10 free Cisco 500-220 ECMS practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 85 questions. Work through them, then open each answer to check your reasoning.
Get all 85 questions (US$39) · Download these 10 as a PDF
Question 1
For which two reasons can an organization become “Out of License”? (Choose two.)
Show answer and explanation
Correct answer: B, C
B. more hardware devices than device licenses C. expired device license An organization becomes out of license when it has more hardware devices than the number of device licenses purchased, or when device licenses expire. Device licenses have expiration dates, and once they expire, the organization no longer has valid licensing for those devices. Similarly, if the count of physical devices exceeds the licensed device count, the organization is in an out-of-license state. Network location and serial number matching are administrative concerns but do not directly result in an out-of-license status.
Why the other options are wrong
- A. License network location is an administrative setting and does not cause out-of- license status.
- D. Serial number mismatches are configuration issues, not licensing compliance issues.
- E. MR model mismatches do not trigger out-of-license status; the license count versus device count determines compliance.
Question 2
In an organization that uses the Co-Termination licensing model, which two operations enable licenses to be applied? (Choose two.)
Show answer and explanation
Correct answer: A, C
A. Renew the Dashboard license. C. License more devices. In the Co-Termination licensing model, licenses are applied by renewing the Dashboard license (which renews all associated licenses simultaneously) and by licensing additional devices. These two operations allow organizations to add or maintain licenses within the co-termination framework. Calling support or waiting for auto-renewal are not standard operational methods for applying licenses, and licensing networks separately is not how co-termination works.
Why the other options are wrong
- B. In co-termination, you license devices, not networks separately.
- D. Calling support is not a standard method to apply licenses in co-termination.
- E. Auto-renewal is automatic but not an operation you perform to apply licenses.
Question 3
Refer to the exhibit. This Dashboard organization uses Co-Termination licensing model.
What happens when an additional seven APs are claimed on this network without adding licenses?

Show answer and explanation
Correct answer: D. All APs stop functioning in 30 days.
Under the Co-Termination licensing model, when devices exceed their license limit, they enter a grace period rather than stopping immediately. The exhibit shows 7 Wireless APs are licensed with 1 currently in use. Adding 7 more APs would exceed the limit of 7 by 7 devices. In Co-Termination models, unlicensed devices operate in a grace period (typically 30 days) before enforcement occurs. At the end of the grace period, all APs stop functioning when compliance is not restored, not just individual ones. This is the standard behavior to encourage license compliance while allowing time for administrative remediation.
Why the other options are wrong
- A. APs do not stop immediately; Co-Termination provides a grace period before enforcement.
- B. While a 30-day grace period applies, the question specifies APs (network devices, not all network devices), and only the APs would stop, not all network devices.
- C. Co-Termination enforces all out-of-compliance devices together after the grace period, not selectively one device at a time.
Question 4
Refer to the exhibit.
What is the minimal Cisco Meraki Insight licensing requirement?

Show answer and explanation
Correct answer: B. A single Meraki Insight license must be configured on network B to gain Web App Health visibility on network B.
network B to gain Web App Health visibility on network B. Meraki Insight licensing is required on the network where visibility and reporting are needed. In this scenario, Network B requires Web App Health visibility, which means a single Meraki Insight license must be configured on Network B itself. The VPN tunnels from Network A to Network B allow the traffic to flow, but the licensing requirement is determined by the destination network that needs the visibility feature. Network A does not need Insight licensing for this use case since the visibility requirement is specifically for Network B.
Why the other options are wrong
- A. Network A does not need licensing to provide visibility for Network B; the license must be on the network requiring visibility.
- C. Only Network B requires licensing since that is where the visibility is needed; Network A licensing is unnecessary for this requirement.
- D. Only one Meraki Insight license is needed on Network B; two licenses on Network A are not required.
- E. Licensing on Network A is not required, and only one license on Network B is needed for Web App Health visibility.
Question 5
How does a Meraki device behave if cloud connectivity is temporarily lost?
Show answer and explanation
Correct answer: A. The offline device continues to run with its last known configuration until cloud connectivity is restored.
configuration until cloud connectivity is restored. When a Meraki device loses cloud connectivity temporarily, it continues to operate using its last known configuration that was pushed from the cloud. The device maintains traffic forwarding and network operations without interruption until connectivity is restored. This resilience is a core feature of Meraki's edge computing architecture, ensuring business continuity during temporary cloud outages.
Why the other options are wrong
- B. Devices do not reboot repeatedly when offline; they maintain stability and operation.
- C. Devices continue to pass traffic using cached configuration; they do not stop traffic flow.
- D. Meraki devices do not attempt to connect to local backup servers; they use their locally cached configuration.
Question 6
What are two organization permission types? (Choose two.)
Show answer and explanation
Correct answer: A, B
A. Full B. Read-only Meraki Dashboard supports two primary organization-level permission types: Full (which grants complete administrative access) and Read-only (which allows viewing but not modifying resources). These represent the two main authorization levels for organization administrators. Monitor-only, Write, and Write-only are not standard organization permission type classifications in Meraki.
Why the other options are wrong
- C. Monitor-only is not a standard organization permission type.
- D. Write is not a distinct organization permission type; Full access includes write capabilities.
- E. Write-only is not a standard organization permission type in Meraki.
Question 7
What is the role of the Meraki Dashboard as the service provider when using SAML for single sign-on to the Dashboard?
Show answer and explanation
Correct answer: A. The Dashboard generates the SAML request.
When using SAML for single sign-on, the Meraki Dashboard acts as the service provider that generates and sends the SAML request to the identity provider. The Dashboard initiates the authentication flow by requesting authentication credentials from the IdP. The Dashboard does not generate SAML responses (the IdP does), does not provide credentials, and does not parse requests; rather, it parses the SAML response that comes back from the identity provider.
Why the other options are wrong
- B. The Dashboard does not provide user credentials; the identity provider does.
- C. The Dashboard parses the SAML response from the IdP, not SAML requests.
- D. The identity provider generates the SAML response, not the Dashboard.
Question 8
A customer wants to use Microsoft Azure to host corporate application servers.
Which feature does the customer get by using a vMX appliance rather than connecting directly to Azure by VPN?
Show answer and explanation
Correct answer: B. SD-WAN
The virtual MX (vMX) appliance provides SD-WAN capabilities that enable intelligent routing and traffic steering between corporate sites and cloud applications like those hosted in Azure. This SD-WAN functionality allows the customer to optimize application performance, manage multiple paths intelligently, and apply policies across the network, capabilities that are not available with a direct VPN connection. Direct VPN connections provide basic connectivity but lack the intelligent routing and policy control that SD-WAN delivers.
Why the other options are wrong
- A. Malware protection is a security function but is not the primary differentiator of vMX over direct VPN.
- C. Next-generation firewall is a security feature but is not the key advantage of vMX for Azure connectivity.
- D. Intrusion prevention is a security capability but is not the defining feature of using vMX instead of direct VPN.
Question 9
When deploying network-wide alerts, which three active alerting techniques can be sent from the Cisco Meraki dashboard? (Choose three.)
Show answer and explanation
Correct answer: A, D, F
A. Email D. Webhooks F. SMS The Meraki Dashboard supports three active alerting techniques for network-wide alerts: Email (sent directly to configured recipients), Webhooks (which trigger HTTP callbacks to external systems for integration), and SMS (text messages sent to phone numbers). These three methods enable real-time notifications to multiple recipients and systems. Event logs and change logs are passive record-keeping mechanisms rather than active alerting techniques, and Teams is not a native alerting channel in Meraki Dashboard.
Why the other options are wrong
- B. Event logs are passive logging, not an active alerting technique.
- C. Change logs are passive record-keeping, not an active alerting method.
- E. Teams is not a native alerting channel supported by Meraki Dashboard.
Question 10
What is a feature of distributed Layer 3 roaming?
Show answer and explanation
Correct answer: A. An MX Security Appliance is not required as a concentrator.
concentrator. Distributed Layer 3 roaming is designed so that an MX Security Appliance is not required to act as a central concentrator. In this architecture, wireless traffic can be routed directly from access points without requiring a centralized appliance, distributing the routing function across the network. This eliminates the bottleneck and single point of failure that a centralized concentrator would introduce, while still maintaining Layer 3 roaming capabilities across multiple APs.
Why the other options are wrong
- B. Distributed Layer 3 roaming specifically eliminates the need for a concentrator MX appliance.
- C. Split-tunneling is not a feature of distributed Layer 3 roaming; traffic is typically tunneled or routed directly.
- D. Not all wireless client traffic is necessarily tunneled in distributed Layer 3 roaming; the architecture allows direct routing without centralized tunneling.
That was 10 of 85.
The full Cisco 500-220 ECMS pack has all 85 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
