500-560 Sample Questions & Answers
Meraki's product mix, licensing and sales cycle make up the largest share, alongside wireless products like Mobility Express and WLC features, switching and routing portfolio basics, and branch threat defense through Umbrella.
Launch the full 500-560 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Security Overview and Features · Branch Threat Defense Umbrella
A company wants to provide secure DNS-layer security for its remote workers who are not connected to the corporate VPN. The solution should block malware, phishing, and command-and-control callbacks before a connection is ever established. Which Cisco security product is designed specifically for this purpose?
Show answer & explanation
Correct answer: B
Cisco Umbrella is a cloud-delivered security service that provides the first line of defense against threats on the internet by blocking malicious DNS requests. It is ideal for protecting remote workers off-VPN by enforcing security at the DNS layer, preventing connections to malicious destinations.
- Question 2Intermediate
Meraki Overview and Products · Meraki MX Security Appliances
A network engineer is deploying a Meraki full-stack solution (MX, MS, MR) for a new branch office. The goal is to simplify network management and gain visibility across the entire network from a single interface. The engineer has configured the devices but needs to enable communication between VLANs. Where in the Meraki dashboard must the engineer configure inter-VLAN routing?
Show answer & explanation
Correct answer: C
In a Meraki network, the MX Security Appliance acts as the Layer 3 gateway and handles inter-VLAN routing. This is configured under the 'Security & SD-WAN -> Addressing & VLANs' page by defining VLANs and their associated subnets. The MS switches operate at Layer 2 by default in this topology, forwarding traffic to the MX for routing decisions.
- Question 3Intermediate
Wireless Overview and Features · Wireless LAN Controller Features
What is the primary function of the Anchor WLC in a Cisco Auto Anchor Mobility configuration?
Show answer & explanation
Correct answer: B
The Anchor WLC provides a fixed point of presence for client traffic, most commonly for guest wireless access. When a guest user roams to an AP on a Foreign WLC, their traffic is tunneled back to the Anchor WLC. This ensures that all guest traffic exits the network from a single, controlled point (often in a DMZ), maintaining a consistent IP address and security policy.
- Question 4Advanced
Meraki Overview and Products · Meraki MV Cameras
A hospital is deploying Meraki MV cameras to monitor hallways and entrances. Due to patient privacy regulations (HIPAA), video footage must be retained for 180 days. The hospital has limited WAN bandwidth at its clinic locations. Which MV camera feature and configuration would best meet these requirements?
Show answer & explanation
Correct answer: D
The best solution is using the Meraki MV Smart Camera Connector. This allows video to be stored on an on-premise Network Video Recorder (NVR), which can be configured for 180-day retention without consuming WAN bandwidth for constant cloud archiving. This hybrid approach keeps video traffic local while still allowing for cloud management and analytics, satisfying both the long-term storage and low-bandwidth constraints.
- Question 5Beginner
Switching Overview and Features · Switching Portfolio
A network administrator needs to connect two switches in a wiring closet using their SFP+ ports. The switches are 5 meters apart. Which type of cable provides the most cost-effective solution for this high-speed, short-distance connection?
Show answer & explanation
Correct answer: C
Direct Attach Copper (DAC) cables are the most cost-effective and simplest solution for short-distance (typically up to 7-10 meters) 10G connections between switches in the same rack or closet. They are fixed-length cables with integrated transceivers, eliminating the need to purchase separate transceivers and fiber patch cords, which reduces cost and complexity.
- Question 6Advanced
Routing Overview and Features · IP Routing Fundamentals
A company has two main sites connected via a private WAN. They are running OSPF as their interior gateway protocol. An engineer needs to ensure that traffic from Site A to a specific server subnet (10.10.100.0/24) in Site B always uses the primary WAN link, even if a backup link has a lower metric for other routes. How should the engineer accomplish this?
Site A (R1) ---- (Primary WAN Link) ---- Site B (R2) | | |-------- (Backup WAN Link) ---------|Show answer & explanation
Correct answer: C
Policy-Based Routing (PBR) is the correct tool for this requirement. OSPF makes decisions based on the destination address and link cost, which applies to all traffic. PBR allows the administrator to override the routing table for specific traffic based on a wider set of criteria (like source/destination address). By creating a route map that matches traffic destined for 10.10.100.0/24 and setting the next-hop to the primary link, the engineer can force that specific traffic over the desired path, regardless of the OSPF metric.
- Question 7Intermediate
Wireless Overview and Features · Cisco DNA Spaces and Assurance
Which Cisco DNA Spaces feature allows a venue to analyze how visitors move between different zones over time?
Show answer & explanation
Correct answer: C
Behavioral Metrics within Cisco DNA Spaces provide insights into visitor behavior, including path analysis and journey tracking. This allows businesses to understand common paths, see which zones are visited in sequence, and analyze how visitors navigate the physical space, which is invaluable for optimizing layouts and engagement.
- Question 8Intermediate
Meraki Overview and Products · Meraki SM Systems Manager
An administrator is using Meraki Systems Manager to manage a fleet of corporate-owned iPads. They need to prevent users from installing unauthorized applications from the public App Store. Which Systems Manager feature should be used to achieve this?
Show answer & explanation
Correct answer: B
The Restrictions profile within a Meraki Systems Manager policy allows administrators to control device functionality. For iOS devices, this includes an option to 'Disallow installing apps using App Store', which effectively blocks users from accessing the public App Store to install applications. Authorized apps can still be pushed to devices through Systems Manager.
- Question 9Beginner
Wireless Overview and Features · Wireless LAN Controller Features
What is the key advantage of using Cisco Catalyst 9800 Series Wireless Controllers, which are based on IOS-XE, compared to older AireOS-based controllers?
Show answer & explanation
Correct answer: B
A major advantage of the IOS-XE based Catalyst 9800 controllers is their support for high availability and seamless software updates. Features like In-Service Software Upgrade (ISSU) allow for patching and minor upgrades without network downtime, which was a significant challenge with older AireOS controllers that often required a full reboot.
- Question 10Beginner
Switching Overview and Features · LAN Switching Fundamentals
The command
switchport port-security maximum 2has been configured on a switch interface. What happens when a third device connects to this port?Show answer & explanation
Correct answer: B
By default, when a port security violation occurs, the violation mode is 'shutdown'. This means that when the third MAC address is detected on the port (exceeding the maximum of 2), the switch will place the interface into an err-disabled state, effectively shutting it down until an administrator manually re-enables it.
Ready for the real thing?
The full 500-560 simulator has every exam-style question, timed mode, and instant scoring.