Travis Flashcards

1
Q

Your company wants to implement a custom Splash page for the ‘Guest’ SSID. The redirect URL is already configured in the dashboard but needs to be added to the walled garden list.

Where in the dashboard would you go to add the Splash page URL to the walled garden list for the ‘Guest’ SSID?

A. Wireless > Configure > Walled garden
B. Wireless > Configure > Splash page
C. Wireless > Configure > Firewall & traffic shaping
D. Wireless > Configure > Access control

A

D

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Refer to the exhibit. A dashboard administrator shared this screenshot reporting a missing access to the Monitor column for this specific network.

Why is the Monitor column not present?

A. Organization administrative privilege for this user are set to ‘Configure-only’
B. The monitor column will appear after the first MS Switch is added to this network
C. The monitor column is not available for template networks
D. MS in this network are currently performing an upgrade, the monitor column will appear when the upgrade is completed

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Refer to the exhibit. You are currently managing an organization that is using the OSPF capabilities of the MX security appliances to redistribute auto VPN routes to neighboring L3 switches.

Due to a new security policy the MD5 Authentication key for OSPF messages needs to be updated.

Where in Dashboard would you go to update the MD5 Authentication key for the ‘Site A’ MX?

A. Network (Site A) > Security & SD-WAN > Configure > Site¬-to-¬site VPN > OSPF settings
B. Organization > Configure > Settings > (Site A) OSPF Settings
C. Network (Site A) > Security & SD-WAN > Configure > Addressing & VLANs > OSPF settings
D. Network (Site A) > Security & SD-WAN > Configure > Security Center > OSPF security settings

A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

On Security & SD-WAN -> Monitor -> Appliance Status -> Uplink you see the following output:

Where can you configure the Connectivity-Destinations (like 103.112.104.41)?
(Select all that apply)

a) Security & SD-WAN -> Configure -> Addressing & VLANs -> Connectivity

b) Security & SD-WAN -> Configure -> SD-WAN & traffic shaping -> Uplink configuration

c) Network-wide -> Configure -> Alerts -> Uplink configuration

d) Organisation -> Configure -> Alerts -> Global Uplink configuration

e) none of the above

A

B

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which of the following families of products can leverage the local override functionality when included in a network bound to a template? (Choose 2)

a. MX Security appliance
b. MV Cameras
c. MT Sensors
d. MG Gateway
e. MR Access point
f. MI Meraki Insight

A

A, E

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A customer has 3 MX security appliances deployed in 3 different locations, All the MX’s are in Routed mode and participate in the VPN topology as hubs. MX 1 and MX 2 report no issue in the dashboard, while MX 3 reports a “NAT unfriendly” warning message in the VPN status page.
Which of the following might be causing the issue?

a. MX 1 is behind an upstream device that is rewriting the source port when trying to establishing the VPN tunnel with MX 3
b. MX 3 is behind an upstream device that is rewriting the destination port when communicating with the two VPN cloud registry
c. MX 3 NAT functionality for the LAN to WAN traffic is not configured properly
d. MX 3 is behind an upstream device the is rewriting different source port when communicating with the two VPN cloud registry

A

d

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Refer to the exhibit. This is the configuration for an SSID to be used as MR Teleworker VPN.
Which of the following statements is true regarding clients connecting to an SSID with no firewall & traffic shaping rules and this configuration applied?

a. Clients connected will be able to communicate with each other
b. Clients with a static IP address will not be able to associate with this SSID
c. Clients connecting to this SSID will receive IP addresses in an isolated 10.0.0.0/8 network
d. Clients traffic with destination IP address 8.8.8.8 will always be sent over the VPN tunnel

A

a

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Look at the image below. It contains information about a device managed via Systems Manager. Which sentence is true about that device?

a. Between 9am and 5pm on weekdays and all day on weekends, some apps will be uninstalled from the device.
b. Between 6am and 6pm on weekdays and all day weekends, some apps will be uninstalled from the device.
c. The Corp security policy has been violated because a disk storage threshold was broken
d. The device has been rebooted within the past couple of days.

A

d

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Fill in the blanks: When enabling IDS/IPS on the Meraki Dashboard, there are 3 different rulesets you can choose: You can leave it as ________ (default, matching CVSS 9 and 10), or you can change it to ________ (matching CVSS 10 only) or ________ (matching CVSS 8, 9 or 10).

a. Balanced - Connectivity - Security
b. Security - Balanced - Connectivity
c. Connectivity - Balanced - Security
d. Connectivity - Security - Balanced

A

a

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Refer to the exhibit. Exhibit A is the current saved configuration on the MX. A network administrator wants to update the IP address configuration for VLAN ID 128 as shown in exhibit B but while saving the new configuration dashboard returns the error shown in exhibit C. What is the root cause of the error?

a. The MX IP address must be the first IP available in the network
b. There is 1 range of reserved IP addresses in the DHCP server configuration for VLAN ID 128 with the previous addressing scheme
c. There is 1 range of reserved IP addresses and 1 fixed IP address in the DHCP server configuration for VLAN ID 128 with the previous addressing scheme
d. There are 2 ranges of reserved IP addresses and 1 fixed IP address in the DHCP server configuration for VLAN ID 128 with the previous addressing scheme

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

On the Meraki Dashboard, where should you navigate to make sure your MV cameras are in the correct time zone, and change it if you need to?

  1. Cameras > Monitor > General
  2. Cameras > Configure > General
  3. Network-wide > Monitor > General
  4. Network-wide > Configure > General
A

4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How many class of service (CoS) queues are supported on MS switches?

a. 4
b. 6
c. 8
d. 10

A

b

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Look at the image below. It shows a layer 2 network topology diagram inside the Meraki Dashboard. Which sentence is true regarding the topology?

a. It can be downloaded in JPEG format.
b. It shows two devices that are offline.
c. It supports both Meraki and non-Meraki devices.
d. It is built based on the default routes (0.0.0.0/0) in the switches.
e. It allows administrators to see static routes for particular nodes by hovering over them.

A

c

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When cloning a Meraki Switch, what does not get copied across?

A.) Local Settings
B.) STP Bridge priority
C.) Port Tag
D.) Interface state

A

A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which section of the Meraki Dashboard allows the configuration of System Manager Sentry policies?

a. Systems Manager > Manage > Sentry policies
b. Security & SD-WAN > Configure > Sentry policies
c. Network-wide > Configure > Sentry policies
d. Systems Manager > Configure > Sentry policies

A

C

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which sentence is true regarding the Per-Device Licensing (PDL) model for Cisco Meraki organizations?

a. You no longer get a 30 day grace period after license expiration date.
b. If your licenses are not activated within 90 days, they are automatically invalidated.
c. PDL is a requirement in order to use MR advanced licenses in an organization.
d. Licenses are cheaper in PDL compared to Co-termination.

A

c

17
Q

Refer to the exhibit. This is the status of the managed apps on an Android device Enrolled in SM with a work profile installed. Trying to manually install the missing application leads to an error displayed in the Google Play Store ‘Your administrator has not given you access to this item’.
What is the reason for this error that prevents the installation of the app?

a. The Target Scope in dashboard does not include this device
b. There are no licenses available for the selected application
c. The permissions for the application are not approved in dashboard
d. The auto-install option is not enabled in dashboard for this application

A

C

18
Q

Refer to the exhibit. What is the expected result of this Dashboard API call assuming the response to the call is 200 OK?

a. The selected organization ‘id’ parameter will be updated to 1234567
b. A new organization named 1234567 will be created
c. A new network named 1234567 will be created inside the selected organization
d. The selected organization ‘name’ parameter will be updated to 1234567

A

d

19
Q

Which sentence is true regarding the use of tags inside the Meraki Dashboard?

  1. Device tags can be used to determine the scope of the SSID availability feature.
  2. Network tags can be used to determine the scope of the SSID availability feature.
  3. Switches apply the recently-added tag to their ports by default.
  4. All network tags are static, and all SM tags are dynamic.
  5. All SM tags are static, and all network tags are dynamic.
A

1

20
Q

What kind of logs are always stored in the UTC time zone inside the Meraki Dashboard?

a. Event log
b. Change log
c. Video access log
d. SM activity log

A

b

21
Q

Which of the following statements is true regarding the dashboard API?

a. Dashboard allow an administrative user to generate and maintain up to 3 API keys
b. API Keys are generated in Organization > Configure > Settings
c. API Access need to be enabled in Organization > Configure > Settings
d. API keys can be retrieved from dashboard at any time after being generated

A

c

22
Q

What two registration interaction levels are available to network admins when building a guest access policy?

A.) User and Automatic
B.) Self-serve and Restricted
C.) CoA and 802.1x
D.) Guest and Executive

A

A

23
Q

On the Meraki Dashboard, where should you navigate to review the Video Access log for MV cameras?

a. Network-Wide > Monitor > Event log > Video Access log
b. Cameras > Monitor > Video Log > Video Access log
c. Cameras > Monitor > Video Access > Video Access log
d. Organization > Monitor > Camera roles > Video Access log

A

C

24
Q

Which of the following is a true statement regarding the MR Advanced License Umbrella integration?

a. Detected MR DNS events are visible navigating to Organization > Monitor > Security Center > MR DNS Events
b. The license is available in both licensing model, Per-Device-Licensing and Co-Termination
c. The Umbrella API key needs to be configured in dashboard in order to turn on the DNS protections included with the MR Advanced license
d. Detected MR DNS events are visible navigating to Wireless > Monitor > Health > DNS Events

A

a

25
Q

Refer to the exhibit. Which of the following is true?
a. None of the ports of the switch displayed is used as an uplink to communicate with the Meraki cloud
b. None of the ports of the switch displayed is providing PoE at the moment
c. The switch is a stack member
d. All of the above

A

d

26
Q

Refer to the exhibit. Which of the following statements is correct?

a. The Chicago network is bound to a template
b. Switch and Security appliance in the network will upgrade at their next reboot
c. Cameras for the Chicago network are not shown in the firmware page because their status in dashboard is Dormant
d. The user currently logged in has Org level administrative access

A

d

27
Q

Which statements about Meraki Auto RF are true? (Select 2)

a. Auto RF is enabled by default.
b. Auto RF requires the meshing parameter in the General network settings to be set to enabled in order to work.
c. Auto RF will affect different parameters of the AP configuration including channel assignment and per-radio transmit power.
d. Auto RF changes are not logged in the event log.
e. In order to work, Auto RF requires an Advanced license associated with every AP in an organization.

A

A, C

28
Q

Why would you want to split an organisation into multiple networks?

A.) To create additional Auto-VPN domains
B.) To calculate a longer licensing co-termination date
C.) To avoid exceeding Dashboard limitations with the max number of devices per network
D.) To unlock the MSP portal navigation feature

A

C

29
Q

Refer to the exhibit. Assume that the MX in question is a spoke connected via AutoVPN to one hub using split tunnels, all its local subnets have been advertised over the VPN, and both its WAN connections are up. How will the MX route traffic sourced from subnet 172.17.25.0/24 destined for the internet?

a. It will be sent out WAN1 as long as it is up.
b. It will be sent out WAN2 as long as it is up.
c. It will be sent out WAN1 as long as it meets the thresholds in the performance class called “Telepresence”.
d. It will be sent out WAN2 as long as it meets the thresholds in the performance class called “Telepresence”.
e. It will be load balanced between WAN1 and WAN2.

A

E

30
Q

Which of the following operations involving an MR access point can only be performed on the local status page of the device?

a. Change the login credential for the local status page
b. Enable survey mode for the access point
c. Assign a static IP to the access point
d. Statically configure the channel for the 2.4 GHz radio

A

b

31
Q

Select the correct firewall rule processing order for the MX security appliance:

A.) L3 allow/deny > L3 implicit deny > L7 deny
B.) L3 allow/deny > L3 implicit allow > L7 deny
C.) L3 allow/deny > L7 deny > L3 default deny
D.) L7 deny > L3 allow/deny > L3 implicit allow

A

B

32
Q

Which of the following statements is true regarding a pair of MX security appliances configured in High Availability (HA) ?

a. It is possible to pair different MX model in an HA deployment
b. Leased DHCP addresses are synchronized between the HA pair
c. HA is achieved using the HSRP protocol
d. MX deployed in Passthrough Mode mode cannot be configured for HA

A

b

33
Q

What is a valid use of Network Tags?

a. Network Tags can be used to create aggregated summary report for a specific group of networks
b. Network Tags can be used simplify the configuration of site-to-site VPN firewall rules
c. Network Tags can be used to determine the availability of an SSID in a group of networks
d. Network Tags are mandatory to assign a network administrator

A

a

34
Q

Which of the following MX types of routes has the highest priority?

a. Non-Meraki VPN Peers
b. Client VPN
c. AutoVPN Routes
d. Static Routes

A

b

35
Q

Where on Dashboard would you go to configure layer 7 firewall rules to deny traffic for specific applications? (Select all that apply)

a. Security & SD-WAN > Configure > Firewall
b. Security & SD-WAN > Configure > Site-to-site VPN
c. Systems Manager > Configure > Policies
d. Wireless > Configure > Firewall & traffic shaping
e. Network-wide > Configure > Group policy

A

A, D, E

36
Q

Which statement correctly describes the minimum Dashboard configuration requirements in order to turn on the wireless connectivity option for MV Cameras?

a. A minimum of 1 wireless profile need to be defined and assigned as Primary
b. A minimum of 2 wireless profiles needs to be defined and assigned, one as Primary and the other as Backup
c. A minimum of 2 wireless profiles needs to be defined and assigned, one as Primary and the other as Secondary
d. A minimum of 2 wireless profiles needs to be defined and assigned, one as Primary and the other as Secondary and Backup

A

c