ExamGecko
Home Home / Cisco / 300-430

Cisco 300-430 Practice Test - Questions Answers, Page 9

Question list
Search
Search

List of questions

Search

Related questions











A wireless engineer must implement a corporate wireless network for a large company in the most efficient way possible. The wireless network must support 32 VLANs for 300 employees in different departments. Which solution must the engineer choose?

A.

Configure a second WLC to support half of the APs in the deployment.

A.

Configure a second WLC to support half of the APs in the deployment.

Answers
B.

Configure one single SSID and implement Cisco ISE for VLAN assignment according to different user roles.

B.

Configure one single SSID and implement Cisco ISE for VLAN assignment according to different user roles.

Answers
C.

Configure different AP groups to support different VLANs, so that all of the WLANs can be broadcast on both radios.

C.

Configure different AP groups to support different VLANs, so that all of the WLANs can be broadcast on both radios.

Answers
D.

Configure 16 WLANs to be broadcast on the 2.4-GHz band and 16 WLANs to be broadcast on the 5.0-GHz band.

D.

Configure 16 WLANs to be broadcast on the 2.4-GHz band and 16 WLANs to be broadcast on the 5.0-GHz band.

Answers
Suggested answer: B

Which feature on the Cisco Wireless LAN Controller must be present to support dynamic VLAN mapping?

A.

FlexConnect ACL

A.

FlexConnect ACL

Answers
B.

VLAN name override

B.

VLAN name override

Answers
C.

CCKM/OKC

C.

CCKM/OKC

Answers
D.

AAA override

D.

AAA override

Answers
Suggested answer: D

Which three properties are used for client profiling of wireless clients? (Choose three.)

A.

HTTP user agent

A.

HTTP user agent

Answers
B.

DHCP

B.

DHCP

Answers
C.

MAC OUI

C.

MAC OUI

Answers
D.

hostname

D.

hostname

Answers
E.

OS version

E.

OS version

Answers
F.

IP address

F.

IP address

Answers
Suggested answer: A, B, C

Which command set configures a Cisco Catalyst 9800 Series Wireless Controller so that the client traffic enters the network at the AP switch port?

A.

Option A

A.

Option A

Answers
B.

Option B

B.

Option B

Answers
C.

Option C

C.

Option C

Answers
D.

Option D

D.

Option D

Answers
Suggested answer: D

What is the default IEEE 802.1x AP authentication configuration on a Cisco Catalyst 9800 Series Wireless Controller?

A.

EAP-PEAP with 802.1x port authentication

A.

EAP-PEAP with 802.1x port authentication

Answers
B.

EAP-TLS with 802.1x port authentication

B.

EAP-TLS with 802.1x port authentication

Answers
C.

EAP-FAST with CAPWAP DTLS + port authentication

C.

EAP-FAST with CAPWAP DTLS + port authentication

Answers
D.

EAP-FAST with CAPWAP DTLS

D.

EAP-FAST with CAPWAP DTLS

Answers
Suggested answer: C

An engineer must implement rogue containment for an SSID. What is the maximum number of APs that should be used for containment?

A.

1

A.

1

Answers
B.

2

B.

2

Answers
C.

3

C.

3

Answers
D.

4

D.

4

Answers
Suggested answer: D

Explanation:

Reference:

https://www.cisco.com/c/en/us/td/docs/wireless/technology/roguedetection_deploy/Rogue_Detection.html

An engineer is following the proper upgrade path to upgrade a Cisco AireOS WLC from version 7.3 to 8.9. Which two ACLs for Cisco CWA must be configured when upgrading from the specified codes?

(Choose two.)

A.

Permit 0.0.0.0 0.0.0.0 any DNS any

A.

Permit 0.0.0.0 0.0.0.0 any DNS any

Answers
B.

Permit 0.0.0.0 0.0.0.0 UDP DNS any

B.

Permit 0.0.0.0 0.0.0.0 UDP DNS any

Answers
C.

Permit 0.0.0.0 0.0.0.0 UDP any DNS

C.

Permit 0.0.0.0 0.0.0.0 UDP any DNS

Answers
D.

Permit any any any

D.

Permit any any any

Answers
E.

Permit 0.0.0.0 0.0.0.0 UDP any any

E.

Permit 0.0.0.0 0.0.0.0 UDP any any

Answers
Suggested answer: B, C

Explanation:

Reference: https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-web-auth-00.html

CMX Facebook Wi-Fi allows access to the network before authentication. Which two elements are available? (Choose two.)

A.

Allow HTTP traffic only before authentication and block all the traffic.

A.

Allow HTTP traffic only before authentication and block all the traffic.

Answers
B.

Allow all the traffic before authentication and intercept HTTPS only.

B.

Allow all the traffic before authentication and intercept HTTPS only.

Answers
C.

Allow HTTPs traffic only before authentication and block all other traffic.

C.

Allow HTTPs traffic only before authentication and block all other traffic.

Answers
D.

Allow all the traffic before authentication and intercept HTTP only.

D.

Allow all the traffic before authentication and intercept HTTP only.

Answers
E.

Allow SNMP traffic only before authentication and block all the traffic.

E.

Allow SNMP traffic only before authentication and block all the traffic.

Answers
Suggested answer: C, D

Explanation:

Reference: https://www.cisco.com/c/en/us/td/docs/wireless/mse/8-0/CMX_Connect_Engage_Visitor_Connect/Guide/Cisco_CMX_Connect_Engage_Config_Guide_VC/CMX_Facebook_Wi-Fi.html

An engineer is implementing Cisco Identity-Based Networking on a Cisco AireOS controller. The engineer has two ACLs on the controller. The first ACL, named BASE_ACL, is applied to the corporate_clients interface on the WLC, which is used for all corporate clients. The second ACL, named HR_ACL, is referenced by ISE in the Human Resources group policy. What is the resulting ACL when a Human Resources user connects?

A.

HR_ACL appended with BASE_ACL

A.

HR_ACL appended with BASE_ACL

Answers
B.

HR_ACL only

B.

HR_ACL only

Answers
C.

BASE_ACL appended with HR_ACL

C.

BASE_ACL appended with HR_ACL

Answers
D.

BASE_ACL only

D.

BASE_ACL only

Answers
Suggested answer: B

Branch wireless users report that they can no longer access services from head office but can access services locally at the site. New wireless users can associate to the wireless while the WAN is down.

Which three elements (Cisco FlexConnect state, operation mode, and authentication method) are seen in this scenario? (Choose three.)

A.

authentication-local/switch-local

A.

authentication-local/switch-local

Answers
B.

WPA2 personal

B.

WPA2 personal

Answers
C.

authentication-central/switch-central

C.

authentication-central/switch-central

Answers
D.

lightweight mode

D.

lightweight mode

Answers
E.

standalone mode

E.

standalone mode

Answers
F.

WEB authentication

F.

WEB authentication

Answers
Suggested answer: A, B, E
Total 216 questions
Go to page: of 22