Exams > Cisco > 300-430: Implementing Cisco Enterprise Wireless Networks (300-430 ENWLSI)
300-430: Implementing Cisco Enterprise Wireless Networks (300-430 ENWLSI)
Page 7 out of 19 pages Questions 61-70 out of 182 questions
Question#61

CMX Facebook Wi-Fi allows access to the network before authentication. Which two elements are available? (Choose two.)

  • A. Allow HTTP traffic only before authentication and block all the traffic.
  • B. Allow all the traffic before authentication and intercept HTTPS only.
  • C. Allow HTTPs traffic only before authentication and block all other traffic.
  • D. Allow all the traffic before authentication and intercept HTTP only.
  • E. Allow SNMP traffic only before authentication and block all the traffic.
Discover Answer Hide Answer

CD
Reference:
https://www.cisco.com/c/en/us/td/docs/wireless/mse/8-0/CMX_Connect_Engage_Visitor_Connect/Guide/
Cisco_CMX_Connect_Engage_Config_Guide_VC/CMX_Facebook_Wi-Fi.html

Question#62

An engineer is implementing Cisco Identity-Based Networking on a Cisco AireOS controller. The engineer has two ACLs on the controller. The first ACL, named
BASE_ACL, is applied to the corporate_clients interface on the WLC, which is used for all corporate clients. The second ACL, named HR_ACL, is referenced by
ISE in the Human Resources group policy. What is the resulting ACL when a Human Resources user connects?

  • A. HR_ACL appended with BASE_ACL
  • B. HR_ACL only
  • C. BASE_ACL appended with HR_ACL
  • D. BASE_ACL only
Discover Answer Hide Answer

B

Question#63

Branch wireless users report that they can no longer access services from head office but can access services locally at the site. New wireless users can associate to the wireless while the WAN is down. Which three elements (Cisco FlexConnect state, operation mode, and authentication method) are seen in this scenario? (Choose three.)

  • A. authentication-local/switch-local
  • B. WPA2 personal
  • C. authentication-central/switch-central
  • D. lightweight mode
  • E. standalone mode
  • F. WEB authentication
Discover Answer Hide Answer

ABE

Question#64


Refer to the exhibit. An engineer deployed a Cisco WLC using local EAP. Users who are configured for EAP-PEAP cannot connect to the network. Based on the local EAP debug on the controller provided, why is the client unable to connect?

  • A. The client is failing to accept certificate.
  • B. The Cisco WLC is configured for the incorrect date.
  • C. The Cisco WLC local EAP profile is misconfigured.
  • D. The user is using invalid credentials.
Discover Answer Hide Answer

A

Question#65

An engineer set up identity-based networking with ISE and configured AAA override on the WLAN. Which two attributes must be used to change the client behavior from the default settings? (Choose two.)

  • A. DHCP timeout
  • B. DNS server
  • C. IPv6 ACL
  • D. DSCP value
  • E. multicast address
Discover Answer Hide Answer

CD

Question#66


Refer to the exhibit. The security team has implemented ISE as an AAA solution for the wireless network. The wireless engineer notices that though clients are able to authenticate successfully, the ISE policies that are designed to place them on different interfaces are not working. Which configuration must be applied in the RADIUS Authentication Settings section from the ISE Network Device page?

  • A. Disable KeyWrap.
  • B. Use ASCII for the key input format.
  • C. Change the CoA Port.
  • D. Correct the shared secret.
Discover Answer Hide Answer

C

Question#67

An engineer is setting up a WLAN to work with a Cisco ISE as the AAA server. The company policy requires that all users be denied access to any resources until they pass the validation. Which component must be configured to achieve this stipulation?

  • A. WPA2 passkey
  • B. AAA override
  • C. CPU ACL
  • D. preauthentication ACL
Discover Answer Hide Answer

B

Question#68

A Cisco WLC has been added to the network and Cisco ISE as a network device, but authentication is failing. Which configuration within the network device configuration should be verified?

  • A. SNMP RO community
  • B. device interface credentials
  • C. device ID
  • D. shared secret
Discover Answer Hide Answer

D

Question#69

A user is trying to connect to a wireless network that is configured for WPA2-Enterprise security using a corporate laptop. The CA certificate for the authentication server has been installed on the Trusted Root Certification Authorities store on the laptop. The user has been prompted to enter the credentials multiple times, but the authentication has not succeeded. What is causing the issue?

  • A. There is an IEEE invalid 802.1X authentication policy on the authentication server.
  • B. The user Active Directory account is locked out after several failed attempts.
  • C. There is an invalid 802.1X authentication policy on the authenticator.
  • D. The laptop has not received a valid IP address from the wireless controller.
Discover Answer Hide Answer

C

Question#70

A wireless engineer is configuring LWA using ISE. The customer is a startup company and requested the wireless users to authenticate against a directory, but
LDAP is unavailable. Which solution should be proposed in order to have the same security and user experience?

  • A. Use SAML.
  • B. Use the internal database of the RADIUS server.
  • C. Use a preshared key on the corporate WLAN.
  • D. Use Novell eDirectory.
Discover Answer Hide Answer

D

chevron rightPrevious Nextchevron right