ExamGecko
Home Home / Cisco / 300-430

Cisco 300-430 Practice Test - Questions Answers, Page 13

Question list
Search
Search

List of questions

Search

Related questions











A wireless engineer must configure access control on a WLC using a TACACS+ server for a company that is implementing centralized authentication on network devices. Which role value must be configured under the shell profile on the TACACS+ server for a user with read-only permissions?

A.

ADMIN

A.

ADMIN

Answers
B.

MANAGEMENT

B.

MANAGEMENT

Answers
C.

MONITOR

C.

MONITOR

Answers
D.

READ

D.

READ

Answers
Suggested answer: C

The CTO of an organization wants to ensure that all Android devices are placed into a separate VLAN on their wireless network. However, the CTO does not want to deploy ISE. Which feature must be implemented on the Cisco WLC?

A.

WLAN local policy

A.

WLAN local policy

Answers
B.

RADIUS server overwrite interface

B.

RADIUS server overwrite interface

Answers
C.

AAA override

C.

AAA override

Answers
D.

custom AVC profile

D.

custom AVC profile

Answers
Suggested answer: A

Refer to the exhibit.

A wireless engineer has integrated the wireless network with a RADIUS server. Although the configuration on the RADIUS is correct, users are reporting that they are unable to connect. During troubleshooting, the engineer notices that the authentication requests are being dropped. Which action will resolve the issue?

A.

Allow connectivity from the wireless controller to the IP of the RADIUS server.

A.

Allow connectivity from the wireless controller to the IP of the RADIUS server.

Answers
B.

Provide a valid client username that has been configured on the RADIUS server.

B.

Provide a valid client username that has been configured on the RADIUS server.

Answers
C.

Configure the shared-secret keys on the controller and the RADIUS server.

C.

Configure the shared-secret keys on the controller and the RADIUS server.

Answers
D.

Authenticate the client using the same EAP type that has been set up on the RADIUS server.

D.

Authenticate the client using the same EAP type that has been set up on the RADIUS server.

Answers
Suggested answer: C

What must be configured on the Global Configuration page of the WLC for an AP to use 802.1x to authenticate to the wired infrastructure?

A.

local access point credentials

A.

local access point credentials

Answers
B.

RADIUS shared secret

B.

RADIUS shared secret

Answers
C.

TACACS server IP address

C.

TACACS server IP address

Answers
D.

supplicant credentials

D.

supplicant credentials

Answers
Suggested answer: B

For security purposes, an engineer enables CPU ACL and chooses an ACL on the Security > Access Control Lists > CPU Access Control Lists menu. Which kind of traffic does this change apply to as soon as the change is made?

A.

wireless traffic only

A.

wireless traffic only

Answers
B.

wired traffic only

B.

wired traffic only

Answers
C.

VPN traffic

C.

VPN traffic

Answers
D.

wireless and wired traffic

D.

wireless and wired traffic

Answers
Suggested answer: A

Refer to the exhibit.

An engineer is creating an ACL to restrict some traffic to the WLC CPU. Which selection must be made from the direction drop- down list?

A.

It must be Inbound because traffic goes to the WLC.

A.

It must be Inbound because traffic goes to the WLC.

Answers
B.

Packet direction has no significance; it is always Any.

B.

Packet direction has no significance; it is always Any.

Answers
C.

It must be Outbound because it is traffic that is generated from the WLC.

C.

It must be Outbound because it is traffic that is generated from the WLC.

Answers
D.

To have the complete list of options, the CPU ACL must be created only by the CLI.

D.

To have the complete list of options, the CPU ACL must be created only by the CLI.

Answers
Suggested answer: A

An engineer must implement a CPU ACL that blocks web management traffic to the controller, but they also must allow guests to reach a Web Authentication Redirect page. To which IP address is guest client HTTPS traffic allowed for this to work?

A.

DNS server IP

A.

DNS server IP

Answers
B.

controller management IP

B.

controller management IP

Answers
C.

virtual interface IP

C.

virtual interface IP

Answers
D.

client interface IP

D.

client interface IP

Answers
Suggested answer: C

An engineer needs to configure an autonomous AP for 802.1x authentication. To achieve the highest security an authentication server is used for user authentication. During testing, the AP fails to pass the user authentication request to the authentication server. Which two details need to be configured on the AP to allow communication between the server and the AP? (Choose two.)

A.

username and password

A.

username and password

Answers
B.

PAC encryption key

B.

PAC encryption key

Answers
C.

RADIUS IP address

C.

RADIUS IP address

Answers
D.

shared secret

D.

shared secret

Answers
E.

group name

E.

group name

Answers
Suggested answer: C, D

A customer wants the APs in the CEO’s office to have different usernames and passwords for administrative support than the other APs deployed throughout the facility. Which feature must be enabled on the WLC and APs to achieve this goal?

A.

local management users

A.

local management users

Answers
B.

HTTPS access

B.

HTTPS access

Answers
C.

802.1X supplicant credentials

C.

802.1X supplicant credentials

Answers
D.

override global credentials

D.

override global credentials

Answers
Suggested answer: D

An engineer configured a Cisco AireOS controller with two TACACS+ servers. The engineer notices that when the primary TACACS+ server fails, the WLC starts using the secondary server as expected, but the WLC does not use the primary server again until the secondary server fails or the controller is rebooted. Which cause of this issue is true?

A.

Fallback is enabled

A.

Fallback is enabled

Answers
B.

Fallback is disabled

B.

Fallback is disabled

Answers
C.

DNS query is disabled

C.

DNS query is disabled

Answers
D.

DNS query is enabled

D.

DNS query is enabled

Answers
Suggested answer: B
Total 216 questions
Go to page: of 22