CMSS logo
Focused certification exam prep
Start practice

CMSS Cheat Sheet 2026: One-Page Review of Must-Know Facts

TL;DR
  • The Cisco Meraki Solutions Specialist exam is Engineering Cisco Meraki Solutions v1.0 (500-220 ECMS): 90 minutes, USD 300.
  • Design and Monitoring and Troubleshooting are each 30% of the blueprint, together 60% of your score.
  • Implementation carries 25%, covering MX, MS, MR, SM, MV and MI configuration tasks.
  • Cloud Management is only 15%, but licensing, co-termination and org structure underpin every other domain.

What This Cheat Sheet Covers

This page is a compressed review sheet for the Cisco Meraki Solutions Specialist credential, earned by passing the Engineering Cisco Meraki Solutions v1.0 exam (500-220 ECMS). It is meant for the final stretch of preparation: the stage where you already know the material and need a fast way to check that nothing is slipping. If you are earlier in your journey, start with the CMSS study guide for a full preparation plan, then return here.

Everything below is organized around the four official blueprint domains. Where Cisco has not published a detail (for example, an exact question count or passing score), this sheet says so rather than guessing. For the passing-score situation specifically, see our breakdown of the CMSS passing score.

Exam Snapshot: 500-220 ECMS at a Glance

ItemWhat to Know
Exam nameEngineering Cisco Meraki Solutions v1.0
Exam code500-220 ECMS
Certifying bodyCisco Systems, Inc.
Duration90 minutes
FeeUSD 300
Number of questionsNot specified in the supplied official source material
Passing scoreNot specified in the supplied official source material
Blueprint domainsFour, weighted 15% / 30% / 25% / 30%

Cisco's blueprint carries an important disclaimer: the listed topics are general guidelines, related topics may appear on the exam, and the guidelines may change without notice. In practice, that means you should treat the official 500-220 ECMS exam topics PDF as the final authority and verify it close to your test date. For the money side of the equation, including what the USD 300 fee does and does not cover, see the CMSS certification cost breakdown.

Weighting insight: Design (30%) and Monitoring and Troubleshooting (30%) add up to 60% of the blueprint. Candidates who spend most of their time memorizing configuration menus often under-prepare for these two domains, which test judgment (what should you build, and why is it broken) more than click paths.

Cloud Management Essentials (15%)

The smallest domain by weight, but it sets the vocabulary for everything else. Expect questions on how the Meraki cloud model works, how administrators reach Dashboard and devices, how organizations are structured, and how licensing behaves over time.

Domain 1: Cisco Meraki Cloud Management (15%)

Blueprint objectives you must be able to explain or compare:

  • Cloud architecture: how devices connect to the Meraki cloud and what the management plane does versus the data plane.
  • Access methods: reaching Dashboard and reaching devices directly, including when local access is useful.
  • Organizational structure, segmentation and permissions: organizations, networks, and role-based administrative scope.
  • Licensing, co-termination and renewals: how license terms align, what renewal does to the expiration date, and what happens when licensing lapses.
  • Deployment workflows: comparing ways to bring new hardware online and into the right network.

Rapid-recall points

  • Permissions questions usually hinge on scope: organization-wide versus network-level versus tag-based access.
  • Co-termination questions are arithmetic-and-logic questions: if licenses with different end dates are merged, what is the resulting expiration behavior? Practice reasoning through a few examples rather than memorizing a rule.
  • "Compare deployment workflows" means be ready to choose the right onboarding method for a scenario (many sites, no on-site IT, and so on), not just define each one.

Each domain gets a deeper treatment in our complete guide to all four CMSS content areas.

Design Essentials (30%)

Design is the heaviest domain tied for first place, and the broadest. The objectives span WAN, LAN services, wireless and endpoint management. Questions tend to be scenario-driven: a customer has requirements, and you must pick the architecture or policy that fits.

Domain 2: Design (30%)

Four clusters of objectives:

  • WAN and VPN: scalable Auto VPN architectures; vMX deployment considerations; dynamic path selection policies; stable, secure and scalable routing.
  • Enterprise network services: redundancy and high availability; QoS strategy for voice and video; Layer 2 security; firewall and IPS rules on MX and MR; network access control solutions.
  • Enterprise wireless: high-density deployments; MR networks for enterprise use; MR networks for guest access.
  • Endpoint and application management: comparing methods, including device enrollment types such as supervised and device owner, and application deployment.

Auto VPN and SD-WAN design

Know the roles in an Auto VPN topology (hub versus spoke), the reasons you would pick a full-mesh style versus hub-and-spoke, and how a vMX fits when a hub lives in a public or private cloud instead of on a physical appliance. For dynamic path selection, be able to reason about which traffic should prefer which uplink and what performance criteria trigger a path change.

High availability and routing

Be ready to compare redundancy mechanisms at the WAN edge, the distribution layer and the access layer, and to explain what each protects against. Routing design questions favor stability and scalability: think about when static routes are acceptable and when dynamic routing is the better call.

QoS, Layer 2 security and access control

For voice and video, understand classification and prioritization conceptually: what gets marked, where it is trusted, and where it is enforced. For Layer 2 security, expect features that protect the switched edge. For access control, understand how 802.1X and policy-based access fit together and when a design calls for them.

Wireless design

High-density design is a capacity problem, not a coverage problem. Guest wireless design is an isolation-and-policy problem. Keep those two mental frames separate and many questions get easier.

Design-question habit: Before looking at answer choices, restate the customer's real constraint in one phrase (for example, "must survive a single uplink failure" or "voice must stay clean under load"). Wrong answers in design questions are usually technically valid features that simply do not address the stated constraint.

Implementation Essentials (25%)

Implementation is where the product lines each get their moment. The blueprint walks through MX, MS, MR, SM, MV and MI, so breadth matters. You do not need to be an expert in every product's every setting, but you should know the main configuration objects for each.

Domain 3: Implementation (25%)

Product-by-product configuration scope:

  • MX security appliances: SVI, static and dynamic routing, Auto VPN, traffic shaping and SD-WAN, threat protection and content filtering rules, access policies and 802.1X.
  • MS switches: SVI, static and dynamic routing, QoS, access policies and 802.1X, and replicating a switch configuration.
  • MR wireless: SSIDs for enterprise and BYOD deployments, traffic shaping, RF profiles and Air Marshal.
  • SM endpoint management: management profiles, security policies and Sentry for Meraki-managed deployments.
  • MV security cameras: video settings, alerting and retention.
  • MI application assurance: standard applications and application thresholds.

Cross-product patterns worth memorizing

  • 802.1X appears on both MX and MS in the blueprint, and SSID authentication on MR is its wireless sibling. Know the common building blocks (authentication server, policy assignment) and how they carry across products.
  • SVI and routing appear on both MX and MS. Be clear on what a switch virtual interface does and when Layer 3 on the switch is the better choice than routing everything at the appliance.
  • Traffic shaping appears on MX and MR. The concepts (classify, then limit or prioritize) are shared even though the interfaces differ.
  • RF profiles and Air Marshal are wireless-specific: RF profiles tune radio behavior per group of access points, while Air Marshal is about detecting and containing rogue or unwanted wireless activity.
  • Sentry ties endpoint management to network access, so know the idea: managed-device posture influencing what the device may reach.

Key Takeaway

For Implementation, build a one-line answer for each bullet in the blueprint: "what does this object do, and where in Dashboard would I set it?" If you can answer for MX, MS, MR, SM, MV and MI in a sentence each, you have the breadth the domain rewards.

Monitoring and Troubleshooting Essentials (30%)

This is the second 30% domain, and it separates people who have operated Meraki networks from people who only read about them. Questions often present a symptom and ask for the next best diagnostic step or the most likely cause.

Domain 4: Monitoring and Troubleshooting (30%)

Two halves: observing the network and fixing it.

  • Monitoring and reporting: alerts via Dashboard, SNMP, Syslog, NetFlow, and logging and reporting in Dashboard.
  • Dashboard API: how it is used to monitor and maintain networks.
  • Firmware upgrades: how they are managed and what to consider.
  • Troubleshooting: Layer 2 and Layer 3 using Dashboard, wireless client connectivity, device local status pages, security threats using Security Center, and application performance using Meraki Insight.

Telemetry tools: what each is for

  • SNMP: polling-based device and interface metrics into an external monitoring system.
  • Syslog: event and message export to an external collector.
  • NetFlow: flow-level visibility into who is talking to whom and how much.
  • Dashboard alerts and reporting: built-in notifications and summaries without external tooling.
  • Dashboard API: programmatic access for automation, reporting and bulk maintenance.

A troubleshooting sequence that matches the blueprint

  1. Define the scope: one client, one SSID, one switch, one site, or everywhere?
  2. Check the lowest layer first: link and port status, then VLAN and Layer 2 behavior, then addressing and routing.
  3. Use Dashboard tools for the matching layer: client details and event logs for wireless issues, switch port and Layer 3 views for wired issues.
  4. Fall back to the device local status page when Dashboard visibility is limited, such as when a device is struggling to reach the cloud.
  5. Bring in Security Center when the symptom looks like a threat event rather than a configuration fault.
  6. Use Meraki Insight when the complaint is "the application is slow" rather than "the network is down."
Firmware reminder: Firmware questions are rarely about a specific version number. They test process judgment: scheduling upgrades to limit disruption, understanding that upgrades happen per network, and knowing why a staged approach beats upgrading everything at once.

Quick-Reference Comparison Tables

DomainWeightDominant Question StyleReview Emphasis
Cisco Meraki Cloud Management15%Conceptual and comparisonLicensing logic, org structure, permissions scope
Design30%Scenario: pick the right architectureAuto VPN, vMX, path selection, HA, QoS, wireless design
Implementation25%Configuration knowledge by productMX, MS, MR, SM, MV, MI configuration objects
Monitoring and Troubleshooting30%Symptom to diagnosisTelemetry tools, Dashboard diagnostics, Security Center, Insight
Tool or FeatureUse It When
Dashboard alertsYou want built-in notification of device or network events
SNMPAn external monitoring platform must poll device metrics
SyslogEvents must be exported to a central log collector
NetFlowYou need traffic-flow visibility and top-talker analysis
Dashboard APIYou want to automate monitoring or bulk configuration tasks
Security CenterThe symptom suggests a security threat
Meraki InsightUsers report slow or degraded application performance
Device local status pageDashboard cannot give you what you need about a specific device

Common Traps and Look-Alike Concepts

Certification exams reward precision, and the Meraki blueprint contains several pairs of concepts that sound similar but differ in purpose. Review these before test day.

  • Auto VPN versus SD-WAN policies. Auto VPN builds the secure overlay between sites; SD-WAN and path selection policies decide which uplink or path carries which traffic across it.
  • Content filtering versus threat protection. Both are MX security features, but one controls access by category and the other detects malicious activity. Match the feature to the stated goal.
  • RF profiles versus Air Marshal. One tunes radios; the other watches for rogue wireless behavior.
  • Supervised versus device owner enrollment. Both are managed-endpoint concepts tied to different device platforms and levels of control, so be ready to match each to the scenario.
  • Security Center versus Meraki Insight. Threat events versus application performance. They answer different questions.
  • SNMP versus Syslog versus NetFlow. Metrics, events and flows. Three different data types.
  • Enterprise SSID versus BYOD or guest SSID design. Authentication method, isolation and policy differ, so read the requirement before choosing.
Why "related topics may appear" matters: Cisco's blueprint note about related topics means a question can touch on adjacent networking fundamentals such as VLANs, routing behavior and wireless basics. Solid general networking knowledge is a safety net for questions that stretch slightly past the listed bullets.

To gauge how these traps translate into difficulty, read how hard the CMSS exam really is, and to understand how the credential is defined and who it targets, see the CMSS requirements and eligibility overview.

Scheduling Your Review by Domain Weight

If you only have a short window, let the blueprint weights drive your calendar. A compact four-week approach tied to this exam's structure:

Week 1

Cloud Management plus Implementation foundations

  • Cover licensing, co-termination, org structure and permissions quickly (the 15% domain).
  • Start MX and MS configuration objects: SVI, routing, 802.1X, access policies.
Week 2

Design, part one: WAN and network services

  • Auto VPN topologies, vMX, dynamic path selection, HA, QoS for voice and video.
  • Layer 2 security, firewall and IPS rule design, network access control.
Week 3

Design, part two, plus remaining Implementation

  • High-density and guest wireless design; endpoint management enrollment methods.
  • MR (SSIDs, RF profiles, Air Marshal), SM, MV and MI configuration.
Week 4

Monitoring and Troubleshooting, then full review

  • Telemetry tools, Dashboard API, firmware process, Layer 2 and Layer 3 diagnostics.
  • Security Center and Meraki Insight scenarios; timed practice to rehearse the 90-minute limit.

Hands-on time in a Dashboard lab or demo environment is the single best multiplier for Weeks 3 and 4, because Monitoring and Troubleshooting questions are much easier when you have actually seen the client details page, the event log and the local status page. When you are ready to test yourself under realistic conditions, our CMSS practice tests are built around these four domains. For a longer-horizon plan, the full study guide expands this outline.

Who Hires for This Skill Set

The Cisco Meraki Solutions Specialist credential speaks to people who design, deploy and support cloud-managed networks. In practice that includes:

  • Managed service providers and Cisco partners that deploy and operate Meraki for many customers and value verified product skills.
  • Network and systems engineers in multi-site organizations such as retail, education, healthcare and hospitality, where distributed branches benefit from centralized management.
  • Network administrators and support engineers who handle day-to-day monitoring, wireless complaints and firmware maintenance.
  • Pre-sales and solutions engineers who must translate customer requirements into Meraki designs, which maps directly to the Design domain.

For market context, see the overview of CMSS jobs, and for compensation discussion without invented figures, the CMSS salary guide and the ROI analysis walk through the factors that actually move pay.

Frequently Asked Questions

What exam do I take to earn the Cisco Meraki Solutions Specialist credential?

You take Engineering Cisco Meraki Solutions v1.0, exam code 500-220 ECMS, offered by Cisco Systems, Inc. It runs 90 minutes and the current fee is USD 300.

Which domains carry the most weight?

Design and Monitoring and Troubleshooting are each 30%. Implementation is 25%, and Cisco Meraki Cloud Management is 15%. Together, the two 30% domains make up 60% of the blueprint.

How many questions are on the exam and what is the passing score?

The supplied official source material does not state a verified question count or passing score, so this cheat sheet does not guess. Check Cisco's official exam page at booking time, and see our passing score article for more context.

Can the exam topics change?

Yes. Cisco's blueprint states that the topics are general guidelines, that related topics may appear, and that the guidelines may change without notice. Always confirm against the current official topics PDF before your test date.

Where can I find testing dates and scheduling details?

Cisco's official exam page is the authoritative source for registration. For a walkthrough of how scheduling typically works, read our guide to CMSS exam dates and scheduling, and use the CMSS practice test site to rehearse the format beforehand.

Ready to pass your CMSS exam?

Put this into practice with free CMSS questions across every exam domain.