Engineering Cisco Meraki Solutions (ECMS) 500-220 — Questions and Answers
Question 1: When a Meraki MS switch loses connectivity to the Meraki cloud, what happens to its switching and routing functions?
- It reverts to factory default settings automatically
- All ports shut down until cloud connectivity is restored
- It continues forwarding traffic using its last known configuration (Correct answer)
- It sends an alert and waits for admin confirmation before continuing
Correct answer: It continues forwarding traffic using its last known configuration
Meraki devices are designed with local intelligence; they store their configuration locally and continue to operate normally even when cloud connectivity is temporarily unavailable.
Question 2: Which Meraki MS feature provides port-level security by restricting which MAC addresses are allowed to communicate through a switch port?
- Port security with MAC address limiting (Correct answer)
- VLAN access control lists
- 802.1X port authentication
- Dynamic ARP Inspection
Correct answer: Port security with MAC address limiting
Meraki port security allows administrators to limit the number of MAC addresses on a port or specify allowed MACs, helping prevent unauthorized devices from connecting.
Question 3: In a Meraki deployment, what is the significance of placing the Meraki dashboard in 'Monitor Only' mode for a network?
- The network devices lose connectivity to the cloud
- Device traffic is limited to monitoring protocols like SNMP
- Administrators can view the network but cannot make configuration changes until the mode is changed (Correct answer)
- The network stops generating Event Log entries
Correct answer: Administrators can view the network but cannot make configuration changes until the mode is changed
Monitor Only mode is a role-based access restriction that allows read-only dashboard access, preventing configuration changes while still enabling visibility and troubleshooting.
Question 4: What technology does Meraki MR use to provide location analytics for Wi-Fi clients including dwell time and foot traffic?
- Bluetooth Low Energy beacons only
- GPS-based positioning
- Meraki Location Analytics using probe request data (Correct answer)
- RFID tag readers
Correct answer: Meraki Location Analytics using probe request data
Meraki Location Analytics uses Wi-Fi probe request frames from nearby devices to estimate location, calculate dwell time, and analyze foot traffic patterns.
Question 5: In the Meraki dashboard, what does a 'Dormant' client status indicate?
- The client was recently associated but has not sent traffic for a defined idle period (Correct answer)
- The client failed 802.1X authentication
- The client's port is administratively disabled
- The client is actively transmitting data at low speed
Correct answer: The client was recently associated but has not sent traffic for a defined idle period
A 'Dormant' status in Meraki indicates a client that has been seen recently (within the last 30 days by default) but is not currently active or transmitting.
Question 6: What is the primary function of the Cisco Meraki MX series?
- Security and SD-WAN appliances with firewall, VPN, and content filtering features. (Correct answer)
- Cloud-managed Layer 3 switches.
- Network video cameras for physical security.
- Wireless access points for secure Wi-Fi networks.
Correct answer: Security and SD-WAN appliances with firewall, VPN, and content filtering features.
The Cisco Meraki MX series consists of cloud-managed security and SD-WAN appliances. Their primary function is to provide comprehensive network security, including firewall capabilities, VPN connectivity, content filtering, and traffic shaping, making them ideal for securing branch offices and distributed environments.
Question 7: How does Systems Manager Sentry WiFi integration work with Meraki MR access points?
- MR access points query SM via API to verify device enrollment before issuing a DHCP lease
- SM configures 802.1X supplicant profiles on enrolled devices; the MR then enforces client isolation for non-SM devices
- SM pushes Wi-Fi credentials to enrolled devices; if a device is non-compliant, it is automatically moved to a restricted SSID via the MR (Correct answer)
- SM acts as the RADIUS server for all MR access points, authenticating devices based on their MAC addresses
Correct answer: SM pushes Wi-Fi credentials to enrolled devices; if a device is non-compliant, it is automatically moved to a restricted SSID via the MR
Sentry WiFi pushes SSID profiles and credentials to SM-enrolled devices; additionally, if a device loses compliance, SM can instruct the MR to move the device to a restricted SSID, effectively enforcing NAC.
Question 8: What is a key design consideration when implementing Meraki Auto VPN with multiple hub sites for redundancy?
- Hub redundancy is only supported with the Advanced Security license
- Each spoke can only connect to one hub at a time
- Spokes can be configured with primary and secondary hubs; if the primary hub becomes unreachable, traffic fails over to the secondary (Correct answer)
- Multiple hubs require manual BGP peering configuration
Correct answer: Spokes can be configured with primary and secondary hubs; if the primary hub becomes unreachable, traffic fails over to the secondary
Meraki Auto VPN supports primary and secondary hub designation per spoke, allowing automatic VPN failover to the secondary hub if the primary becomes unavailable.
Question 9: Which Meraki dashboard tool allows administrators to trace the network path a packet takes from one client to another across Meraki devices?
- Live Tools > Ping / Traceroute (Correct answer)
- Network topology
- Packet capture
- Event Log search
Correct answer: Live Tools > Ping / Traceroute
Meraki Live Tools includes ping and traceroute capabilities that can be run directly from the dashboard, allowing path tracing without needing CLI access to individual devices.
Question 10: In Meraki SD-WAN design, what is 'WAN load balancing' and how does it differ from failover?
- Load balancing distributes active traffic across both WAN links simultaneously, while failover only uses the secondary link when the primary fails (Correct answer)
- Load balancing requires a third-party appliance in addition to the MX
- Load balancing uses BGP to distribute traffic; failover uses STP
- Load balancing and failover are identical features with different names
Correct answer: Load balancing distributes active traffic across both WAN links simultaneously, while failover only uses the secondary link when the primary fails
WAN load balancing actively distributes flow-level traffic across both uplinks to maximize available bandwidth, while failover keeps the secondary link idle until the primary fails.
Question 11: Which Meraki product provides cloud-managed Layer 2 and Layer 3 switching capabilities?
- Meraki MV
- Meraki MS (Correct answer)
- Meraki MX
- Meraki MR
Correct answer: Meraki MS
The Meraki MS series represents Cisco Meraki's line of cloud-managed switches. These devices offer both Layer 2 and Layer 3 switching capabilities, providing robust and scalable network connectivity with simplified management through the Meraki dashboard. They enable centralized control over port configurations, VLANs, and QoS settings.
Question 12: Which protocol does Meraki Systems Manager use to distribute certificates to enrolled endpoints for Wi-Fi or VPN authentication?
- RADIUS
- LDAP
- SCEP (Simple Certificate Enrollment Protocol) (Correct answer)
- OCSP (Online Certificate Status Protocol)
Correct answer: SCEP (Simple Certificate Enrollment Protocol)
Systems Manager uses SCEP to automatically request and distribute digital certificates to enrolled devices, enabling certificate-based authentication for Wi-Fi (WPA2-Enterprise) and VPN connections.
Question 13: What is the purpose of configuration templates in Cisco Meraki's API?
- To apply the same network settings manually to each device.
- To standardize and apply a common set of configurations across multiple networks and devices automatically. (Correct answer)
- To provide no use case for large networks.
- To disable automation capabilities within the network.
Correct answer: To standardize and apply a common set of configurations across multiple networks and devices automatically.
Configuration templates in Cisco Meraki's API are designed to standardize and automatically apply a common set of network settings across multiple networks and devices. This ensures consistency, reduces configuration errors, and significantly speeds up the deployment and management of large-scale or multi-site networks.
Question 14: What is one of the primary advantages of Cisco Meraki's cloud-based architecture?
- The need for a physical controller at every site.
- Only works with Cisco hardware.
- Centralized management of network devices via the Meraki dashboard. (Correct answer)
- Manual configuration required for each device at the site.
Correct answer: Centralized management of network devices via the Meraki dashboard.
Cisco Meraki's cloud-based architecture offers centralized management, allowing administrators to control and monitor all network devices from a single web-based Meraki dashboard. This eliminates the need for on-site controllers and simplifies network operations across multiple locations. It provides a unified view and control point for the entire network infrastructure.
Question 15: What Meraki feature enables administrators to generate scheduled summary reports of network activity, clients, and device status?
- Summary Report emailed on a schedule from Organization > Summary Report (Correct answer)
- Manual CSV download only
- Live dashboard auto-export
- Syslog export to external server
Correct answer: Summary Report emailed on a schedule from Organization > Summary Report
Meraki's Summary Report feature generates and emails periodic reports on network usage, top clients, application traffic, and device health on a configurable schedule.
Question 16: When sizing a Meraki MX for a branch deployment, what throughput specification should be the primary consideration?
- Stateful firewall throughput matching expected WAN bandwidth plus headroom for growth (Correct answer)
- Maximum number of Meraki cloud API calls per second
- Number of VLANs supported
- Number of SSIDs the MX can broadcast
Correct answer: Stateful firewall throughput matching expected WAN bandwidth plus headroom for growth
The MX stateful firewall throughput rating should match or exceed the site's WAN link capacity, with additional headroom to account for traffic growth and inspection overhead.
Question 17: What is Meraki Systems Manager Sentry, and what is its primary purpose?
- A feature that integrates SM with Meraki MR and MX to enforce network access control based on device compliance status (Correct answer)
- A vulnerability scanner that periodically scans enrolled devices for known CVEs
- A cloud-based SIEM platform that aggregates security events from all SM-enrolled endpoints
- A dedicated hardware appliance that provides intrusion prevention for enrolled mobile devices
Correct answer: A feature that integrates SM with Meraki MR and MX to enforce network access control based on device compliance status
SM Sentry integrates Systems Manager with Meraki MR access points and MX appliances to enforce network access control (NAC), allowing only compliant and enrolled devices to connect to protected SSIDs or VPN tunnels.
Question 18: When a Meraki MR access point shows a 'Rogue AP' alert in Air Marshal, what action can an administrator take directly from the dashboard?
- Physically locate and remove the AP using GPS
- Push a firmware update to the rogue AP
- Automatically block the AP at the ISP level
- Classify the AP as 'Known' to suppress alerts, or contain it by sending de-authentication frames (Correct answer)
Correct answer: Classify the AP as 'Known' to suppress alerts, or contain it by sending de-authentication frames
Air Marshal allows administrators to classify rogue APs as 'Known' (benign neighbor) to stop alerting, or actively contain them using de-authentication frames to disrupt client connections.
Question 19: Which Meraki MR feature allows the deployment of access points in outdoor or remote environments using a cellular uplink?
- MX passthrough mode with LTE
- Meraki MR Outdoor AP with cellular gateway pairing
- Meraki MG cellular gateway connected to an MR AP (Correct answer)
- Auto VPN over LTE
Correct answer: Meraki MG cellular gateway connected to an MR AP
Meraki MG cellular gateways provide WAN connectivity via 4G/5G LTE, and can be paired with Meraki MR access points to deliver Wi-Fi in locations without wired internet.
Question 20: Which Meraki MS feature helps identify connected device types (IP phones, APs, cameras) automatically by reading LLDP/CDP neighbor data?
- MAC OUI lookup only
- Auto device discovery via nmap
- LLDP/CDP neighbor discovery displayed in the dashboard (Correct answer)
- Meraki Systems Manager device enrollment
Correct answer: LLDP/CDP neighbor discovery displayed in the dashboard
Meraki MS switches collect LLDP and CDP neighbor information from connected devices and display device type, hostname, and capabilities in the dashboard port detail view.
Question 21: What Meraki SD-WAN feature allows real-time measurement of WAN link performance using continuous active probing?
- BGP keepalive monitoring
- SNMP polling every 5 minutes
- VPN Registry health checks using ICMP and UDP probes (Correct answer)
- Manual bandwidth speed tests only
Correct answer: VPN Registry health checks using ICMP and UDP probes
Meraki SD-WAN continuously sends ICMP and UDP probes over each WAN link to the Meraki cloud servers, measuring latency, jitter, and packet loss in real time for intelligent path selection.
Question 22: Which IEEE standard does Meraki MR use for neighbor AP reporting to assist client roaming decisions?
- 802.11a
- 802.11ac
- 802.11n
- 802.11k (Correct answer)
Correct answer: 802.11k
802.11k enables APs to provide clients with a neighbor report containing nearby AP information, allowing clients to make informed roaming decisions.
Question 23: What is the benefit of enabling 'NAT traversal' (NAT-T) in Meraki Auto VPN configurations?
- It eliminates the need for NAT on WAN interfaces
- It allows VPN tunnels to be established even when one or both MX appliances are behind a NAT device (Correct answer)
- It automatically configures port forwarding on upstream routers
- It provides additional encryption for VPN traffic behind NAT
Correct answer: It allows VPN tunnels to be established even when one or both MX appliances are behind a NAT device
NAT traversal encapsulates IPsec traffic in UDP port 4500, allowing VPN tunnels to pass through NAT devices that would otherwise block ESP protocol packets.
Question 24: What is the recommended Meraki architecture for providing high-availability at a data center hub site with no single point of failure?
- Single high-powered MX with RAID storage
- Warm Spare (VRRP) with two MX appliances sharing a virtual IP (Correct answer)
- Active-active clustering of four MX appliances
- Dual ISP connections to a single MX
Correct answer: Warm Spare (VRRP) with two MX appliances sharing a virtual IP
Meraki Warm Spare uses VRRP to deploy two MX appliances where one is active and one is standby; if the active unit fails, the standby takes over the virtual IP within seconds.
Question 25: Which of the following tasks can be automated using the Cisco Meraki API?
- Setting up physical cabling between devices.
- Automatically adding devices to a network and applying configuration templates. (Correct answer)
- Requiring all users to configure devices via the CLI.
- Changing the default firmware manually.
Correct answer: Automatically adding devices to a network and applying configuration templates.
The Cisco Meraki API enables automation of various network tasks, such as automatically adding new devices to a network and applying pre-defined configuration templates. This capability streamlines large-scale deployments and ensures consistent configurations across multiple devices without manual intervention, significantly improving efficiency.
Question 26: What is the primary use of the Cisco Meraki API?
- to provide hardware support for Meraki devices.
- To automate network configurations, integrate with third-party systems, and retrieve network data programmatically. (Correct answer)
- To create new cloud-based network hardware.
- To manually configure each device through a command-line interface (CLI).
Correct answer: To automate network configurations, integrate with third-party systems, and retrieve network data programmatically.
The Cisco Meraki API (Application Programming Interface) is primarily used to automate network configurations, integrate Meraki networks with third-party systems, and programmatically retrieve network data. It allows developers and IT teams to extend Meraki's capabilities, create custom applications, and streamline operational workflows through code.
Question 27: How are VLANs configured on Meraki MS switch ports in the dashboard?
- Via SNMP push from the NMS
- Only through the local console CLI
- Using LLDP neighbor discovery to auto-assign VLANs
- As access or trunk ports with VLAN IDs defined in the Switch > Configure > Switch ports section (Correct answer)
Correct answer: As access or trunk ports with VLAN IDs defined in the Switch > Configure > Switch ports section
VLAN configuration on Meraki MS switches is done through the dashboard under Switch > Configure > Switch ports, where each port can be set to access or trunk mode with specific VLANs.
Question 28: How does Meraki MX handle failover when dual WAN uplinks are configured?
- It uses BGP to reroute traffic automatically
- Manual administrator intervention is required
- It requires a separate failover appliance
- It monitors uplink health and automatically fails over to the secondary WAN (Correct answer)
Correct answer: It monitors uplink health and automatically fails over to the secondary WAN
Meraki MX continuously monitors WAN uplink health using active/passive probing and automatically switches to the secondary uplink upon failure.
Question 29: When an organization has both Meraki and non-Meraki devices, how can site-to-site VPN be established with the non-Meraki side?
- Using Non-Meraki VPN peers configured with IKEv1/IKEv2 and PSK or certificate authentication under Site-to-site VPN settings (Correct answer)
- Only through a Cisco ISR router as intermediary
- Non-Meraki VPN is not supported on MX appliances
- By upgrading the non-Meraki device to Meraki firmware
Correct answer: Using Non-Meraki VPN peers configured with IKEv1/IKEv2 and PSK or certificate authentication under Site-to-site VPN settings
Meraki MX supports Non-Meraki VPN peer configuration using standard IKEv1/IKEv2 IPsec with pre-shared keys, enabling interoperability with third-party firewalls and routers.
Engineering Cisco Meraki Solutions (ECMS) 500-220
The ECMS exam (500-220) validates skills in designing, implementing, operating, and troubleshooting Cisco Meraki cloud-managed networking solutions including MR wireless access points, MS switching, MX security appliances, and SD-WAN deployments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds