What must be configured on ISE version 2.1 BYOD when using Single SSID?
A.
no authentication
B.
WPA2
C.
open authentication
D.
802.1x
WPA2
An engineer completed the basic installation for two Cisco CMX servers and is in the
process of configuring high availability, but it fails. Which two statements about the root of
the issue are true? (Choose two.)
A.
The Cisco CMX instances are installed in the same subnet.
B.
The types of the primary and secondary Cisco CMX installations differ.
C.
The delay between the primary and secondary instance is 200 ms.
D.
The sizes of the primary and secondary Cisco CMX installations differ.
E.
Both Cisco CMX installations are virtual
The types of the primary and secondary Cisco CMX installations differ.
The sizes of the primary and secondary Cisco CMX installations differ.
Explanation:
https://www.cisco.com/c/en/us/td/docs/wireless/mse/106/cmx_config/b_cg_cmx106/managi
ng_cisco_cmx_system_settings.html
A user is trying to connect to a wireless network that is configured for WPA2-Enterprise
security using a corporate laptop. The CA certificate for the authentication server has been
installed on the Trusted Root Certification Authorities store on the laptop. The user has
been prompted to enter the credentials multiple times, but the authentication has not
succeeded. What is causing the issue?
A.
There is an IEEE invalid 802.1X authentication policy on the authentication server.
B.
The user Active Directory account is locked out after several failed attempts.
C.
There is an invalid 802.1X authentication policy on the authenticator.
D.
The laptop has not received a valid IP address from the wireless controller.
There is an IEEE invalid 802.1X authentication policy on the authentication server.
https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_199/Dot1X_
Deployment/Dot1x_Dep_Guide.html
The security learn is concerned about the access to all network devices, including the
Cisco WLC. To permit only the admin subnet to have access to management, a CPU ACL
is created and applied. However, guest users cannot get to the web portal. What must be
configured to permit only admins to have access?
A.
The guest portal must be configured on the CPU ACLs on the Cisco WLC.
B.
Access to Cisco ISE must be allowed on the pre authentication ACL.
C.
Management traffic from the guest network must be configured on the ACL rules.
D.
Traffic toward the virtual interface must be permitted.
Management traffic from the guest network must be configured on the ACL rules.
An IT team is growing quickly and needs a solution for management device access. The
solution must authenticate users from an external repository instead of the current local on
the WLC, and it must also identify the user and determine what level of access users
should have. Which protocol do you recommend to achieve these goals?
A.
network policy server
B.
RADIUS
C.
TACACS+
D.
LDAP
TACACS+
https://www.cisco.com/c/en/us/td/docs/switches/lan/Denali_161/ConfigExamples_Technote
s/Techzone_Articles/Example_and_Technotes_Denali_16_1_1/Example_and_Technotes_
Denali_16_1_1_chapter_010110.pdf
An engineer must implement rogue containment for an SSID. What is the maximum
number of APs that should be used for containment?
A.
1
B.
2
C.
3
D.
4
4
An engineer wants to configure WebEx to adjust the precedence and override the QoS
profile on the WLAN.
Which configuration is needed to complete this task?
A.
Change the WLAN reserved bandwidth for WebEx
B.
Create an AVC profile for WebEx
C.
Create an ACL for WebEx
D.
Change the AVC application WebEx-app-sharing to mark
Create an AVC profile for WebEx
A network engineer has been hired to perform a new MSE implementation on an existing
network. The MSE must be installed in a different network than the Cisco WLC. Which
configuration allows the devices to communicate over NMSP?
A.
Allow UDP/16113portonthe central switch.
B.
Allow TCP/16666 port on the router.
C.
Allow TCP/16113 port on the firewall.
D.
Allow UDP/16666 port on the VPN router.
Allow TCP/16113 port on the firewall.
What is the difference between PIM sparse mode and PIM dense mode?
A.
Sparse mode supports only one switch. Dense mode supports multiswitch networks.
B.
Sparse mode floods. Dense mode uses distribution trees.
C.
Sparse mode uses distribution trees. Dense mode floods.
D.
Sparse mode supports multiswitch networks. Dense mode supports only one switch
Sparse mode uses distribution trees. Dense mode floods.
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipmulti_pim/configuration/xe-16/imc-pimxe-
16-book/imc-tech-oview.html
Which three characteristics of a rogue AP pose a high security risk? (Choose three.)
A.
open authentication
B.
high RSSI
C.
foreign SSID
D.
accepts clients
E.
low RSSI
F.
distant location
open authentication
foreign SSID
accepts clients
https://www.cisco.com/c/en/us/td/docs/wireless/controller/74/configuration/guides/consolida
ted/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010111001.html
A company has a single WLAN configured for 802.1x authentication with the QoS set to
Silver. This WLAN supports all corporate and BYOD access. A decision has been made to
allow users to install Cisco Jabber on their personal mobile devices. Users report poor
voice quality when using Jabber. QoS is being applied only as best effort. What must be
configured to ensure that the WLAN remains on the Silver class and to ensure Platinum
class for Jabber?
A.
Configure an AVC profile for the Jabber traffic and apply it to the WLAN.
B.
Configure the WLAN to broadcast on 5 GHz radios only and allow Jabber users to
conned.
C.
Enable Cisco Centralized Key Management on the WLAN so that the Jabber-enabled
devices will connect.
D.
Configure QoS on the mobile devices that have Jabber installed
Configure an AVC profile for the Jabber traffic and apply it to the WLAN.
Which three properties are used for client profiling of wireless clients? (Choose three.)
A.
HTTP user agent
B.
DHCP
C.
MAC OUI
D.
hostname
E.
OS version
F.
IP address
HTTP user agent
DHCP
MAC OUI
Reference: https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/7-
5/NativeProfiling75.html
| Page 5 out of 24 Pages |
| 12345678 |
| 300-430 Practice Test Home |
Real-World Scenario Mastery: Our 300-430 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.
Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Implementing Cisco Enterprise Wireless Networks (ENWLSI) exam day arrives.
Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive 300-430 practice exam questions pool covering all topics, the real exam feels like just another practice session.