ECMS Systems Manager and Endpoint Management 2 — Questions and Answers
Question 1: What is Meraki Systems Manager Sentry, and what is its primary purpose?
- A dedicated hardware appliance that provides intrusion prevention for enrolled mobile devices
- A feature that integrates SM with Meraki MR and MX to enforce network access control based on device compliance status (Correct answer)
- A cloud-based SIEM platform that aggregates security events from all SM-enrolled endpoints
- A vulnerability scanner that periodically scans enrolled devices for known CVEs
Correct answer: A feature that integrates SM with Meraki MR and MX to enforce network access control based on device compliance status
SM Sentry integrates Systems Manager with Meraki MR access points and MX appliances to enforce network access control (NAC), allowing only compliant and enrolled devices to connect to protected SSIDs or VPN tunnels.
Question 2: How does Systems Manager Sentry WiFi integration work with Meraki MR access points?
- SM pushes Wi-Fi credentials to enrolled devices; if a device is non-compliant, it is automatically moved to a restricted SSID via the MR (Correct answer)
- SM acts as the RADIUS server for all MR access points, authenticating devices based on their MAC addresses
- MR access points query SM via API to verify device enrollment before issuing a DHCP lease
- SM configures 802.1X supplicant profiles on enrolled devices; the MR then enforces client isolation for non-SM devices
Correct answer: SM pushes Wi-Fi credentials to enrolled devices; if a device is non-compliant, it is automatically moved to a restricted SSID via the MR
Sentry WiFi pushes SSID profiles and credentials to SM-enrolled devices; additionally, if a device loses compliance, SM can instruct the MR to move the device to a restricted SSID, effectively enforcing NAC.
Question 3: An administrator wants to ensure that only SM-enrolled and compliant devices can connect to a corporate SSID on a Meraki MR. Which feature should be configured?
- MAC address allow-listing on the MR SSID
- Systems Manager Sentry with the SSID set to 'SM Sentry' association requirement (Correct answer)
- WPA2-PSK with a complex shared key distributed only to enrolled devices
- Captive portal with Active Directory authentication
Correct answer: Systems Manager Sentry with the SSID set to 'SM Sentry' association requirement
Configuring the MR SSID association type as 'SM Sentry' enforces that only devices with a valid SM enrollment and passing compliance checks can associate to that SSID.
Question 4: What type of VPN configuration in Systems Manager allows only traffic from specific applications to traverse the VPN tunnel on an iOS device?
- Split-tunnel IKEv2 VPN
- Per-app VPN (Correct answer)
- Full-tunnel SSL VPN
- Client VPN with traffic selector ACLs
Correct answer: Per-app VPN
Per-app VPN, configured via a Systems Manager profile payload, routes VPN traffic only for designated apps, preventing all other traffic from entering the tunnel and improving performance for BYOD scenarios.
Question 5: How does Systems Manager distribute managed apps to enrolled iOS devices?
- By sideloading IPA files directly to devices over the local network via Apple Configurator
- By pushing App Store apps using Apple Volume Purchase Program (VPP) / Apple Business Manager licenses managed in SM (Correct answer)
- By hosting an internal app repository that devices download apps from using HTTPS
- By using MDX wrapping technology to repackage and sign App Store apps for enterprise distribution
Correct answer: By pushing App Store apps using Apple Volume Purchase Program (VPP) / Apple Business Manager licenses managed in SM
Systems Manager integrates with Apple Volume Purchase Program (now part of Apple Business Manager) to silently push licensed App Store apps to enrolled iOS devices without requiring end-user Apple IDs.
Question 6: Which Systems Manager profile payload type is used to push corporate email account settings automatically to enrolled mobile devices?
- Network payload
- Exchange ActiveSync (EAS) or email payload (Correct answer)
- VPN payload
- Certificate payload
Correct answer: Exchange ActiveSync (EAS) or email payload
The Exchange ActiveSync or email payload in a Systems Manager profile automatically configures corporate email accounts on enrolled devices, eliminating the need for users to manually enter server details.
Question 7: What happens to a device's network access when it violates a Systems Manager compliance policy and SM Sentry is configured on the associated MR SSID?
- The device is immediately wiped remotely to prevent data leakage
- The device is disassociated from the corporate SSID or moved to a restricted SSID until compliance is restored (Correct answer)
- The device's VPN certificate is revoked and the MX blocks all VPN traffic from that device
- The administrator receives an email alert but no automatic enforcement action is taken
Correct answer: The device is disassociated from the corporate SSID or moved to a restricted SSID until compliance is restored
With SM Sentry enforcement, a non-compliant device is automatically disassociated from the corporate SSID or quarantined to a restricted SSID, preventing access to corporate resources until the compliance issue is resolved.
What is Meraki Systems Manager Sentry, and what is its primary purpose?