Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

300-430 Implementing Cisco Enterprise Wireless Networks (300-430 ENWLSI) Questions and Answers

Questions 4

What are two considerations when deploying a Cisco Hyperlocation? (Choose two.)

Options:

A.

NTP configuration is available, but not recommended.

B.

The Cisco Hyperlocation feature must be enabled only on the wireless LAN controller.

C.

After enabling Cisco Hyperlocation on Cisco CMX, the APs and the wireless LAN controller must be restarted.

D.

The Cisco Hyperlocation feature must be enabled on the wireless LAN controller and Cisco CMX.

E.

If the Cisco CMX server is a VM, a high-end VM is needed for Cisco Hyperlocation deployments.

Buy Now
Questions 5

Refer to the exhibit.

300-430 Question 5

The image shows a packet capture that was taken at the CLI of the Cisco CMX server. It shows UDP traffic from the WLC coming into the server. What does the capture prove?

Options:

A.

The Cisco CMX server receives NetFlow data from the WLC.

B.

The Cisco CMX server receives NMSP traffic from the WLC.

C.

The Cisco CMX server receives SNMP traffic from the WLC.

D.

The Cisco CMX server receives Angle-of-Arrival data from the WLC.

Buy Now
Questions 6

An engineer set up identity-based networking with ISE and configured AAA override on the WLAN. Which two attributes must be used to change the client behavior from the default settings? (Choose two.)

Options:

A.

DHCP timeout

B.

DNS server

C.

IPv6 ACL

D.

DSCP value

E.

multicast address

Buy Now
Questions 7

An engineer must perform a Layer 2 survey for a mining facility. Which type of antenna does the

engineer use in the mine shaft?

Options:

A.

dipole

B.

omnidirectional

C.

patch

D.

internal

Buy Now
Questions 8

An engineer is planning an image upgrade of the WLC, and hundreds of APs are spread across remote sites with limited WAN bandwidth. The engineer must minimize the WAN utilization for this upgrade. Which approach must be used for the AP image upgrade?

Options:

A.

Predownload the new code to the APs.

B.

Use the Smart AP image upgrade feature.

C.

Allow the APs to download their code after WLC reboot.

D.

Execute parallel TFTP code upgrade on the APs via SSH.

Buy Now
Questions 9

An engineer configures a Cisco Aironet 600 Series OfficeExtend AP for a user who works remotely. What is configured on the Cisco WLC to allow the user to print a printer on his home network?

Options:

A.

split tunneling

B.

SE-connect

C.

FlexConnect

D.

AP failover priority

Buy Now
Questions 10

Refer to the exhibit.

300-430 Question 10

An engineer needs to configure location services in an office. The requirement is to use FastLocate and achieve higher locations refresh rates. Which location-based technique should be implemented?

Options:

A.

probe-based

B.

location patterning

C.

data packet-based

D.

angulation

Buy Now
Questions 11

Refer to the exhibit.

300-430 Question 11

A network administrator deploys the DHCP profiler service in two ISE servers: 10.3.10.101 and 10.3.10.102. All BYOD devices connecting to WLAN on VLAN63 have been incorrectly profiled and are assigned as unknown profiled endpoints. Which action efficiently rectifies the issue according to Cisco recommendations?

Options:

A.

Nothing needed to be added on the Cisco WLC or VLAN interface. The ISE configuration must be fixed.

B.

Disable DHCP proxy on the Cisco WLC.

C.

Disable DHCP proxy on the Cisco WLC and run the ip helper-address command under the VLAN interface to point to DHCP and the two ISE servers.

D.

Keep DHCP proxy enabled on the Cisco WLC and define helper-address under the VLAN interface to point to the two ISE servers.

Buy Now
Questions 12

Which component must be integrated with Cisco DNA Center to display the location of a client that is experiencing connectivity issues?

Options:

A.

Cisco Hyperlocation Module

B.

Wireless Intrusion Prevention System

C.

Cisco Connected Mobile Experiences

D.

Cisco Mobility Services Engine

Buy Now
Questions 13

An engineer completes the setup of a two-node Cisco ISE deployment for a guest portal. When testing the portal, the engineer notices that sometimes there is a certificate CN mismatch. Which certificate type helps resolve this issue?

Options:

A.

Public-Signed Root

B.

Public-Signed SAN

C.

Self-Signed Wildcard

D.

Self-Signed Standard

Buy Now
Questions 14

Refer to the exhibit.

300-430 Question 14

An engineer deployed a Cisco WLC using local EAP. Users who are configured for EAP-PEAP cannot connect to the network. Based on the local EAP debug on the controller provided, why is the client unable to connect?

Options:

A.

The client is failing to accept certificate.

B.

The Cisco WLC is configured for the incorrect date.

C.

The Cisco WLC local EAP profile is misconfigured.

D.

The user is using invalid credentials.

Buy Now
Questions 15

An engineer wants to configure WebEx to adjust the precedence and override the QoS profile on the WLAN. Which configuration is needed to complete this task?

Options:

A.

Change the WLAN reserved bandwidth for WebEx

B.

Create an AVC profile for WebEx

C.

Create an ACL for WebEx

D.

Change the AVC application WebEx-app-sharing to mark

Buy Now
Questions 16

300-430 Question 16

Refer to the exhibit. A network administrator must implement a video stream using the multicast-direct feature on a Cisco Catalyst 9800 WLC. After the configuration, the clients should be able to stream video from a multicast source. The APs used are Cisco 9130-AXI. Which two implementations must the engineer perform? (Choose two.)

Options:

A.

Enable multicast routing on VLAN 2631 for the wireless client VLAN.

B.

Enable multicast routing on VLAN 210 for the wireless management VLAN.

C.

Enable IGMP v3 support to support AP lOS-based access points.

D.

Enable IGMP support across multicast hosts, routers, and multilayer switches.

E.

Configure the CAPWAP multicast group address to enable multicast mode on the device.

Buy Now
Questions 17

300-430 Question 17

Refer to the exhibit A network engineer must deploy a configuration to a Cisco Catalyst 9800 WLC to prevent a FlexConnect AP from allowing wireless clients to connect when its Ethernet connection is down Which code snippet must be added to the box in the code to complete the configuration?

300-430 Question 17

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 18

You are configuring the social login for a guest network. Which three options are configurable social connectors in Cisco CMX Visitor Connect? (Chose three)

Options:

A.

Linkedn

B.

Pinterest

C.

Medium

D.

Google+

E.

Facebook

F.

Myspace

Buy Now
Questions 19

A company wants to switch to BYOD to reduce IT support costs for the company. Which option is an impact of BYOD should be considered?

Options:

A.

increased VPN connections

B.

restricted device enforcement

C.

increased phishing attacks

D.

decreased support calls

Buy Now
Questions 20

What must be configured on the Global Configuration page of the WLC for an AP to use 802.1x to authenticate to the wired infrastructure?

Options:

A.

local access point credentials

B.

RADIUS shared secret

C.

TACACS server IP address

D.

supplicant credentials

Buy Now
Questions 21

A corporation is spread across different countries and uses MPLS to connect the offices. The senior management wants to utilize the wireless network for all the employees. To ensure strong connectivity and minimize delays, an engineer needs to control the amount of traffic that is traversing between the APs and the central WLC. Which configuration should be used to accomplish this goal?

Options:

A.

FlexConnect mode with central switching enabled

B.

FlexConnect mode with central authentication

C.

FlexConnect mode with OfficeExtend enabled

D.

FlexConnect mode with local authentication

Buy Now
Questions 22

An engineer wants to upgrade the APs in a Cisco FlexConnect group. To accomplish this upgrade, the FlexConnect AP Upgrade setting will be used. One AP of each model with the lowest MAC address in the group must receive the upgrade directly from the controller. Which action accomplishes this direct upgrade?

Options:

A.

Remove the APs from the group.

B.

Reboot all APs before the upgrade.

C.

Allocate the master APs to different groups.

D.

Do not set any master APs.

Buy Now
Questions 23

A university implemented a Cisco Catalyst Center (formerly DNA Center) solution to help its network administrator resolve Wi-Fi issues that are raised by students. A client dashboard must be used to view, monitor, and troubleshoot the captured data packets. Which feature must be used?

Options:

A.

Intelligent Capture

B.

Packet Sniffer

C.

Packet Capture

D.

Cisco CleanAir

Buy Now
Questions 24

What is characteristic of Multicast mode that affects the wireless network when configured on a Cisco WLC?

Options:

A.

Packet replication is performed on the controller

B.

The controller sends every multicast packet associated APs

C.

Packet replication is performed on the network

D.

The controller sends multicast packets to a user group.

Buy Now
Questions 25

A network administrator managing a Cisco Catalyst 9800-80 WLC must place all iOS connected devices to the guest SSID on VLAN 101. The rest of the clients must connect on VLAN 102 distribute load across subnets. To achieve this configuration, the administrator configures a local policy on the WLC. Which two configurations are required? (Choose two.)

Options:

A.

Assign a policy map under global security policy settings.

B.

Add local profiling policy under global security policy settings.

C.

Create a service template.

D.

Allow HTTP and DHCP profiling under policy map.

E.

Enable device classification on global wireless settings.

Buy Now
Questions 26

An engineer must configure Cisco OEAPs for three executives. As soon as the NAT address is configured on the management interface, it is noticed that the WLC is not responding for APs that are trying to associate to the internal IP management address. Which command should be used to reconcile this?

Options:

A.

config flexconnect office-extend nat-ip-only disable

B.

config network ap-discovery nap-ip-only enable

C.

config flexconnect office-extend nat-ip-only enable

D.

config network ap-discovery nat-ip-only disable

Buy Now
Questions 27

On a branch office deployment, it has been noted that if the FlexConnect AP is in standalone mode and loses connection to the WLC, all clients are disconnected, and the SSID is no longer advertised. Considering that FlexConnect local switching is enabled, which setting is causing this behavior?

Options:

A.

ISE NAC is enabled

B.

802.11r Fast Transition is enabled

C.

Client Exclusion is enabled

D.

FlexConnect Local Auth is disabled

Buy Now
Questions 28

A company has a Cisco wireless solution and uses Cisco ISE to authenticate corporate users using 802.1X. Users must be grouped by endpoints, and a policy profile must be added and then assigned to an identity group. What is the configuration path in the Cisco ISE user interface?

Options:

A.

Policy > Profiling > Profiling Policies > Add

B.

Policy > Policy Elements > Profiling > Add

C.

Policy > Posture > Posture Profile > Add

D.

Policy > Client Provisioning > Client Provisioning Policy > Add

Buy Now
Questions 29

The security learn is concerned about the access to all network devices, including the Cisco WLC. To permit only the admin subnet to have access to management, a CPU ACL is created and applied. However, guest users cannot get to the web portal. What must be configured to permit only admins to have access?

Options:

A.

The guest portal must be configured on the CPU ACLs on the Cisco WLC.

B.

Access to Cisco ISE must be allowed on the pre authentication ACL.

C.

Management traffic from the guest network must be configured on the ACL rules. D. Traffic toward the virtual interface must be permitted.

Buy Now
Questions 30

An engineer configures Cisco CMX. which uses Layer 2 high availability on primary and secondary CMX instances, according to these specifications:

· Primary CMX IP address: 192.168.1.4/24

· Secondary CMX IP address 192 168.4.4/24

· Virtual IP address: 192.168.4.1/24

in testing, the engineer discovers that the failover fails. Which action resolves the issue?

Options:

A.

Place the primary CMX IP address and the virtual IP address in the same subnet

B.

Use a virtual IP address with CMX Layer 3 high availability

C.

Place the primary CMX IP address and the secondary CMX IP address in the same subnet.

D.

Place the primary CMX IP address and the secondary CMX IP address in the same subnet

Buy Now
Questions 31

A network engineer must get an autonomous AP to authenticate to the upstream switch via IEEE 802.1 X. Drag and drop the commands from the left onto the right to complete the configuration.

300-430 Question 31

Options:

Buy Now
Questions 32

An IT department receives a report of a stolen laptop and has information on the MAC address of the laptop. Which two settings must be set on the wireless infrastructure to determine its location? (Choose two.)

Options:

A.

Location History for Clients must be enabled on the MSE.

B.

Client location tracking must be enabled on the MSE.

C.

Location History for Visitors must be enabled on the MSE.

D.

Location History for Rogue APs & Rogue Clients must be enabled on the MSE.

E.

Tracking optimization must be enabled on the WLC.

Buy Now
Questions 33

An engineer must implement intrusion protection on the WLAN. The AP coverage is adequate and on-channel attacks are the primary concern. The building is historic, which makes adding APs difficult. Which AP mode and submode must be implemented?

Options:

A.

AP mode: local, AP submode: none

B.

AP mode: monitor, AP submode: WIPS

C.

AP mode: monitor, AP submode: none

D.

AP mode: local, AP submode: WIPS

Buy Now
Questions 34

Company XYZ recently migrated from AireOS to IOS XE 9800 WLCs. The Internet bandwidth must be limited to 5 Mbps for each guest client as per the global standard. In which configuration on the Cisco Catalyst 9800 WLC must the QoS requirement be added?

Options:

A.

table map

B.

policy map

C.

service policy

D.

class map

Buy Now
Questions 35

When using a Cisco Catalyst 9800 Series Wireless Controller, which statement about AutoQoS is true?

Options:

A.

It has a set of predefined profiles that you cannot modify further

B.

It matches traffic and assigns each matched packet to QoS groups

C.

It automates deployment of wired QoS and makes wireless QoS implementation easier

D.

It allows the output policy map to put specific QoS queues into specific subgroups

Buy Now
Questions 36

You enter the command or a Cisco Catalyst 3850 Series Switch that runs Cisco ISO XE. What does the command do?

Options:

A.

It defines the user identity or the device identity to be validated by the RADIUS server.

B.

It captures information on the length of the authorized session, as well as the bandwidth usage of the client.

C.

It defines the RADIUS server used to track which sessions are still active.

D.

It defines the level of access of the user or the device.

Buy Now
Questions 37

A wireless engineer deployed all remote sites as FlexConnect. The client VLAN assignment on these sites is configured manually mapped by WLAN and using local switching. Dynamic VLAN assignment is provided by the newly deployed Cisco ISE. Which IETF attribute must be configured on the AAA server to send that VLAN ID?

Options:

A.

Tunnel-Medium-Type

B.

Tunnel-Client-Endpoint

C.

Tunnel-Assignment-ID

D.

Tunnel-Private-Group-ID

Buy Now
Questions 38

An engineer has configured the wireless controller to authenticate clients on the employee SSID against Microsoft Active Directory using PEAP authentication.

Which protocol does the controller use to communicate with the authentication server?

Options:

A.

EAP

B.

802.1X

C.

RADIUS

D.

WPA2

Buy Now
Questions 39

After looking in the logs, an engineer notices that RRM keeps changing the channels for non-IEEE 802.11 interferers. After surveying the area, it has been decided that RRM should not change the channel. Which feature must be enabled to ignore non-802.11 interference?

Options:

A.

Avoid Cisco AP Load

B.

Avoid Non-802.11 Noise

C.

Avoid Persistent Non-WiFi Interference

D.

Avoid Foreign AP Interference

Buy Now
Questions 40

An engineer is performing a Cisco Hyperlocation accuracy test and executes the cmxloc start command on Cisco CMX. Which two parameters are

relevant? (Choose two.)

Options:

A.

X, Y real location

B.

client description

C.

AP name

D.

client MAC address

E.

WLC IP address

Buy Now
Questions 41

An engineer is configuring wireless guests using Cisco CWA. When a device connects, it must be redirected to the WebAuth, but this was failing. What must be configured for the device to be redirected correctly?

Options:

A.

Configure the ACL name on the anchor controller

B.

Enabled DHCP option 7.

C.

Remove the CN entry from the SAN

D.

Allow ICMP toward the portal

Buy Now
Questions 42

When implementing self-registration for guest/BYOD devices, what happens when an employee tries to connect four devices to the network at the same time?

Options:

A.

The last device is removed and the newly added device is updated as active device.

B.

The registration is allowed, but only one device is connected at any given time.

C.

All devices are allowed on the network simultaneously.

D.

Purge time dictates how long a device is registered to the portal.

Buy Now
Questions 43

Refer to the exhibit. A network administrator must automate notifications for Security Advisories Data reports on the Cisco Catalyst Center v2.3.7 using the Report notification feature. Preferring a programmable approach over UI/CLI, the administrator decides to create a webhook via the Cisco DNA Center API to send real-time HTTP notifications to an external application. The webhook URL https://example.com/webhook uses HTTPS with a self-signed certificate, which requires a specific configuration in the payload to ensure the webhook functions correctly. Which code snippet must be placed onto the box in the code to complete the Python script that configures the webhook to use the self-signed certificate to extract the Security Advisories Data report?

300-430 Question 43

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 44

What is the Cisco recommended configuration for a Cisco switch port connected to an AP in local mode for optimal voice over WLAN performance with an 8821 wireless phone?

Options:

A.

switchport encapsulation dot1q

switchport mode trunk

mls qos trust device cisco-phone

B.

switchport mode access

mls qos trust device cisco-phone

C.

switchport mode access mls qos trust cos

D.

switchport mode access mls qos trust dscp

Buy Now
Questions 45

A wireless network uses Cisco ISE to implement 802 1x for user authentication and an Active Directory server as a user database After a power outage, the wireless clients cannot connect to the wireless network The ISE log reports a " clock skew " Which action addresses this issue?

Options:

A.

Enter the correct credentials

B.

Restart the ISE service

C.

Install a trusted certificate

D.

Configure NTP

Buy Now
Questions 46

What is the difference between PIM sparse mode and PIM dense mode?

Options:

A.

Sparse mode supports only one switch. Dense mode supports multiswitch networks.

B.

Sparse mode floods. Dense mode uses distribution trees.

C.

Sparse mode uses distribution trees. Dense mode floods.

D.

Sparse mode supports multiswitch networks. Dense mode supports only one switch.

Buy Now
Questions 47

The IT manager is asking the wireless team to get a report for all guest user associations during the past two weeks. In which two formats can Cisco Prime save this report? (Choose two.)

Options:

A.

CSV

B.

PDF

C.

XLS

D.

DOC

E.

plain text

Buy Now
Questions 48

A university campus uses Cisco Catalyst Center and Cisco Spaces to provide indoor wayfinding for students and guests by leveraging the university mobile app. IT administrators notice that location tracking is inaccurate in multistory buildings, especially near staircases and elevators. Upon investigation, they find that overlapping signals from APs on different floors are causing triangulation errors. The IT team already ensured that APs are not placed directly above or below each other. However, the problem persists, and location accuracy remains unreliable near vertical structures. Which action must the IT team take to resolve the issue?

Options:

A.

Increase the maximum allowable client connections per AP to compensate for signal overlap in high-traffic areas.

B.

Enable coverage hole detection and mitigation to address areas with inconsistent signal strength near staircases and elevators.

C.

Adjust AP transmit power and orientation to minimize vertical signal propagation between floors and optimize coverage for horizontal triangulation

D.

Configure all the APs in the building to use the same channel to provide consistent signal coverage across floors.

Buy Now
Questions 49

Refer to the exhibit.

300-430 Question 49

The security team has implemented ISE as an AAA solution for the wireless network. The wireless engineer notices that though clients are able to authenticate successfully, the ISE policies that are designed to place them on different interfaces are not working. Which configuration must be applied in the RADIUS Authentication Settings section from the ISE Network Device page?

Options:

A.

Disable KeyWrap.

B.

Use ASCII for the key input format.

C.

Change the CoA Port.

D.

Correct the shared secret.

Buy Now
Questions 50

300-430 Question 50

Refer to the exhibit. A network administrator must migrate a Cisco Catalyst 9800 WLC from local client profiling to RADIUS profiling through Cisco ISE. The engineer must enable RADIUS CoA based on detecting the client type as Windows to update the access policy based on profile detection immediately. Which CoA type configuration must the engineer apply on Cisco ISE?

Options:

A.

no CoA

B.

reauth

C.

port

D.

bounce

E.

preauth

Buy Now
Questions 51

What two actions must be taken by an engineer configuring wireless Identity-Based Networking for a WLAN to enable VLAN tagging? (Choose two.)

Options:

A.

enable AAA override on the WLAN

B.

create and apply the appropriate ACL to the WLAN

C.

update the RADIUS server attributes for tunnel type 64, medium type 65, and tunnel private group type 81

D.

configure RADIUS server with WLAN subnet and VLAN ID E. enable VLAN Select on the wireless LAN controller and the WLAN

Buy Now
Questions 52

The security policy mandates that only controller web management traffic is allowed from the IT subnet. In testing, an engineer is trying to connect to a WLAN with Web Authentication for guest users, but the page is timing out on the wireless client browser. What is the cause of the issue?

Options:

A.

The implemented CPU ACL on the controller is blocking HTTP/HTTPS traffic from the guest clients.

B.

Web Authentication Redirect is not supported with CPU ACLs.

C.

The DNS server that is configured on the controller is incorrect.

D.

Web Authentication Redirect is supported only with Internet Explorer, and the client is using Google Chrome.

Buy Now
Questions 53

An engineer configures the wireless LAN controller to perform 802.1x user authentication. Which configuration must be enabled to ensure that client devices can connect to the wireless, even when WLC cannot communicate with the RADIUS?

Options:

A.

pre-authentication

B.

local EAP

C.

authentication caching

D.

Cisco Centralized Key Management

Buy Now
Questions 54

Refer to the exhibit.

300-430 Question 54

An engineer must connect a fork lift via a WGB to a wireless network and must authenticate the WGB certificate against the RADIUS server. Which three steps are required for this configuration? (Choose three.)

Options:

A.

Configure the certificate, WLAN, and radio interface on WGB.

B.

Configure the certificate on the WLC.

C.

Configure WLAN to authenticate using ISE.

D.

Configure the access point with the root certificate from ISE.

E.

Configure WGB as a network device in ISE.

F.

Configure a policy on ISE to allow devices to connect that validate the certificate.

Buy Now
Questions 55

An engineer has been hired to implement a way for users to stream video content without having issues on the wireless network. To accomplish this goal, the engineer must set up a reliable way for a Media Stream to work between Cisco FlexConnect APs. Which feature must be enabled to guarantee delivery?

Options:

A.

Unicast Direct

B.

IGMP Direct

C.

Multicast Direct

D.

Multicast-to-Unicast Direct

Buy Now
Questions 56

Refer to the exhibit.

300-430 Question 56

An engineer implemented the CPU ACL on your Cisco 5520 Series Wireless LAN Controller, and the controller is no longer manageable via the network. What must be changes on this CPU ACL to enable it to manage the controller again?

Options:

A.

Permit statements must be added to the top of the ACL in both directions, which specify the network to be managed from and the virtual interface of the controller.

B.

Line 1 must be set to a destination port of HTTP.

C.

Permit statements must be added to the top of the ACL, which specify the network to be managed from.

D.

Line 1 must be set to the inbound direction.

Buy Now
Questions 57

An engineer is implementing profiling for BYOD devices using Cisco ISE. When using a distributed model, which persona must the engineer configure with the profiling service?

Options:

A.

Device Admin Node

B.

Primary Admin Node

C.

Monitor Node

D.

Policy Services Node

Buy Now
Questions 58

A corporation has recently implemented a BYOD policy at their HQ. Which two risks should the security director be concerned about? (Choose two.)

Options:

A.

network analyzers

B.

malware

C.

lost and stolen devices

D.

keyloggers

E.

unauthorized users

Buy Now
Questions 59

A customer is deploying Cisco Catalyst Center (formerly DNA Center) to manage a Cisco Catalyst 9800 Series Wireless Controller Cisco CleanAir is used to address wireless interference Which two configurations must be completed from the Cisco Catalyst Center GUI to manage the interferes? (Choose two )

Options:

A.

Enable Neighbor List Dual Band on the configured WLANs

B.

Disable Persistent Device Propagation in the CleanAir configuration model

C.

Configure the RX SOP threshold to be high

D.

Enable CleanAir Device Reporting in the CleanAir configuration model

E.

The CleanAir configuration model must be applied to a wireless network profile

Buy Now
Questions 60

A user is trying to connect to a wireless network that is configured for WPA2-Enterprise security using a corporate laptop. The CA certificate for the authentication server has been installed on the Trusted Root Certification Authorities store on the laptop. The user has been prompted to enter the credentials multiple times, but the authentication has not succeeded. What is causing the issue?

Options:

A.

There is an IEEE invalid 802.1X authentication policy on the authentication server.

B.

The user Active Directory account is locked out after several failed attempts.

C.

There is an invalid 802.1X authentication policy on the authenticator.

D.

The laptop has not received a valid IP address from the wireless controller.

Buy Now
Questions 61

A company has an existing Cisco wireless solution deployed to a remote branch location with centrally switched control and data traffic. A new solution is needed to locally switch client traffic when Wi-Fi is used. A new SSID that is used only for voice devices must be mapped to an onsite voice VLAN named VLAN 25. Which configuration on the switch interface that connects to the APs meets the requirement?

Options:

A.

switchport mode trunk switch trunk native vlan 25

B.

switchport mode access switchport access vlan 25 switchport access voice vlan 25

switchport mode trunk

C.

switchport trunk allowed vlan add vlan 25

D.

switchport mode access switchport access vlan 25

Buy Now
Questions 62

300-430 Question 62

Refer to the exhibit. A university network administrator notices that wireless guest users consume a significant amount of uplink internet bzjjlwidth in the library, which causes throughput issues on staff SSID. To throttle this bandwidth use, the administrator intends to configure a QoS policy for guests that:

300-430 Question 62

Which class-map configuration must the administrator implement?

300-430 Question 62

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 63

For security purposes, an engineer enables CPU ACL and chooses an ACL on the Security > Access Control Lists > CPU Access Control Lists menu. Which kind of traffic does this change apply to as soon as the change is made?

Options:

A.

wireless traffic only

B.

wired traffic only

C.

VPN traffic

D.

wireless and wired traffic

Buy Now
Questions 64

An enterprise has recently deployed a voice and video solution available to all employees using AireOS controllers. The employees must use this service over their laptops, but users report poor service when connected to the wireless network. The programs that consume bandwidth must be identified and restricted. Which configuration on the WLAN aids in recognizing the traffic?

Options:

A.

NetFlow Monitor

B.

AVC Profile

C.

QoS Profile

D.

Application Visibility

Buy Now
Questions 65

An engineer wants the wireless voice traffic class of service to be used to determine the queue order for packets received, and then have the differentiated services code point set to match when it is resent to another port on the switch. Which configuration is required in the network?

Options:

A.

Platinum QoS configured on the WLAN

B.

WMM set to required on the WLAN

C.

msl qos trust dscp configured on the controller switch port

D.

msl qos trust cos configured on the controller switch port

Buy Now
Questions 66

A controller shows that an AP in your environment is detecting interference, but the AP health score in Cisco DNA Center is unaffected. What are two reasons that Cisco DNA Center is ignoring the interference? (Choose two.)

Options:

A.

The interference is less than or equal to 30% on the 2.4 GHz radio.

B.

The interference is less than or equal to 50% on the 2.4 GHz radio.

C.

Cisco DNA Center includes only Cisco CleanAir interferers in the AP health score.

D.

The interference is less than or equal to 30% on the 5 GHz radio.

E.

Cisco DNA Center does not include interference in the AP health score.

Buy Now
Questions 67

Refer to the exhibit.

300-430 Question 67

An ACL is configured to restrict access for BYOD clients. The ACL must redirect devices to the guest portal. To which two devices on the local network must the ACL allow access other than the DHCP server? (Choose two.)

Options:

A.

RADIUS server

B.

DNS server

C.

Cisco ISE

D.

SNMP server

E.

WLC

Buy Now
Questions 68

A company is collecting the requirements for an on-premises event. During the event, a wireless client connected to a dedicated WLAN will run a video application that will need on average 391595179 bits per second to function properly. What is the QoS marking that needs to be applied to that WLAN?

Options:

A.

Platinum

B.

Gold

C.

Silver

D.

Bronze

Buy Now
Questions 69

Which AP model of the Cisco Aironet Active Sensor is used with Cisco DNA Center?

Options:

A.

1800s

B.

3600e

C.

3800s

D.

4800i

Buy Now
Questions 70

A consulting engineer must migrate the APs from a Cisco 8540 WLC to a Cisco Catalyst 9800-80 WLC. As part of the migration, the engineer is advised to use a policy map as part of the configuration on the Catalyst 9800-80 WLC to mirror the platinum QoS settings on voice WLAN to accommodate CP-840 wireless phones. Which configuration must the engineer implement on the voice WLAN?

300-430 Question 70

300-430 Question 70

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 71

A customer has a distributed wireless deployment model where the WLCs are located in the data centers. Because the file servers are located in the data center, the traffic from the corporate WLAN “Corp-401266017” must go through the controllers, where the guest WLAN “Guest-19283746” traffic must use the local Internet line installed in each office. Which configuration will accomplish this task?

Options:

A.

Disable Local Switching for the corporate and guest WLAN.

B.

Disable Local Switching for the corporate WLAN and enable it for the guest WLAN.

C.

Enable Local Switching for the corporate and guest WLAN.

D.

Enable Local Switching for the corporate WLAN and disable it for the guest WLAN.

Buy Now
Questions 72

An SSID is set up with central web authentication using Cisco ISE The new SSID uses guest tunneling from the foreign controller to the anchor controller. Which device must be configured ISE as the one performing the RADIUS authentication requests for the web authentication method?

Options:

A.

APs

B.

authentication server

C.

anchor controller

D.

foreign controller

Buy Now
Questions 73

A Cisco WLC has been added to the network and Cisco ISE as a network device, but authentication is failing. Which configuration within the network device configuration should be verified?

Options:

A.

SNMP RO community

B.

device interface credentials

C.

device ID

D.

shared secret

Buy Now
Questions 74

An engineer configured a Cisco AireOS controller with two TACACS+ servers. The engineer notices that when the primary TACACS+ server fails, the WLC starts using the secondary server as expected, but the WLC does not use the primary server again until the secondary server fails or the controller is rebooted. Which cause of this issue is true?

Options:

A.

Fallback is enabled

B.

Fallback is disabled

C.

DNS query is disabled

D.

DNS query is enabled

Buy Now
Questions 75

Branch wireless users report that they can no longer access services from head office but can access services locally at the site. New wireless users can associate to the wireless while the WAN is down. Which three elements (Cisco FlexConnect state, operation mode, and authentication method) are seen in this scenario? (Choose three.)

Options:

A.

authentication-local/switch-local

B.

WPA2 personal

C.

authentication-central/switch-central

D.

lightweight mode

E.

standalone mode

F.

WEB authentication

Buy Now
Questions 76

All APs are receiving multicast traffic, instead of only the APs that need it. What is the cause of this problem?

Options:

A.

The multicast group includes all APs

B.

The wrong multicast address was used

C.

The multicast group is assigned the wrong VLAN

D.

Multicast IGMP snooping is not enabled

Buy Now
Questions 77

A network is set up to support wired and wireless clients. Both types must authenticate using 802.1X before connecting to the network. Different types of client authentication must be separated on a Cisco ISE deployment. Which two configuration items achieve this task? (Choose two.)

Options:

A.

device profiles

B.

policy sets

C.

separate networks

D.

policy groups

E.

policy results

Buy Now
Questions 78

A network administrator for a corporation must create a guest SSID for a captive portal redirect powered by Cisco Catalyst Center (formerly DNA Center). The network includes a Cisco Catalyst 9800-80 WLC, Cisco 9130AXI APs, and Cisco Spaces (formerly Cisco DNA Spaces) using a connector. To support guest client captive portal redirect, the administrator must create a security ACL and an intercept ACL. The ACL requirement is:

ACL WA-v4-int34.235.248.212 must be applied first on traffic coming from the client and keep HTTP(s) traffic toward Cisco DNA Spaces portal IP 34.235.248.212 on the data plane. No drop or forward action, just hand the traffic over to the data plane. Then send it to the CPU for redirection except for virtual IP traffic, which is serviced by the web server for all HTTP(s) traffic. Other types of traffic is given to the data plane.

ACL WA-sec-34.235.248.212 must permit HTTP and HTTPS traffic to the Cisco Spaces portal IP 34.235.248.212 that the administrator configured in the web authentication parameter map. DNS and DHCP traffic must be allowed, but drop the rest. HTTP traffic is intercepted before reaching this ACL and therefore does not need to be covered by this ACL.

Which configuration implements the ACL requirements?

300-430 Question 78

300-430 Question 78

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Buy Now
Questions 79

A customer must provide a secure wireless network from a Cisco Catalyst 9800 Series Wireless Controller to a Cisco AP to remote users The corporate WLAN must be provided over the Internet to specific locations and support a locally-installed IP phone Which two actions accomplish this configuration? (Choose two )

Options:

A.

Configure NAT on the physical interface

B.

Enable Local Switching under the WLAN

C.

Create a Flex Group and add the AP

D.

Enable Office Extend AP on the Flex Profile

E.

Configure Remote LAN under the Remote LAN

Buy Now
Questions 80

An engineer must create an account to log in to the CLI of an access point for troubleshooting. Which configuration on the WLC will accomplish this?

Options:

A.

Allow New Telnet Sessions

B.

ReadWrite User Access Mode

C.

SNMP V3 User

D.

Global Configuration Enable Password

Buy Now
Questions 81

Refer to the exhibit.

300-430 Question 81

An engineer needs to manage non-802.11 interference. What is observed in the output on PI?

Options:

A.

At least one strong interferer is impacting connectivity at this site.

B.

Several light interferers are collectively impacting connectivity at this site.

C.

The three individual clusters shown indicate poor AP placement.

D.

RF at this site is unable to provide adequate wireless performance.

Buy Now
Questions 82

An engineer must implement a BYOD policy with these requirements:

Onboarding unknown machines

Easily scalable

Low overhead on the wireless network

Which method satisfies these requirements?

Options:

A.

triple SSID

B.

single SSID

C.

open SSID

D.

dual SSID

Buy Now
Questions 83

Which statement about the VideoStream/Multicast Direct feature is true?

Options:

A.

IP multicast traffic is reliable over WLAN by default as defined by the IEEE 802.11 wireless multicast delivery mechanism.

B.

Each VideoStream client acknowledges receiving a video IP multicast stream.

C.

It converts the unicast frame to a multicast frame over the air.

D.

It makes the delivery of the IP multicast stream less reliable over the air, but reliable over Ethernet.

Buy Now
Exam Code: 300-430
Exam Name: Implementing Cisco Enterprise Wireless Networks (300-430 ENWLSI)
Last Update: May 25, 2026
Questions: 277

PDF + Testing Engine

$65.27   $186.49

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11