500-470 Sample Questions & Answers
Identity Services Engine and SD-Access tie for the top weight, each spanning discovery through design, defense and demonstration work, while SD-WAN's own discovery-to-demonstration path fills out the rest for enterprise networks.
Launch the full 500-470 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
SD-WAN Discover · Describe customer discovery (use case, buying triggers)
A retail company with 500 stores is planning an SD-WAN rollout. During the 'Discovery' phase, the IT director mentions that their primary pain point is the high cost and low bandwidth of their existing MPLS circuits. They want to leverage low-cost broadband internet but are concerned about the security of transmitting sensitive sales data. Which Cisco SD-WAN capability should a systems engineer highlight to directly address this specific concern?
Show answer & explanation
Correct answer: C
The core security concern of using public internet for sensitive data is addressed by the fundamental architecture of Cisco SD-WAN. The solution builds a secure VPN overlay using IPsec tunnels over any available transport (MPLS, broadband, LTE). This ensures that all data, regardless of the underlying carrier, is encrypted and secure, directly mitigating the customer's primary security concern about moving away from private MPLS.
- Question 2Intermediate
SD-WAN Design · Describe solution-architecture
To complete the configuration for a centralized control policy that redirects specific traffic to a firewall service chain in an SD-WAN fabric, the policy must be applied to a specific ______ in the correct direction.
Show answer & explanation
Correct answer: B
Centralized control policies, including those for service chaining, are applied to a 'site list' from the perspective of the vSmart controller. The direction is critical: 'from-service' or 'from-tunnel' for traffic coming into the site from the overlay, and 'from-site' for traffic leaving the site. For service chaining, the policy is typically applied to a site list containing the spoke sites in the 'from-site' direction to redirect traffic towards the firewall at a hub site.
- Question 3Intermediate
ISE Demonstration · Describe Demo and POV
A systems engineer is conducting a Proof of Value (POV) for Cisco ISE. The customer wants to see how ISE can provide visibility into unmanaged IoT devices, such as security cameras and HVAC sensors, without requiring 802.1X. Which ISE feature should be the primary focus of this demonstration?
Show answer & explanation
Correct answer: C
For devices that do not support 802.1X, ISE's primary visibility tool is the Profiler service. The engineer should demonstrate how ISE can be configured to use various probes (DHCP, RADIUS, SNMP, NMAP, etc.) to collect attributes from network traffic and devices. ISE then matches these attributes against pre-defined or custom profiles to identify the endpoint's type, manufacturer, and OS, providing the exact visibility the customer wants to see.
- Question 4Advanced
SD-Access Design · Describe high level design of SDA
A global enterprise is designing an SD-Access fabric that will span multiple continents. To ensure scalability and efficient management, they plan to use a hierarchical Cisco DNA Center deployment. What is the relationship between the primary and subordinate DNA Center appliances in this model?
Show answer & explanation
Correct answer: C
In a hierarchical (or multi-instance) Cisco DNA Center design, the primary or 'master' appliance is used for centralized design, policy creation, and global reporting. This master configuration is then synchronized down to the subordinate or 'regional' appliances. The subordinate appliances are responsible for the operational management of the devices within their specific geographic region, including provisioning, assurance, and local event handling. This model provides both centralized control and regional autonomy/scalability.
- Question 5Intermediate
SD-WAN Demonstration · Describe reinventing WAN operations
A customer is concerned about the operational complexity of managing a large SD-WAN fabric. During a demonstration, which vManage feature best illustrates how Cisco SD-WAN simplifies troubleshooting and reduces mean time to resolution (MTTR)?
Show answer & explanation
Correct answer: D
The vManage operational monitoring dashboard is the most powerful feature for demonstrating simplified troubleshooting. It provides an immediate, intuitive, and centralized view of the entire fabric's health. An engineer can quickly see the status of all control connections, identify underperforming sites or links, view application performance scores (QoE), and then drill down into specific devices or tunnels to get detailed statistics and logs. This centralized visibility drastically reduces the time it takes to isolate and resolve issues compared to logging into individual routers.
- Question 6IntermediateSelect 3
ISE Design · Describe an overview of solutions and architecture
A hospital needs to implement secure access for medical staff, patients, and IoT medical devices (like infusion pumps). The CISO has mandated a Zero Trust security model, requiring that every connection be authenticated and authorized. Which three Cisco ISE features are fundamental to building this Zero Trust access solution? (Select THREE)
Show answer & explanation
Correct answers: A, B, D
Zero Trust starts with knowing what is on the network. ISE Profiling provides the visibility to identify every device (staff laptop, patient phone, infusion pump) to make an informed policy decision.
To provide controlled and auditable access for patients, a secure Guest Access portal is essential. It allows for self-registration, credential delivery, and enforcement of an acceptable use policy.
After identifying and authenticating a device, TrustSec provides micro-segmentation by assigning a Security Group Tag (SGT). This allows the creation of granular policies (e.g., infusion pumps can only talk to specific servers), which is a cornerstone of Zero Trust enforcement.
- Question 7Intermediate
SD-Access Design · Describe high level branch design
A systems engineer is designing an SD-Access solution for a company with a small remote branch office. The customer wants to extend the fabric policy to this branch but has a limited budget and cannot afford a full fabric-enabled switch and router. Which SD-Access component is designed specifically for this use case?
Show answer & explanation
Correct answer: D
The SD-Access Extended Node feature is designed for this exact scenario. It allows a compatible Catalyst switch (like a 9200 or 9300 series) at a remote site to connect back to a main campus fabric edge node over a Layer 3 connection. The extended node itself doesn't participate in the fabric control plane (LISP) but acts as a policy enforcement point, extending the fabric's VNs and SGTs to the remote branch without requiring a full fabric deployment at that site.
- Question 8Intermediate
SD-WAN Design · Describe reinventing WAN application services
During an SD-WAN design session, a customer asks how Cisco's solution can improve the user experience for critical SaaS applications like Salesforce and Office 365. Which specific Cisco SD-WAN feature provides automated path selection and direct internet access for these applications based on real-time performance monitoring?
Show answer & explanation
Correct answer: B
Cloud OnRamp for SaaS is the specific feature designed to optimize performance for well-known SaaS applications. It continuously probes the paths from the branch to the SaaS provider (e.g., Microsoft, Salesforce) over all available internet circuits. It then calculates a quality score (vQoE) for each path and automatically steers the SaaS traffic to the best-performing path in real-time, ensuring the best possible user experience without backhauling traffic to a data center.
- Question 9Beginner
ISE Design · Describe an overview of solutions and architecture
True or False: In a Cisco ISE distributed deployment, the Primary Administration Node (PAN) is responsible for processing all RADIUS authentication requests from network devices.
Show answer & explanation
Correct answer: B
This statement is false. In a distributed ISE deployment, the Policy Service Nodes (PSNs) are responsible for handling all RADIUS and other network access requests. The Primary Administration Node (PAN) is used for configuration, management, and policy distribution to the PSNs but does not actively process endpoint authentication traffic. This separation of roles allows the deployment to scale.
- Question 10Beginner
SD-Access Design · Describe high level migration considerations
A systems engineer is designing a migration from a traditional campus network to SD-Access. The customer wants a phased approach that minimizes disruption. The plan is to introduce the SD-Access fabric in a new building first, while maintaining connectivity with the existing legacy network. Which fabric role is essential for connecting the SD-Access domain to the external, non-fabric network?
Show answer & explanation
Correct answer: C
The Fabric Border Node is the gateway between the SD-Access fabric and any external network, including the internet, WAN, data center, or a legacy campus network. It handles the translation and routing between the fabric's overlay (LISP/VXLAN) and the traditional IP routing of the external world. In a migration scenario, the border node is critical for ensuring seamless communication between users in the new fabric and resources still residing on the old network.
Ready for the real thing?
The full 500-470 simulator has every exam-style question, timed mode, and instant scoring.