ECMS Systems Manager and Endpoint Management 1 — Questions and Answers
Question 1: What is the primary function of Cisco Meraki Systems Manager (SM) in a Meraki deployment?
- To provide centralized MDM/EMM capabilities for managing and securing enrolled endpoints from the Meraki dashboard (Correct answer)
- To act as a Layer 3 gateway for routing traffic between VLANs across the campus network
- To aggregate Netflow data from switches and generate bandwidth reports for all connected devices
- To manage firmware upgrades for all Meraki hardware appliances in the organization
Correct answer: To provide centralized MDM/EMM capabilities for managing and securing enrolled endpoints from the Meraki dashboard
Systems Manager is Meraki's cloud-based MDM/EMM solution that allows administrators to enroll, configure, monitor, and secure endpoints from the centralized Meraki dashboard.
Question 2: Which enrollment method leverages Apple Business Manager (ABM) for zero-touch iOS device provisioning in Meraki Systems Manager?
- Over-the-Air (OTA) enrollment via an enrollment URL
- Automated Device Enrollment (ADE) via Apple Business Manager integration (Correct answer)
- Manual profile installation using Apple Configurator 2
- LDAP-based enrollment using corporate Active Directory credentials
Correct answer: Automated Device Enrollment (ADE) via Apple Business Manager integration
Automated Device Enrollment (ADE), formerly known as DEP, integrates with Apple Business Manager so that devices are automatically enrolled into Systems Manager during initial setup without user intervention.
Question 3: When configuring a Systems Manager compliance policy, which check can detect whether a mobile device has been jailbroken or rooted?
- Certificate expiration check
- OS version minimum requirement check
- Jailbreak and root detection check (Correct answer)
- Application blocklist violation check
Correct answer: Jailbreak and root detection check
Systems Manager compliance policies include a jailbreak/root detection check that flags devices where the OS security model has been compromised, allowing administrators to take remediation actions.
Question 4: Which of the following is a valid remote action an administrator can perform on an enrolled device through the Meraki Systems Manager dashboard?
- Remotely upgrade the firmware of a connected Meraki MX appliance
- Remotely lock, wipe, or locate the enrolled endpoint (Correct answer)
- Remotely reconfigure the SSID settings on Meraki MR access points
- Remotely reset the BGP session on a connected upstream router
Correct answer: Remotely lock, wipe, or locate the enrolled endpoint
Systems Manager allows administrators to perform remote device actions such as lock, full wipe, selective wipe, and locate — essential for lost or stolen device management.
Question 5: How are devices typically organized within the Meraki Systems Manager dashboard to enable targeted profile and policy deployment?
- By assigning devices to VLANs that correspond to different policy groups
- By using tags to group devices, which are then used as scope selectors for profiles and policies (Correct answer)
- By creating separate Meraki networks for each device category and applying network-level settings
- By enrolling devices into specific subnets that automatically inherit predefined configurations
Correct answer: By using tags to group devices, which are then used as scope selectors for profiles and policies
Systems Manager uses tags as the primary mechanism for organizing devices into logical groups; profiles, apps, and policies are then scoped to specific tags to control which devices receive which configurations.
Question 6: Which protocol does Meraki Systems Manager use to distribute certificates to enrolled endpoints for Wi-Fi or VPN authentication?
- RADIUS
- LDAP
- SCEP (Simple Certificate Enrollment Protocol) (Correct answer)
- OCSP (Online Certificate Status Protocol)
Correct answer: SCEP (Simple Certificate Enrollment Protocol)
Systems Manager uses SCEP to automatically request and distribute digital certificates to enrolled devices, enabling certificate-based authentication for Wi-Fi (WPA2-Enterprise) and VPN connections.
Question 7: Which Systems Manager feature allows an administrator to restrict a device's access or trigger compliance actions based on the device's physical location?
- Network access control (NAC) via SM Sentry
- Geofencing policies (Correct answer)
- Lost Mode activation
- Application blocklist enforcement
Correct answer: Geofencing policies
Geofencing in Systems Manager lets administrators define geographic boundaries and trigger compliance actions (such as locking or wiping a device) when a device enters or leaves a defined area.
What is the primary function of Cisco Meraki Systems Manager (SM) in a Meraki deployment?