Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cisco Implementing Cisco Enterprise Wireless Networks 300-430 Exam Questions

Page: 1 / 19 Total 277 questions

Want more questions? Get Premium Access.

Question 1

A user is trying to connect to a wireless network that is configured for WPA2-Enterprise security using a corporate laptop. The CA certificate for the authentication server has been installed on the Trusted Root Certification Authorities store on the laptop. The user has been prompted to enter the credentials multiple times, but the authentication has not succeeded. What is causing the issue?

Correct Answer: C. There is an invalid 802.1X authentication policy on the authenticator.
Explanation:

The issue described indicates a problem with the 802.1X authentication policy on the authenticator, which is typically the wireless controller or access point. Even though the CA certificate is correctly installed on the laptop, if the authenticator's policy is incorrectly configured or does not match the required settings for the corporate network, the user's authentication attempts will fail. It is essential to review and correct the 802.1X policy settings on the authenticator to resolve this issue.Reference: CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide


Question 2

An engineer is performing a Cisco Hyperlocation accuracy test and executes the cmxloc start command on Cisco CMX. Which two parameters are

relevant? (Choose two.)

Correct Answer: A. X, Y real location; D. client MAC address
Explanation:

When performing a Cisco Hyperlocation accuracy test, the relevant parameters include the X, Y real location and the client MAC address. The X, Y coordinates provide the actual location data needed for the test, while the client MAC address identifies the specific device being located.


Question 3

A customer has Cisco FlexConnect APs in all remote branches and requires zero downtime with the FlexConnect Fault Tolerance feature. Which two configurations must be the same in both controllers to connected clients when the APs switch from primary to backup WLC due to WAN failure? (Choose two.)

Correct Answer: C. WLAN ordering; E. mobility domain

Question 4

A network engineer observes a spike in controller CPU overhead and overall network utilization after multicast is enabled on a controller with 500 APs. Which feature corrects the issue?

Correct Answer: D. unicast AP multicast mode
Explanation:

Enabling unicast AP multicast mode can correct the issue of increased controller CPU overhead and overall network utilization after multicast is enabled. This mode allows the controller to send multicast traffic to the APs as unicast, which is more efficient for the wireless medium and reduces the load on the controller's CPU.


Question 5

Refer to the exhibit.

Refer to the exhibit. A network administrator must migrate a Cisco Catalyst 9800 WLC from local client profiling to RADIUS profiling through Cisco ISE. The engineer must enable RADIUS CoA based on detecting the client type as Windows to update the access policy based on profile detection immediately. Which CoA type configuration must the engineer apply on Cisco ISE?

Correct Answer: B. reauth

Question 6

An engineer is adding APs to an existing VolMLAN to allow for location based services. Which option will the primary change be to the network?

Correct Answer: C. AP footprint
Explanation:

The primary change to the network when adding APs for location-based services, such as VolMLAN, would be theAP footprint. This refers to the physical coverage area of the access points. Increasing the AP footprint enhances the ability to perform location-based services by improving the accuracy oftriangulationandlocation trackingof devices. This is because a denser AP footprint allows for more precise determination of a device's location within the network.Reference: CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide, specifically the sections discussing location-based services and AP deployment strategies for optimal coverage and location tracking.


Question 7

A customer wants to allow employees to easily onboard their personal devices to the wireless network. The visitors also must be able to connect to the same network without the need to engage with anyone from the reception desk. Which process must be configured on Cisco ISE to support this requirement?

Correct Answer: D. self-registration guest portal
Explanation:

To meet the requirement of allowing employees to easily onboard their personal devices and visitors to connect without reception desk intervention, configuring a self-registration guest portal on Cisco ISE is the appropriate solution. This feature enables guests to create their own accounts and gain network access, streamlining the process for both employees' personal devices and visitors.Reference: CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide


Question 8

An engineer has configured the wireless controller to authenticate clients on the employee SSID against Microsoft Active Directory using PEAP authentication.

Which protocol does the controller use to communicate with the authentication server?

Correct Answer: C. RADIUS
Explanation:

When a wireless controller is configured to authenticate clients against Microsoft Active Directory using PEAP (Protected Extensible Authentication Protocol), it uses RADIUS (Remote Authentication Dial-In User Service) as the protocol to communicate with the authentication server. RADIUS is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA) management for users who connect and use a network service.


Question 9

A customer is experiencing performance issues with its wireless network and asks a wireless engineer to provide information about all sources of interference and their impacts to the wireless network over the past few days. Where can the requested information be accessed?

Correct Answer: A. CleanAir reports on Cisco Prime Infrastructure

Question 10

A network engineer is deploying 8865 IP phones with wireless clients connected to them. In order to apply the appropriate QoS, the IP voice traffic needs to be distinguished from client data traffic. Which switch configuration feature must be enabled?

Correct Answer: A. Voice VLAN
Explanation:

The Voice VLAN feature on switches allows the network to distinguish between voice traffic and data traffic from wireless clients connected to IP phones. This is crucial for applying the appropriate QoS to ensure that voice traffic is prioritized over client data traffic.Reference: CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide.


Question 11

A customer must provide a secure wireless network from a Cisco Catalyst 9800 Series Wireless Controller to a Cisco AP to remote users The corporate WLAN must be provided over the Internet to specific locations and support a locally-installed IP phone Which two actions accomplish this configuration? (Choose two )

Correct Answer: D. Enable Office Extend AP on the Flex Profile; E. Configure Remote LAN under the Remote LAN

Question 12

An engineer must configure a Cisco WLC to support Cisco Aironet 600 Series OfficeExtend APs. Which two Layer 2 security options are supported in this environment? (Choose two.)

Correct Answer: B. WPA+WPA2; E. 802.1X
Explanation:

The Cisco Aironet 600 Series OfficeExtend APs support various Layer 2 security options, including WPA+WPA2 and 802.1X. WPA and WPA2 provide secure encryption for wireless data, while 802.1X offers a robust authentication framework. These security options ensure that the wireless network is protected against unauthorized access and data breaches, which is crucial for remote workers connecting to the corporate network.Reference:= CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide


Question 13

A network engineer is implementing a wireless network and is considering deploying a single SSID for device onboarding.

Which option is a benefit of using dual SSIDs with a captive portal on the onboard SSID compared to a single SSID solution?

Correct Answer: B. restrict allowed devices types

Question 14

A customer is concerned that their wireless network is detecting spurious threats from channels that are not being used by their wireless infrastructure. Which two technologies must they deploy? (Choose two.)

Correct Answer: B. monitor mode; D. local mode with WIPS submode
Explanation:

To address concerns about detecting spurious threats from channels not used by the wireless infrastructure, deploying APs in monitor mode (B) and local mode with WIPS submode (D) would be beneficial. Monitor mode allows APs to listen to the wireless spectrum and identify potential threats, while WIPS (Wireless Intrusion Prevention System) submode enhances the ability to detect and mitigate wireless threats.Reference: CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide


Question 15

What is the default IEEE 802.1x AP authentication configuration on a Cisco Catalyst 9800 Series Wireless Controller?

Correct Answer: D. EAP-FAST with CAPWAP DTLS
Explanation:

The default IEEE 802.1x AP authentication configuration on a Cisco Catalyst 9800 Series Wireless Controller is EAP-FAST with CAPWAP DTLS (Option D). This method uses EAP-FAST for authentication within a secure tunnel established by Datagram Transport Layer Security (DTLS) over CAPWAP, which provides both security for authentication credentials and encryption for wireless management frames.Reference:= ( CCNP Enterprise Wireless Design ENWLSD 300-425 and Implementation ENWLSI 300-430 Official Cert Guide )