Free 300-430 Practice Test Questions 2026

277 Questions


Last Updated On : 17-Aug-2026


A customer is experiencing performance issues with its wireless network and asks a wireless engineer to provide information about all sources of interference and their impacts to the wireless network over the past few days. Where can the requested information be accessed?


A. CleanAir reports on Cisco Prime Infrastructure


B. Performance reports on Cisco Prime Infrastructure


C. Interference Devices reports on Cisco Wireless LAN Controller


D. Air Quality reports on Cisco Wireless LAN Controller





A.
  CleanAir reports on Cisco Prime Infrastructure

Explanation:

To review historical interference information, you need a centralized management system that aggregates and stores this data. The CleanAir reports on Cisco Prime Infrastructure (PI) are specifically designed for this purpose .

The Cisco CleanAir system, which is built into supported access points and controllers, can identify and categorize non-Wi-Fi interference sources like microwave ovens and Bluetooth devices . A key feature of this solution is its ability to track and locate these sources historically, not just in real-time . Prime Infrastructure provides the reporting interface to access this archived data, enabling you to view interference sources and their impact on wireless network performance over a specified period, such as the requested "past few days" .

Why the others are wrong:

B. Performance reports on Cisco Prime Infrastructure:
This is a general report category that focuses on network health metrics like AP utilization, client count, and throughput . It does not provide the specialized, categorized information about RF interference sources that CleanAir reports do.

C. Interference Devices reports on Cisco Wireless LAN Controller:
The WLC GUI provides a "Cisco CleanAir" menu where you can view current, active interference devices . However, this is primarily a real-time view. It lacks the robust, historical archiving and reporting capabilities that Prime Infrastructure offers .

D. Air Quality reports on Cisco Wireless LAN Controller:
Similar to the Interference Devices report, you can view the current Air Quality Index (AQI) on a WLC . This is a live metric that shows the impact of noise on RF channel quality . It is not designed to provide a comprehensive historical report spanning multiple days.

References:

Cisco Prime Infrastructure User Guide: Report generation and management sections.
Cisco CleanAir Deployment Guide: Historical data and Prime Infrastructure integration.
Cisco Wireless LAN Controller Configuration Guide: Real-time CleanAir information.

An engineer configured a Cisco AireOS controller with two TACACS+ servers. The engineer notices that when the primary TACACS+ server fails, the WLC starts using the secondary server as expected, but the WLC does not use the primary server again until the secondary server fails or the controller is rebooted. Which cause of this issue is true?


A. Fallback is enabled


B. Fallback is disabled


C. DNS query is disabled


D. DNS query is enabled





B.
  Fallback is disabled

Explanation:

The issue you've described is the classic behavior of a controller configured for failover only, with the fallback feature disabled.

In this "failover only" mode, the WLC is designed to switch to a backup server only when the primary is unreachable. It will continue to use that secondary server indefinitely, even after the primary server becomes available again, until the secondary also fails or the controller is rebooted .

The feature that resolves this is fallback. When enabled, fallback allows the WLC to periodically check if the primary server is back online and, if so, gracefully switch back to it. The problem you're observing is the direct result of this fallback function being turned off .

Why the others are wrong:

A. Fallback is enabled: This would cause the exact opposite behavior. If fallback were enabled, the controller would attempt to revert to the primary server once it's available again.

C. DNS query is disabled & D. DNS query is enabled:
The DNS query option is not related to server failover or fallback. It controls whether the WLC queries DNS to resolve hostnames, not how it handles AAA server redundancy .

References
Cisco TACACS+ Failover and Fallback behavior on WLC .
Cisco AireOS WLC AAA server failover/fallback mechanisms .

On a branch office deployment, it has been noted that if the FlexConnect AP is in standalone mode and loses connection to the WLC, all clients are disconnected, and the SSID is no longer advertised. Considering that FlexConnect local switching is enabled, which setting is causing this behavior?


A. ISE NAC is enabled


B. 802.11r Fast Transition is enabled


C. Client Exclusion is enabled


D. FlexConnect Local Auth is disabled





D.
  FlexConnect Local Auth is disabled

Explanation:

FlexConnect APs are designed to continue servicing clients even when the WAN link to the controller fails. This is known as Standalone Mode. However, their ability to do so depends on how authentication is configured for the WLAN.

For a FlexConnect AP in standalone mode to keep broadcasting an SSID and allow clients to connect, the WLAN must support authentication that can be handled locally on the AP. WLANs using authentication methods like PSK, WPA2-PSK, or with local RADIUS servers can operate this way. The specific setting that enables this fallback capability for 802.1X networks is FlexConnect Local Authentication.

Why the others are wrong:

A. ISE NAC is enabled:
While ISE (NAC) integration is a form of central authentication, simply being enabled does not inherently cause the AP to behave this way. The direct cause is the lack of a local authentication mechanism for the AP to use during a WLC outage.

B. 802.11r Fast Transition is enabled:
Cisco's official documentation confirms that 802.11r Fast Transition (FT) is not supported on FlexConnect APs operating with local authentication in standalone mode. However, enabling FT is a compatibility restriction; it does not directly force the AP to hide the SSID during a WLC outage. In many configurations, the SSID can still be advertised, but roaming may fail.

C. Client Exclusion is enabled:
This is a security feature used to blacklist malfunctioning or malicious clients. It does not control whether the AP advertises its SSID or stays operational when the controller is unavailable.

References:

Cisco FlexConnect Deployment Guide: Standalone mode operation and local authentication requirements.

Which two steps are needed to complete integration of the MSE to Cisco Prime Infrastructure and be able to track the location of clients/rogues on maps? (Choose two.)


A. A. Synchronize access points with the MSE.


B. Add the MSE to Cisco Prime Infrastructure using the CLI credentials.


C. Add the MSE to Cisco Prime Infrastructure using the Cisco Prime Infrastructure communication credentials configured during set up.


D. Apply a valid license for Wireless Intrusion Prevention System.


E. Apply a valid license for location tracking.





C.
  Add the MSE to Cisco Prime Infrastructure using the Cisco Prime Infrastructure communication credentials configured during set up.

E.
  Apply a valid license for location tracking.

Explanation:

Adding MSE via Communication Credentials (Option C):
When integrating the Mobility Services Engine (MSE) into Cisco Prime Infrastructure, the management server connects using the programmatic communication credentials (username, password, and NMSP keys) established during the initial setup script of the MSE appliance, rather than basic Linux shell CLI credentials.

Location Tracking License Requirement (Option E):
To track wireless clients, rogue APs, and rogue clients on Cisco Prime maps, the MSE requires a valid CAS (Context Aware Service) / Location tracking license applied for the total number of tracked endpoints. Without an active location license, the MSE cannot process or render client floor map coordinates.

Why the others are wrong:

A. Synchronize access points with the MSE:
In Prime Infrastructure, administrators synchronize WLCs (Wireless LAN Controllers) and floor maps/services with the MSE. Individual APs are synchronized implicitly via their parent controller sync, not as direct standalone entities.

B. Add the MSE to Cisco Prime Infrastructure using the CLI credentials:
The SSH/Linux CLI root/admin credentials are used for operating system administration, not for establishing programmatic API/SOAP integration between Prime Infrastructure and MSE.

D. Apply a valid license for Wireless Intrusion Prevention System:
A wIPS license is required specifically for tracking and mitigating wireless security threats/attacks via wIPS, but it is not required for standard location tracking of clients and rogues on floor maps.

References

Cisco Prime Infrastructure & MSE Integration Guide: Outlines adding an MSE node using HTTPS API communication credentials and applying Context Aware Location (CAS) licenses to enable client and rogue endpoint positioning on floor plan maps.

Which component must be integrated with Cisco DNA Center to display the location of a client that is experiencing connectivity issues?


A. Cisco Hyperlocation Module


B. Wireless Intrusion Prevention System


C. Cisco Connected Mobile Experiences


D. Cisco Mobility Services Engine





A.
  Cisco Hyperlocation Module

Explanation:

Cisco DNA Center requires integration with an external location engine to display client locations . The component that must be integrated for this functionality is Cisco Connected Mobile Experiences (CMX) .

When CMX is added as an external service and synchronized, Cisco DNA Center queries it for client location data and displays the client's location as a blue dot on the floor map . CMX calculates precise client positions, including for clients experiencing connectivity issues .

Why the others are wrong:

A. Cisco Hyperlocation Module:
This is a hardware feature on APs that enhances location accuracy by providing Angle of Arrival data to the location engine. It is not the engine itself and does not integrate directly with DNA Center.

B. Wireless Intrusion Prevention System (wIPS):
This is a security service for detecting and mitigating wireless threats. It provides no client location capabilities.

D. Cisco Mobility Services Engine (MSE):
This is the older platform for location services that has been superseded by CMX. Cisco's current documentation focuses on CMX integration for client location in DNA Center.

References:
Cisco DNA Assurance User Guide – CMX integration for wireless maps

A network engineer observes a spike in controller CPU overhead and overall network utilization after multicast is enabled on a controller with 500 APs. Which feature connects the issue?


A. controller IGMP snooping


B. multicast AP multicast mode


C. broadcast forwarding


D. unicast AP multicast mode





D.
  unicast AP multicast mode

Explanation:

The performance issue occurs because the WLC is likely operating in unicast AP multicast mode . In this mode, the controller must create a separate, individual copy of every multicast packet for each of the 500 access points, which is a very CPU-intensive process . This is why you see a CPU spike and high network utilization.

To fix this, you should switch to multicast AP multicast mode. In this mode, the controller sends only a single copy of the multicast packet to a CAPWAP multicast group address. The network infrastructure, rather than the WLC's CPU, handles the replication and distribution of this traffic to all APs that have subscribed to the group . This shift in processing responsibility away from the controller resolves the CPU overhead issue and is the recommended configuration for large-scale networks .

Why the others are wrong:

A. controller IGMP snooping:
IGMP snooping optimizes which APs receive the traffic but does not change the fundamental, inefficient "one-copy-per-AP" delivery method of the unicast mode.

C. broadcast forwarding:
This is not related to multicast forwarding at all.

D. unicast AP multicast mode:
This is the current problematic configuration, not the fix. Switching to this mode would be moving in the wrong direction .

References:
Cisco Wireless Controller Configuration Guide
ExamTopics 300-430 Discussion

An engineer is configuring multicast for wireless for an all-company video meeting on a network using EIGRP and BGP within a single domain from a single source. Which type of multicast routing should be implemented?


A. Protocol Independent Multicast Dense Mode


B. Source Specific Multicast


C. Multicast Source Discovery Protocol


D. Protocol Independent Multicast Sparse Mode





D.
  Protocol Independent Multicast Sparse Mode

Explanation:

The scenario involves a single source delivering a video stream to many viewers (an all-company meeting) over a single network domain. PIM Sparse Mode is the most suitable and scalable multicast routing protocol for this environment for the following reasons:

Efficient Traffic Distribution: PIM-SM was specifically designed for "single ASN operation" and uses a "pull model" where traffic is only forwarded to routers that explicitly request it via a Rendezvous Point (RP) . This is in contrast to PIM Dense Mode, which floods traffic to the entire network, creating unnecessary overhead.

Optimal for Single Domain: For deployments within a single domain, PIM-SM is the recommended and widely deployed standard . It is the fundamental mechanism for building distribution trees from the source to receivers.

Support for EIGRP and BGP: PIM is "Protocol Independent," meaning it can use the underlying unicast routing table (populated by protocols like EIGRP and BGP) for its Reverse Path Forwarding (RPF) checks. This flexibility makes PIM-SM a natural choice for networks already using these routing protocols .

Why the others are wrong:

A. PIM Dense Mode: PIM-DM uses a "flood and prune" method, which is inefficient and creates unnecessary traffic overhead, especially for a large, enterprise-wide video meeting . Its operation contrasts with PIM-SM's data-driven, on-demand approach.

B. Source Specific Multicast (SSM): While SSM is a highly efficient model for one-to-many video applications, it is a more advanced deployment that requires IGMPv3 and PIM-SM support . The question's options categorize it as a separate type from PIM-SM, and the most direct, appropriate choice for a single domain is PIM-SM. SSM can be seen as a specific application of PIM-SM, not the routing protocol itself .

References
Exam 300-430 discussion, confirming PIM-SM is the correct answer for this scenario .
Cisco NX-OS Multicast Routing Configuration Guide, outlining PIM-SM operation and the need for a Rendezvous Point (RP) .

Refer to the exhibit

An engineer must connect a fork lift via a WGB to a wireless network and must
authenticate the WGB certificate against the RADIUS server. Which three steps are
required for this configuration? (Choose three.)


A. Configure the certificate, WLAN, and radio interface on WGB.


B. Configure the certificate on the WLC.


C. Configure WLAN to authenticate using ISE.


D. Configure the access point with the root certificate from ISE.


E. Configure WGB as a network device in ISE.


F. Configure a policy on ISE to allow devices to connect that validate the certificate.





A.
  Configure the certificate, WLAN, and radio interface on WGB.

C.
  Configure WLAN to authenticate using ISE.

F.
  Configure a policy on ISE to allow devices to connect that validate the certificate.

Explanation:

WGB Endpoint Setup (Option A):
To perform certificate-based 802.1X authentication (such as EAP-TLS), the Workgroup Bridge (WGB) acts as the supplicant endpoint. The client certificate and trust anchor (CA root certificate) must be installed on the WGB, and the local dot11 radio interface and WLAN configuration must be enabled to present these credentials during association.

WLC RADIUS Delegation (Option C):
The Wireless LAN Controller (WLC) acts as the 802.1X authenticator, relaying Extensible Authentication Protocol (EAP) messages between the WGB supplicant and the authentication server. The target WLAN on the WLC must be configured to point to Cisco ISE as the RADIUS server.

ISE Authentication Policy (Option F):
Cisco ISE acts as the RADIUS server that validates the presented digital certificate against trusted Certificate Authorities (CAs). An Authorization Policy rule must be created in ISE to verify certificate validity, match key attributes (such as Subject Alternative Name or SAN), and grant network access upon successful validation.

Why the others are wrong:

B. Configure the certificate on the WLC:
The 802.1X EAP-TLS transaction occurs directly between the supplicant (WGB) and the EAP server (ISE). The WLC acts purely as a pass-through authenticator and does not require the client or client-CA certificate for this flow.

D. Configure the access point with the root certificate from ISE:
Infrastructure Access Points managed by a WLC do not store client authentication certificates or handle RADIUS EAP transactions locally.

E. Configure WGB as a network device in ISE:
The WLC is configured as the Network Access Device (NAD) in ISE, not the WGB. The WGB connects to the wireless network as an end client/supplicant behind the infrastructure AP.

References:

Cisco Enterprise Mobility Deployment Guide (WGB Configuration): Details EAP-TLS certificate installation on autonomous/WGB radios and configuring Cisco ISE policies to authenticate WGB supplicant credentials.

A FlexConnect remote office deployment is using five 2702i APs indoors and two 1532i APs outdoors. When a code upgrade is performed and FlexConnect Smart AP Image Upgrade is leveraged, but no FlexConnect Master AP has been configured, how many image transfers between the WLC and APs will occur?


A. 1


B. 2


C. 5


D. 7





B.
  2

Explanation:

The FlexConnect Smart AP Image Upgrade feature is designed to optimize software upgrades by minimizing the number of image transfers across the WAN link . It works like a master/slave model, where one AP per model acts as the master to download the new image from the controller and share it with other APs of the same model locally .

Why the others are wrong:

A. 1: This would imply only a single AP model is being upgraded or that a single master AP services all APs. Because you have two distinct AP models and the smart image upgrade feature selects a master per model, there are two transfers from the controller.

C. 5: This number incorrectly assumes a transfer from the controller for each indoor AP. The rest of the 2702i APs would download the image from the master 2702i AP, not directly from the WLC.

D. 7: This would represent a normal upgrade process without the smart image feature, where every AP downloads the image directly from the WLC. The Smart AP Image Upgrade is specifically used to avoid this.

References
Cisco documentation states that one AP per model per FlexConnect group acts as a master to download the image from the WLC .

The slave APs then download the image locally from their respective master AP, not from the WLC .

Which QoS level is recommended for guest services?


A. gold


B. bronze


C. platinum


D. silver





B.
  bronze

Explanation:

The purpose of applying a QoS level to guest services is to ensure that guest traffic does not consume bandwidth needed for critical business applications. Cisco defines four QoS levels with specific priorities and use cases.

The Bronze QoS profile is explicitly designed to provide the lowest bandwidth for guest services. This ensures that guest traffic operates at a "background" priority, preventing it from interfering with more critical traffic such as voice (Platinum), video (Gold), or corporate data (Silver). Why the others are wrong:

D. silver:
This is the default QoS level, designated as "Best Effort" for standard clients. While some documentation may refer to it for guest services in certain contexts, Cisco's official recommendation for guest traffic is to use the lower-bandwidth Bronze profile to minimize impact on business applications.

A. gold:
This profile is reserved for high-priority applications such as video streaming, not for guest access.

C. platinum:
This is the highest-priority profile, intended for real-time applications like voice over IP, and would be inappropriate for guest traffic.

References:

Cisco Wireless Controller Configuration Guide – QoS Profiles: Bronze/Background—Provides the lowest bandwidth for guest services.

Cisco 300-430 ENWLSI Exam Guide – QoS Profile table listing Bronze for guest services.

An engineer is following the proper upgrade path to upgrade a Cisco AireOS WLC from version 7.3 to 8.9. Which two ACLs for Cisco CWA must be configured when upgrading from the specified codes? (Choose two.)


A. Permit 0.0.0.0 0.0.0.0 UDP any any


B. Permit 0.0.0.0 0.0.0.0 any DNS any


C. Permit 0.0.0.0 0.0.0.0 UDP DNS any


D. Permit 0.0.0.0 0.0.0.0 UDP any DNS


E. Permit any any any





C.
  Permit 0.0.0.0 0.0.0.0 UDP DNS any

D.
  Permit 0.0.0.0 0.0.0.0 UDP any DNS

Explanation:

When upgrading a Cisco AireOS WLC from version 7.3 to 8.9, the proper upgrade path requires specific pre-authentication ACL (pre-auth ACL) configurations for Central Web Authentication (CWA). This is due to changes in how the WLC handles DNS redirection between these code versions.

What changes between versions:
In version 7.3 and earlier, the pre-auth ACL needed to permit UDP DNS any traffic (DNS responses from any DNS server to the client).
In version 8.9, the pre-auth ACL must permit UDP any DNS traffic (DNS queries from the client to any DNS server).

Why both are required during upgrade:
During a staged upgrade, the WLC may run intermediate versions or have mixed code levels. To ensure DNS resolution and web authentication redirection work correctly throughout the entire upgrade process, the ACL must permit DNS traffic in both directions:

Permit 0.0.0.0 0.0.0.0 UDP DNS any → Allows DNS responses from the DNS server to the client.
Permit 0.0.0.0 0.0.0.0 UDP any DNS → Allows DNS queries from the client to the DNS server.

These entries are necessary because the pre-authentication ACL must allow clients to resolve the web authentication server's hostname before authentication completes.

Why the others are wrong

A. Permit 0.0.0.0 0.0.0.0 UDP any any:
This is too permissive and allows all UDP traffic, defeating the security purpose of the pre-auth ACL.

B. Permit 0.0.0.0 0.0.0.0 any DNS any:
This uses "any" for the protocol, which is incorrect. The specific protocol is UDP for DNS, not any protocol.

E. Permit any any any:
This is a wildcard permit that bypasses all restrictions, which is not appropriate for a pre-authentication ACL used for CWA.

References:

Cisco AireOS WLC Upgrade Guide – CWA Pre-Authentication ACL requirements for 7.3 to 8.9 upgrades.

Cisco Wireless Controller Configuration Guide – Pre-authentication ACLs for Web Authentication.

Which AP model of the Cisco Aironet Active Sensor is used with Cisco DNA Center?


A. 1800s


B. 3600e


C. 3800s


D. 4800i





A.
  1800s

Explanation:

The Cisco Aironet 1800S Active Sensor is the specific hardware device designed to work with Cisco DNA Center for proactive wireless network monitoring and assurance . The device functions as a compact, simulated wireless client that can be deployed at desktop height (22 to 47 inches from the floor) to accurately replicate real-world user experiences .

When integrated with Cisco DNA Center, the 1800S Active Sensor can run automated tests to measure connectivity, authentication, roaming, application performance, and throughput (supporting iPerf3 and NDT 7) . These sensors are managed through Cisco DNA Assurance and must be provisioned using Plug and Play (PnP) for inventory visibility in DNA Center .

Why Others Are Wrong:

B. 3600e, C. 3800s, D. 4800i:
These are standard access point models designed for client-serving functions, not dedicated active sensors. While the 4800 series may offer active sensor capabilities as a software feature, the explicit dedicated hardware model for this purpose is the 1800S .

References
Cisco Aironet Active Sensor Data Sheet
Cisco Aironet 1800S Active Sensor Release Notes
Cisco Aironet Active Sensor Deployment Guide


Page 6 out of 24 Pages
PreviousNext
23456789
300-430 Practice Test Home

What Makes Our Implementing Cisco Enterprise Wireless Networks (ENWLSI) Practice Test So Effective?

Real-World Scenario Mastery: Our 300-430 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.

Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Implementing Cisco Enterprise Wireless Networks (ENWLSI) exam day arrives.

Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive 300-430 practice exam questions pool covering all topics, the real exam feels like just another practice session.