ExamGecko
Home Home / Cisco / 300-430

Cisco 300-430 Practice Test - Questions Answers, Page 10

Question list
Search
Search

List of questions

Search

Related questions











Refer to the exhibit.

An engineer deployed a Cisco WLC using local EAP. Users who are configured for EAP-PEAP cannot connect to the network. Based on the local EAP debug on the controller provided, why is the client unable to connect?

A.

The client is failing to accept certificate.

A.

The client is failing to accept certificate.

Answers
B.

The Cisco WLC is configured for the incorrect date.

B.

The Cisco WLC is configured for the incorrect date.

Answers
C.

The Cisco WLC local EAP profile is misconfigured.

C.

The Cisco WLC local EAP profile is misconfigured.

Answers
D.

The user is using invalid credentials.

D.

The user is using invalid credentials.

Answers
Suggested answer: A

An engineer set up identity-based networking with ISE and configured AAA override on the WLAN.

Which two attributes must be used to change the client behavior from the default settings? (Choose two.)

A.

DHCP timeout

A.

DHCP timeout

Answers
B.

DNS server

B.

DNS server

Answers
C.

IPv6 ACL

C.

IPv6 ACL

Answers
D.

DSCP value

D.

DSCP value

Answers
E.

multicast address

E.

multicast address

Answers
Suggested answer: C, D

Refer to the exhibit.

The security team has implemented ISE as an AAA solution for the wireless network. The wireless engineer notices that though clients are able to authenticate successfully, the ISE policies that are designed to place them on different interfaces are not working. Which configuration must be applied in the RADIUS Authentication Settings section from the ISE Network Device page?

A.

Disable KeyWrap.

A.

Disable KeyWrap.

Answers
B.

Use ASCII for the key input format.

B.

Use ASCII for the key input format.

Answers
C.

Change the CoA Port.

C.

Change the CoA Port.

Answers
D.

Correct the shared secret.

D.

Correct the shared secret.

Answers
Suggested answer: C

An engineer is setting up a WLAN to work with a Cisco ISE as the AAA server. The company policy requires that all users be denied access to any resources until they pass the validation. Which component must be configured to achieve this stipulation?

A.

WPA2 passkey

A.

WPA2 passkey

Answers
B.

AAA override

B.

AAA override

Answers
C.

CPU ACL

C.

CPU ACL

Answers
D.

preauthentication ACL

D.

preauthentication ACL

Answers
Suggested answer: B

A Cisco WLC has been added to the network and Cisco ISE as a network device, but authentication is failing. Which configuration within the network device configuration should be verified?

A.

SNMP RO community

A.

SNMP RO community

Answers
B.

device interface credentials

B.

device interface credentials

Answers
C.

device ID

C.

device ID

Answers
D.

shared secret

D.

shared secret

Answers
Suggested answer: D

A user is trying to connect to a wireless network that is configured for WPA2-Enterprise security using a corporate laptop. The CA certificate for the authentication server has been installed on the Trusted Root Certification Authorities store on the laptop. The user has been prompted to enter the credentials multiple times, but the authentication has not succeeded. What is causing the issue?

A.

There is an IEEE invalid 802.1X authentication policy on the authentication server.

A.

There is an IEEE invalid 802.1X authentication policy on the authentication server.

Answers
B.

The user Active Directory account is locked out after several failed attempts.

B.

The user Active Directory account is locked out after several failed attempts.

Answers
C.

There is an invalid 802.1X authentication policy on the authenticator.

C.

There is an invalid 802.1X authentication policy on the authenticator.

Answers
D.

The laptop has not received a valid IP address from the wireless controller.

D.

The laptop has not received a valid IP address from the wireless controller.

Answers
Suggested answer: C

A wireless engineer is configuring LWA using ISE. The customer is a startup company and requested the wireless users to authenticate against a directory, but LDAP is unavailable. Which solution should be proposed in order to have the same security and user experience?

A.

Use SAML.

A.

Use SAML.

Answers
B.

Use the internal database of the RADIUS server.

B.

Use the internal database of the RADIUS server.

Answers
C.

Use a preshared key on the corporate WLAN.

C.

Use a preshared key on the corporate WLAN.

Answers
D.

Use Novell eDirectory.

D.

Use Novell eDirectory.

Answers
Suggested answer: D

An engineer has implemented 802.1x authentication on the wireless network utilizing the internal database of a RADIUS server. Some clients reported that they are unable to connect. After troubleshooting, it is found that PEAP authentication is failing. A debug showed the server is sending an Access- Reject message. Which action must be taken to resolve authentication?

A.

Use the user password that is configured on the server.

A.

Use the user password that is configured on the server.

Answers
B.

Disable the server certificate to be validated on the client.

B.

Disable the server certificate to be validated on the client.

Answers
C.

Update the client certificate to match the user account.

C.

Update the client certificate to match the user account.

Answers
D.

Replace the client certificates from the CA with the server certificate.

D.

Replace the client certificates from the CA with the server certificate.

Answers
Suggested answer: B

A customer wants to allow employees to easily onboard their personal devices to the wireless network. The visitors also must be able to connect to the same network without the need to engage with anyone from the reception desk. Which process must be configured on Cisco ISE to support this requirement?

A.

MAC authentication bypass

A.

MAC authentication bypass

Answers
B.

native supplicant provisioning

B.

native supplicant provisioning

Answers
C.

local web auth

C.

local web auth

Answers
D.

self-registration guest portal

D.

self-registration guest portal

Answers
Suggested answer: D

A customer has a distributed wireless deployment model where the WLCs are located in the data centers. Because the file servers are located in the data center, the traffic from the corporate WLAN “Corp-401266017” must go through the controllers, where the guest WLAN “Guest-19283746” traffic must use the local Internet line installed in each office. Which configuration will accomplish this task?

A.

Disable Local Switching for the corporate and guest WLAN.

A.

Disable Local Switching for the corporate and guest WLAN.

Answers
B.

Disable Local Switching for the corporate WLAN and enable it for the guest WLAN.

B.

Disable Local Switching for the corporate WLAN and enable it for the guest WLAN.

Answers
C.

Enable Local Switching for the corporate and guest WLAN.

C.

Enable Local Switching for the corporate and guest WLAN.

Answers
D.

Enable Local Switching for the corporate WLAN and disable it for the guest WLAN.

D.

Enable Local Switching for the corporate WLAN and disable it for the guest WLAN.

Answers
Suggested answer: D
Total 216 questions
Go to page: of 22