500-490 Designing Cisco Enterprise Networks exam

Loading demo links...

Showing 1–3 of 5 questions

Question 1

Which two statements are true regarding CiscoISE?(Choose two.)

Select all that apply, then click Submit answer.

  • In distributed deployments, failover from primary to secondary Policy Administration Nodes happens automatically.

  • ISE can detected endpoints whose addresses have been translated via NAT.

  • In two-node standalone ISE deployments, failover must be done manually.

  • ISE supports IPv6 downloadable ACLs.

  • ISE supports up to 100 Policy Services Nodes.

  • The number of logs that ISE can retain is determined by your disk space.


Question 2

Whichtwostatements regarding CiscoSD-WANvEdge routers canmitigate DoS attacks against the infrastructure? (Choose two.)

Select all that apply, then click Submit answer.

  • The vEdge routers run on hardened Linux operating systems.

  • Only authorized controllers are allowed to communicate back to the vEdg e router after the vEdge router establishes connection with the controllers.

  • In case of direct Internet access, the only traffic allowed back is the traffic matching the state table entries on the vEdge router.

  • Open Certificate Authority and automated enrollment feature.

  • By default, all incoming traffic is denied at the transport (WAN) side interfaces.


Question 3

WhichelementoftheCiscoSD-WANarchitecturefacilitatesthefunctions ofcontroller discovery and NAT traversal?

Select an option, then click Submit answer.

  • vManage

  • vEdge

  • vBond orchestrator

  • vSmart controller