No account required · source-reviewed July 17, 2026

See how the training works

A real public sample from the current course model: one short lesson, one approved question with option-by-option feedback, one simulator-lab walkthrough, and a three-question diagnostic.

Certification transition: Cisco lists August 26, 2026 as the last test date for 500-220 ECMS. The exam sprint ends with that window; the simulator remains available as Meraki operational-skills training. Read the full scope.
Lesson sample · Domain 1: Cloud Management

Management plane versus data plane

Meraki is cloud-managed, but “cloud-managed” does not mean ordinary user traffic is automatically sent through the Meraki cloud. The Dashboard provides the management plane: administrators define configuration and view telemetry there. The MX, MS, and MR devices apply that configuration and forward production traffic locally.

Meraki Dashboard
Configuration and telemetry
MX / MS / MR
Local production forwarding

Why the distinction matters

This lesson is intentionally concise. For production design, validate behavior, licensing, and failure modes against current Meraki documentation for the exact device and feature.

Approved practice question · Inventory item, Domain 1

In the Meraki cloud-managed architecture, which statement best describes how user data traffic is handled?

A. User data traffic is proxied through the Meraki cloud before reaching its destination.
Incorrect: the cloud is the management plane, not a default data-path proxy.
B. Only management/control traffic goes to the cloud; user data is switched/routed locally by the device.
Correct: Dashboard controls configuration and telemetry while the local device forwards production traffic.
C. All traffic is encrypted and stored in the Meraki cloud for compliance.
Incorrect: ordinary user payloads are not stored in the cloud as a general property of Meraki management.
D. User data is tunneled to the nearest Meraki data center for inspection.
Incorrect: data is not automatically tunneled to a Meraki data center for inspection.

Key concept: out-of-band cloud management. This question is original practice material, not a copied Cisco exam item and not proof of what any learner will see on test day.

Simulator walkthrough · Wireless access control

Configure Identity PSK without RADIUS

Scenario: a shared residential SSID needs per-resident keys, with each key mapped to a policy. The training goal is to rehearse the decision and Dashboard-style path—not to configure a real organization.

  1. Open Wireless › Access control.
    Select the training SSID. The simulator presents a simplified access-control screen.
  2. Choose Identity PSK without RADIUS.
    The learner distinguishes a shared PSK from per-identity keys that map to policies.
  3. Add an identity.
    Enter a practice name, an 8–63 character passphrase, and a group policy. Use fabricated values only.
  4. Add a second identity and compare policy mapping.
    The check looks for multiple identity records and a valid passphrase length in simulator state.
  5. Review the “why.”
    Each key can identify a user or group without an external RADIUS workflow, while the mapped policy carries network treatment.
Known limit: this walkthrough does not call a live Dashboard API, create a real SSID, validate licensing, exercise wireless clients, or prove packet isolation. Labels and control placement can change in the live product. See the fidelity scope.
No-login diagnostic · 3 questions

Check the Cloud Management baseline

Submit all three for explanations. The result is a tiny practice check, not a readiness score or exam prediction.

1. How is ordinary user traffic handled in the default cloud-managed architecture?
2. Forty devices bought at different times share one expiration date. Which license model does that describe?
3. Which hierarchy is correct from largest to smallest?
Your explanations will appear here.