifying large-scale deployments.
Question 15: What does the Meraki 'Cable Test' Live Tool on an MS switch port help diagnose?
- Physical cable faults such as opens, shorts, and impedance mismatches using TDR technology (Correct answer)
- Duplex negotiation issues between devices
- PoE power delivery faults
- VLAN misconfiguration on the cable pair
Correct answer: Physical cable faults such as opens, shorts, and impedance mismatches using TDR technology
The Cable Test tool uses Time Domain Reflectometry (TDR) to detect and locate physical cable faults, providing fault type and estimated distance to the fault.
Question 16: What is the primary function of Cisco Meraki Systems Manager (SM) in a Meraki deployment?
- To aggregate Netflow data from switches and generate bandwidth reports for all connected devices
- To act as a Layer 3 gateway for routing traffic between VLANs across the campus network
- To manage firmware upgrades for all Meraki hardware appliances in the organization
- To provide centralized MDM/EMM capabilities for managing and securing enrolled endpoints from the Meraki dashboard (Correct answer)
Correct answer: To provide centralized MDM/EMM capabilities for managing and securing enrolled endpoints from the Meraki dashboard
Systems Manager is Meraki's cloud-based MDM/EMM solution that allows administrators to enroll, configure, monitor, and secure endpoints from the centralized Meraki dashboard.
Question 17: What does the Meraki dashboard's 'Wireless Health' feature provide?
- RF spectrum analysis graphs per AP radio
- Real-time packet capture from APs
- Individual client signal strength history
- Aggregated metrics on association failures, DHCP failures, and DNS failures across the wireless network (Correct answer)
Correct answer: Aggregated metrics on association failures, DHCP failures, and DNS failures across the wireless network
Wireless Health aggregates data across all APs to identify systemic issues like high association failure rates, DHCP timeouts, and DNS resolution problems.
Question 18: How does Systems Manager distribute managed apps to enrolled iOS devices?
- By hosting an internal app repository that devices download apps from using HTTPS
- By sideloading IPA files directly to devices over the local network via Apple Configurator
- By pushing App Store apps using Apple Volume Purchase Program (VPP) / Apple Business Manager licenses managed in SM (Correct answer)
- By using MDX wrapping technology to repackage and sign App Store apps for enterprise distribution
Correct answer: By pushing App Store apps using Apple Volume Purchase Program (VPP) / Apple Business Manager licenses managed in SM
Systems Manager integrates with Apple Volume Purchase Program (now part of Apple Business Manager) to silently push licensed App Store apps to enrolled iOS devices without requiring end-user Apple IDs.
Question 19: Which Meraki tool provides a real-time view of spectrum utilization and interference sources on wireless radio channels?
- RF profile interference graph
- Wireless spectrum analysis from compatible MR APs (Correct answer)
- Client association heatmap
- Air Marshal rogue detection
Correct answer: Wireless spectrum analysis from compatible MR APs
Certain Meraki MR access points support spectrum analysis mode, which scans radio channels and displays interference sources, channel utilization, and noise floor in real time.
Question 20: What Meraki alerting feature automatically notifies administrators when a device goes offline?
- Manual monitoring via dashboard refresh only
- Syslog messages only
- SNMP traps sent to a configured NMS
- Email and SMS alerts configured under Network > Alerts (Correct answer)
Correct answer: Email and SMS alerts configured under Network > Alerts
Meraki allows administrators to configure email and webhook alerts for events including device offline, WAN failover, and client connection issues under Network > Alerts.
Question 21: Which of the following devices is part of Cisco Meraki’s wireless portfolio?
- Meraki MS
- Meraki MV
- Meraki MX
- Meraki MR (Correct answer)
Correct answer: Meraki MR
The Meraki MR series specifically refers to Cisco Meraki's line of cloud-managed wireless access points. These devices are designed to provide secure and scalable Wi-Fi connectivity, offering features like guest access, traffic shaping, and RF optimization, all managed from the Meraki dashboard.
Question 22: An administrator wants to ensure that only SM-enrolled and compliant devices can connect to a corporate SSID on a Meraki MR. Which feature should be configured?
- MAC address allow-listing on the MR SSID
- WPA2-PSK with a complex shared key distributed only to enrolled devices
- Systems Manager Sentry with the SSID set to 'SM Sentry' association requirement (Correct answer)
- Captive portal with Active Directory authentication
Correct answer: Systems Manager Sentry with the SSID set to 'SM Sentry' association requirement
Configuring the MR SSID association type as 'SM Sentry' enforces that only devices with a valid SM enrollment and passing compliance checks can associate to that SSID.
Question 23: What Meraki MR capability provides seamless wireless roaming by allowing APs to coordinate client handoffs using 802.11r?
- Load balancing
- Fast BSS Transition (FT) / 802.11r (Correct answer)
- Band steering
- Air Marshal
Correct answer: Fast BSS Transition (FT) / 802.11r
Meraki supports 802.11r Fast BSS Transition, which reduces roaming latency by pre-establishing security keys before a client completes the handoff to a new AP.
Question 24: An organization wants to support BYOD by allowing personal devices to access email but preventing those devices from accessing the internal corporate file shares. Which SM feature supports this scenario?
- Selective wipe combined with per-app VPN to limit corporate app access without managing the entire device (Correct answer)
- Mandatory full MDM enrollment with all management profiles applied identically to BYOD and corporate devices
- Full device wipe policy scoped to BYOD-tagged devices
- MAC address filtering on the MX to block personal devices from specific subnets
Correct answer: Selective wipe combined with per-app VPN to limit corporate app access without managing the entire device
Selective wipe removes only managed corporate data/apps from the device while leaving personal data intact, and per-app VPN can restrict which apps can reach internal resources, making it ideal for BYOD scenarios.
Question 25: Which enrollment method leverages Apple Business Manager (ABM) for zero-touch iOS device provisioning in Meraki Systems Manager?
- Automated Device Enrollment (ADE) via Apple Business Manager integration (Correct answer)
- Manual profile installation using Apple Configurator 2
- Over-the-Air (OTA) enrollment via an enrollment URL
- LDAP-based enrollment using corporate Active Directory credentials
Correct answer: Automated Device Enrollment (ADE) via Apple Business Manager integration
Automated Device Enrollment (ADE), formerly known as DEP, integrates with Apple Business Manager so that devices are automatically enrolled into Systems Manager during initial setup without user intervention.
Question 26: Which authentication method on a Meraki SSID integrates with an enterprise RADIUS server for user-based access control?
- Meraki authentication only
- WPA2-Personal (PSK)
- WPA2-Enterprise (802.1X) (Correct answer)
- Open with MAC filtering
Correct answer: WPA2-Enterprise (802.1X)
WPA2-Enterprise with 802.1X authentication passes credentials to a RADIUS server, enabling per-user or per-device access policies and dynamic VLAN assignment.
Question 27: What Meraki MS capability provides automatic VLAN assignment based on 802.1X authentication results from a RADIUS server?
- Static VLAN configuration
- LLDP-based VLAN negotiation
- Auto-trunk VLAN learning
- Dynamic VLAN assignment via RADIUS attributes (Correct answer)
Correct answer: Dynamic VLAN assignment via RADIUS attributes
When 802.1X authentication succeeds, the RADIUS server can return a VLAN ID attribute that Meraki MS uses to dynamically place the port into the appropriate VLAN.
Question 28: Which of the following can be retrieved through the Cisco Meraki API?
- Physical configurations of network cabling.
- Hardware schematics for Meraki devices.
- Weather information for Meraki-managed locations.
- Network health metrics, device status, and client usage statistics. (Correct answer)
Correct answer: Network health metrics, device status, and client usage statistics.
The Cisco Meraki API provides extensive capabilities for retrieving detailed network data. This includes real-time network health metrics, the operational status of individual devices, and comprehensive client usage statistics, which are invaluable for monitoring, reporting, and capacity planning.
Question 29: What is the purpose of Meraki 'Network Tags' when applied to networks in an organization?
- They define routing policies between tagged networks
- They assign Meraki cloud region for data residency purposes
- They control which VLANs are allowed on trunk ports
- They group networks for bulk operations, reporting, and configuration template binding (Correct answer)
Correct answer: They group networks for bulk operations, reporting, and configuration template binding
Network tags in Meraki allow administrators to logically group networks, enabling bulk firmware upgrades, alert configuration, API filtering, and template assignment for networks sharing common attributes.
Question 30: When deploying Meraki devices at a site without a local IT administrator, what feature ensures the devices automatically connect and receive configuration without manual setup?
- USB configuration file import
- Zero-Touch Provisioning (ZTP) via Meraki cloud (Correct answer)
- Manual staging by Meraki TAC
- TFTP-based configuration bootstrap
Correct answer: Zero-Touch Provisioning (ZTP) via Meraki cloud
Meraki's Zero-Touch Provisioning allows devices to be shipped directly to a site where they automatically connect to the cloud using pre-claimed licensing and receive their full configuration.
Question 31: When an organization has both Meraki and non-Meraki devices, how can site-to-site VPN be established with the non-Meraki side?
- Non-Meraki VPN is not supported on MX appliances
- Only through a Cisco ISR router as intermediary
- Using Non-Meraki VPN peers configured with IKEv1/IKEv2 and PSK or certificate authentication under Site-to-site VPN settings (Correct answer)
- By upgrading the non-Meraki device to Meraki firmware
Correct answer: Using Non-Meraki VPN peers configured with IKEv1/IKEv2 and PSK or certificate authentication under Site-to-site VPN settings
Meraki MX supports Non-Meraki VPN peer configuration using standard IKEv1/IKEv2 IPsec with pre-shared keys, enabling interoperability with third-party firewalls and routers.
Question 32: What is the purpose of creating a 'Switch Virtual Interface (SVI)' on a Meraki MS Layer 3 switch?
- It creates a virtual AP for wireless clients on the switch
- It mirrors all traffic from a VLAN to a monitoring tool
- It defines a dedicated management VLAN separate from all other VLANs
- It provides a Layer 3 IP interface for a VLAN, enabling inter-VLAN routing on the switch itself (Correct answer)
Correct answer: It provides a Layer 3 IP interface for a VLAN, enabling inter-VLAN routing on the switch itself
An SVI is a logical IP interface assigned to a VLAN that allows the switch to route traffic between VLANs and serve as the default gateway for hosts in that VLAN.
Question 33: What is the benefit of enabling 'NAT traversal' (NAT-T) in Meraki Auto VPN configurations?
- It automatically configures port forwarding on upstream routers
- It allows VPN tunnels to be established even when one or both MX appliances are behind a NAT device (Correct answer)
- It eliminates the need for NAT on WAN interfaces
- It provides additional encryption for VPN traffic behind NAT
Correct answer: It allows VPN tunnels to be established even when one or both MX appliances are behind a NAT device
NAT traversal encapsulates IPsec traffic in UDP port 4500, allowing VPN tunnels to pass through NAT devices that would otherwise block ESP protocol packets.
Question 34: Which Meraki MS feature helps identify connected device types (IP phones, APs, cameras) automatically by reading LLDP/CDP neighbor data?
- LLDP/CDP neighbor discovery displayed in the dashboard (Correct answer)
- Auto device discovery via nmap
- MAC OUI lookup only
- Meraki Systems Manager device enrollment
Correct answer: LLDP/CDP neighbor discovery displayed in the dashboard
Meraki MS switches collect LLDP and CDP neighbor information from connected devices and display device type, hostname, and capabilities in the dashboard port detail view.
Question 35: How are devices typically organized within the Meraki Systems Manager dashboard to enable targeted profile and policy deployment?
- By enrolling devices into specific subnets that automatically inherit predefined configurations
- By using tags to group devices, which are then used as scope selectors for profiles and policies (Correct answer)
- By creating separate Meraki networks for each device category and applying network-level settings
- By assigning devices to VLANs that correspond to different policy groups
Correct answer: By using tags to group devices, which are then used as scope selectors for profiles and policies
Systems Manager uses tags as the primary mechanism for organizing devices into logical groups; profiles, apps, and policies are then scoped to specific tags to control which devices receive which configurations.
Question 36: How does Cisco Meraki simplify the process of deploying new devices in the network?
- By requiring an on-site engineer for device setup.
- By using local storage for configuration settings.
- By requiring manual firmware upgrades for each device.
- By using zero-touch provisioning to automatically download configurations from the cloud. (Correct answer)
Correct answer: By using zero-touch provisioning to automatically download configurations from the cloud.
Cisco Meraki simplifies device deployment through zero-touch provisioning. New devices can be shipped directly to a site, powered on, and automatically connect to the Meraki cloud to download their pre-configured settings. This eliminates the need for manual on-site configuration, drastically speeding up deployment and reducing operational costs.
Question 37: When configuring site-to-site VPN on a Meraki MX, which encryption standard is used by default for Auto VPN tunnels?
- AES-128 with SHA-256
- AES-256 with SHA-256 (Correct answer)
- DES with MD5
- 3DES with SHA-1
Correct answer: AES-256 with SHA-256
Meraki Auto VPN tunnels use AES-256 encryption with SHA-256 authentication by default, providing strong security for inter-site communications.
Question 38: Which Meraki dashboard feature provides a topology view showing how MS switches are interconnected with other Meraki devices?
- Monitor > Topology (Correct answer)
- Network > Alerts
- Switch > Port schedule
- Organization > Inventory
Correct answer: Monitor > Topology
The Meraki Monitor > Topology view automatically discovers and displays the physical connections between Meraki switches, APs, and MX appliances using LLDP data.
Question 39: Which Meraki network health feature provides a single score summarizing the overall wireless performance experience for clients?
- Wireless Health Score (Correct answer)
- Client satisfaction (CSAT) rating
- Uplink health score
- Network availability percentage
Correct answer: Wireless Health Score
Meraki Wireless Health calculates a health score based on association failures, DHCP failures, and DNS failures, giving a quick overall picture of wireless client experience.
Question 40: What is the primary Meraki SD-WAN feature that allows administrators to define preferred WAN paths for specific applications based on performance?
- WAN load balancing
- Static default route with metric
- SD-WAN policies with performance classes (Correct answer)
- PBR using ACLs
Correct answer: SD-WAN policies with performance classes
Meraki SD-WAN performance classes allow administrators to define latency, jitter, and loss thresholds and automatically route specific application traffic to the best-performing WAN link.
Question 41: What Meraki feature allows an administrator to remotely capture packets on a specific MS switch port for troubleshooting?
- SNMP trap analysis
- Meraki dashboard packet capture tool (Correct answer)
- Remote CLI via SSH
- SPAN port mirroring to a PCAP server
Correct answer: Meraki dashboard packet capture tool
The Meraki dashboard includes a built-in packet capture tool that can capture live traffic from switch ports or wireless interfaces and download the PCAP file for analysis.
Question 42: What is a key design consideration when implementing Meraki Auto VPN with multiple hub sites for redundancy?
- Each spoke can only connect to one hub at a time
- Hub redundancy is only supported with the Advanced Security license
- Multiple hubs require manual BGP peering configuration
- Spokes can be configured with primary and secondary hubs; if the primary hub becomes unreachable, traffic fails over to the secondary (Correct answer)
Correct answer: Spokes can be configured with primary and secondary hubs; if the primary hub becomes unreachable, traffic fails over to the secondary
Meraki Auto VPN supports primary and secondary hub designation per spoke, allowing automatic VPN failover to the secondary hub if the primary becomes unavailable.
Question 43: What is the purpose of configuring outbound firewall rules on a Meraki MX appliance?
- To define VPN split tunneling rules
- To prioritize traffic for QoS marking
- To block inbound traffic from reaching LAN hosts
- To control traffic leaving the local network toward the internet or WAN (Correct answer)
Correct answer: To control traffic leaving the local network toward the internet or WAN
Outbound firewall rules on the MX control which local clients can communicate with which external destinations, based on source, destination, and protocol.
Question 44: Which Meraki product provides cloud-managed Layer 2 and Layer 3 switching capabilities?
- Meraki MS (Correct answer)
- Meraki MV
- Meraki MX
- Meraki MR
Correct answer: Meraki MS
The Meraki MS series represents Cisco Meraki's line of cloud-managed switches. These devices offer both Layer 2 and Layer 3 switching capabilities, providing robust and scalable network connectivity with simplified management through the Meraki dashboard. They enable centralized control over port configurations, VLANs, and QoS settings.
Question 45: What Meraki MX Live Tool helps verify whether a specific remote host is reachable and measures round-trip time?
- DNS lookup
- ARP cache flush
- Ping from appliance (Correct answer)
- Traceroute only
Correct answer: Ping from appliance
The Ping from appliance Live Tool sends ICMP echo requests from the MX to a specified host, confirming reachability and measuring latency directly from the appliance.
Question 46: What is the primary function of the Cisco Meraki MX series?
- Wireless access points for secure Wi-Fi networks.
- Network video cameras for physical security.
- Cloud-managed Layer 3 switches.
- Security and SD-WAN appliances with firewall, VPN, and content filtering features. (Correct answer)
Correct answer: Security and SD-WAN appliances with firewall, VPN, and content filtering features.
The Cisco Meraki MX series consists of cloud-managed security and SD-WAN appliances. Their primary function is to provide comprehensive network security, including firewall capabilities, VPN connectivity, content filtering, and traffic shaping, making them ideal for securing branch offices and distributed environments.
Question 47: What is Meraki Systems Manager Sentry, and what is its primary purpose?
- A dedicated hardware appliance that provides intrusion prevention for enrolled mobile devices
- A cloud-based SIEM platform that aggregates security events from all SM-enrolled endpoints
- A feature that integrates SM with Meraki MR and MX to enforce network access control based on device compliance status (Correct answer)
- A vulnerability scanner that periodically scans enrolled devices for known CVEs
Correct answer: A feature that integrates SM with Meraki MR and MX to enforce network access control based on device compliance status
SM Sentry integrates Systems Manager with Meraki MR access points and MX appliances to enforce network access control (NAC), allowing only compliant and enrolled devices to connect to protected SSIDs or VPN tunnels.
Question 48: Which of the following is NOT included with a Cisco Meraki license?
- Ongoing software and firmware updates.
- Replacement hardware for devices in case of failure. (Correct answer)
- Access to Meraki's cloud-based management dashboard.
- 24/7 technical support.
Correct answer: Replacement hardware for devices in case of failure.
A Cisco Meraki license includes access to the cloud-based management dashboard, ongoing software and firmware updates, and 24/7 technical support. However, replacement hardware for devices in case of failure is covered by the hardware warranty, which is a separate entitlement from the software license itself.
Question 49: Which Systems Manager profile payload type is used to push corporate email account settings automatically to enrolled mobile devices?
- VPN payload
- Network payload
- Exchange ActiveSync (EAS) or email payload (Correct answer)
- Certificate payload
Correct answer: Exchange ActiveSync (EAS) or email payload
The Exchange ActiveSync or email payload in a Systems Manager profile automatically configures corporate email accounts on enrolled devices, eliminating the need for users to manually enter server details.
Question 50: When sizing a Meraki MX for a branch deployment, what throughput specification should be the primary consideration?
- Stateful firewall throughput matching expected WAN bandwidth plus headroom for growth (Correct answer)
- Maximum number of Meraki cloud API calls per second
- Number of VLANs supported
- Number of SSIDs the MX can broadcast
Correct answer: Stateful firewall throughput matching expected WAN bandwidth plus headroom for growth
The MX stateful firewall throughput rating should match or exceed the site's WAN link capacity, with additional headroom to account for traffic growth and inspection overhead.
Question 51: What is a key advantage of using webhooks with the cisco Meraki platform?
- Webhooks are used only for historical reporting.
- Webhooks require constant manual input to work properly.
- Webhooks replace the need for the Meraki API entirely.
- Webhooks provide real-time alerts and automate responses to specific network events. (Correct answer)
Correct answer: Webhooks provide real-time alerts and automate responses to specific network events.
Webhooks are a key advantage for real-time network management with the Cisco Meraki platform. They allow the Meraki cloud to send immediate, automated alerts to external systems when specific network events occur, enabling real-time monitoring and triggering automated responses or actions based on these events.
Question 52: When deploying Meraki Systems Manager in an environment with both iOS and Windows endpoints, which enrollment approach is supported for Windows devices?
- Windows devices are enrolled using the SM Windows agent installer, which can be deployed via GPO, Intune, or manual install (Correct answer)
- Windows devices are managed exclusively via SNMP polling from the SM cloud and do not require an agent
- Windows devices can only be enrolled via Group Policy pushing a custom SM ADMX template
- Windows enrollment requires installing the SM iOS companion app on a paired iPhone to proxy device management commands
Correct answer: Windows devices are enrolled using the SM Windows agent installer, which can be deployed via GPO, Intune, or manual install
Windows devices are enrolled by installing the Meraki SM Windows agent, which can be deployed via Group Policy (GPO), Microsoft Intune, SCCM, or manually, after which the device appears in the SM dashboard for management.
Question 53: Which Meraki MR feature allows the deployment of access points in outdoor or remote environments using a cellular uplink?
- Meraki MR Outdoor AP with cellular gateway pairing
- MX passthrough mode with LTE
- Meraki MG cellular gateway connected to an MR AP (Correct answer)
- Auto VPN over LTE
Correct answer: Meraki MG cellular gateway connected to an MR AP
Meraki MG cellular gateways provide WAN connectivity via 4G/5G LTE, and can be paired with Meraki MR access points to deliver Wi-Fi in locations without wired internet.
Question 54: In the Meraki dashboard, where can administrators view a history of configuration changes made to the network?
- Network > Event Log
- Help > Diagnostics
- Organization > Change Log (Correct answer)
- Monitor > Summary
Correct answer: Organization > Change Log
The Organization > Change Log records all configuration changes including who made the change, when, and what was modified, providing a complete audit trail.
Question 55: When configuring Meraki MX in One-Armed Concentrator mode, where is it typically deployed?
- At the data center to terminate VPN tunnels without being inline (Correct answer)
- On the DMZ for public-facing services
- As a WAN edge device replacing the ISP router
- At the branch office as the primary gateway
Correct answer: At the data center to terminate VPN tunnels without being inline
One-Armed Concentrator mode is used at a data center or hub site to aggregate VPN tunnels without disrupting the existing routing infrastructure.
Question 56: What Meraki MS feature helps prevent rogue DHCP servers from distributing addresses on the network?
- DHCP relay agent configuration
- Static ARP entries
- Gratuitous ARP blocking
- DHCP snooping (Correct answer)
Correct answer: DHCP snooping
DHCP snooping on Meraki MS switches validates DHCP messages and only forwards DHCP offers/acknowledgments received on trusted (uplink) ports, blocking unauthorized DHCP servers.
Question 57: What type of VPN configuration in Systems Manager allows only traffic from specific applications to traverse the VPN tunnel on an iOS device?
- Client VPN with traffic selector ACLs
- Per-app VPN (Correct answer)
- Split-tunnel IKEv2 VPN
- Full-tunnel SSL VPN
Correct answer: Per-app VPN
Per-app VPN, configured via a Systems Manager profile payload, routes VPN traffic only for designated apps, preventing all other traffic from entering the tunnel and improving performance for BYOD scenarios.
Question 58: In a Meraki SD-WAN deployment, what is the role of the 'Hub' site in an Auto VPN topology?
- It serves as a central aggregation point that spoke sites connect to for VPN and shared resource access (Correct answer)
- It performs deep packet inspection on behalf of spoke devices
- It provides internet breakout for all spoke sites
- It manages firmware updates for all spoke devices
Correct answer: It serves as a central aggregation point that spoke sites connect to for VPN and shared resource access
The Hub site in Meraki Auto VPN serves as the central termination point for spoke-to-hub VPN tunnels, enabling spokes to access data center resources and shared services through the hub.
Question 59: Which of the following is a benefit of Cisco Meraki's automatic firmware updates?
- The system applies firmware updated to all devices without administrator intervention, ensuring devices stay secure and up-to-date. (Correct answer)
- Devices remain outdated unless manually updated.
- Firmware updates must be applied manually to maintain network stability
- Only specific devices receive updates, requiring manual updates for others.
Correct answer: The system applies firmware updated to all devices without administrator intervention, ensuring devices stay secure and up-to-date.
Cisco Meraki's automatic firmware updates ensure that all network devices consistently run the latest software versions. This process is managed seamlessly by the cloud, reducing administrative burden and enhancing network security by promptly applying patches and new features without requiring manual intervention from IT staff.
Question 60: What Meraki feature enables branch sites to send internet-bound traffic directly to the internet rather than backhauling it through a hub data center?
- Internet traffic is always sent to the hub in Meraki
- Content filtering must be disabled for local breakout
- MPLS replacement with dedicated VPN for internet traffic
- Local internet breakout configured via SD-WAN traffic policies (Correct answer)
Correct answer: Local internet breakout configured via SD-WAN traffic policies
Meraki SD-WAN supports local internet breakout by configuring SD-WAN policies to route internet traffic directly out of the local WAN interface rather than through the Auto VPN tunnel to the hub.
Question 61: How are security threat intelligence updates delivered to Meraki MX appliances?
- Automatically via the Meraki cloud without requiring firmware upgrades (Correct answer)
- Manual firmware updates downloaded by the administrator
- Through a local threat intelligence server on-premises
- Only during scheduled maintenance windows
Correct answer: Automatically via the Meraki cloud without requiring firmware upgrades
Meraki delivers IPS signatures, AMP definitions, and URL category updates automatically through the cloud, independent of firmware version.
Engineering Cisco Meraki Solutions (ECMS) 500-220
The ECMS exam (500-220) validates skills in designing, implementing, operating, and troubleshooting Cisco Meraki cloud-managed networking solutions including MR wireless access points, MS switching, MX security appliances, and SD-WAN deployments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds