Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cisco CCNP Enterprise 300-430 Questions and answers with CertsForce

Viewing page 3 out of 9 pages
Viewing questions 21-30 out of questions
Questions # 21:

An engineer has configured passive fallback mode for RADIUS with default timer settings. What will occur when the primary RADIUS fails then recovers?

Options:

A.

RADIUS requests will be sent to the secondary RADIUS server until the secondary fails to respond.


B.

The controller will immediately revert back after it receives a RADIUS probe from the primary server.


C.

After the inactive time expires the controller will send RADIUS to the primary.


D.

Once RADIUS probe messages determine the primary controller is active the controller will revert back to the primary RADIUS.


Expert Solution
Questions # 22:

An engineer is configuring multicast for two WLCs. The controllers are in different physical locations and each handles around 500 wireless clients. How should the CAPWAP multicast group address be assigned during configuration?

Options:

A.

Each WLC must be assigned a unique multicast group address.


B.

Each WLC management address must be in the same multicast group.


C.

Both WLCs must be assigned the same multicast group address.


D.

Each WLC management address must be in a different multicast group.


Expert Solution
Questions # 23:

Question # 23

Refer to the exhibit. A network administrator must migrate a Cisco Catalyst 9800 WLC from local client profiling to RADIUS profiling through Cisco ISE. The engineer must enable RADIUS CoA based on detecting the client type as Windows to update the access policy based on profile detection immediately. Which CoA type configuration must the engineer apply on Cisco ISE?

Options:

A.

no CoA


B.

reauth


C.

port


D.

bounce


E.

preauth


Expert Solution
Questions # 24:

An engineer is setting up a WLAN to work with a Cisco ISE as the AAA server. The company policy requires that all users be denied access to any resources until they pass the validation. Which component must be configured to achieve this stipulation?

Options:

A.

WPA2 passkey


B.

AAA override


C.

CPU ACL


D.

preauthentication ACL


Expert Solution
Questions # 25:

An engineer must create an account to log in to the CLI of an access point for troubleshooting. Which configuration on the WLC will accomplish this?

Options:

A.

Allow New Telnet Sessions


B.

ReadWrite User Access Mode


C.

SNMP V3 User


D.

Global Configuration Enable Password


Expert Solution
Questions # 26:

An engineer is setting up a new unique NAD on a Cisco ISE.

Which two parameters must be configured? (Choose two.)

Options:

A.

device host name


B.

device password


C.

RADIUS fallback


D.

device IP address


E.

RADIUS shared secret


Expert Solution
Questions # 27:

An engineer is configuring wireless guests using Cisco CWA. When a device connects, it must be redirected to the WebAuth, but this was failing. What must be configured for the device to be redirected correctly?

Options:

A.

Configure the ACL name on the anchor controller


B.

Enabled DHCP option 7.


C.

Remove the CN entry from the SAN


D.

Allow ICMP toward the portal


Expert Solution
Questions # 28:

Which two events are outcomes of a successful RF jamming attack? (Choose two.)

Options:

A.

disruption of WLAN services


B.

unauthentication association


C.

deauthentication broadcast


D.

deauthentication multicast


E.

physical damage to AP hardware


Expert Solution
Questions # 29:

CMX Facebook Wi-Fi allows access to the network before authentication. Which two elements are available? (Choose two.)

Options:

A.

Allow HTTP traffic only before authentication and block all the traffic.


B.

Allow all the traffic before authentication and intercept HTTPS only.


C.

Allow HTTPs traffic only before authentication and block all other traffic.


D.

Allow all the traffic before authentication and intercept HTTP only.


E.

Allow SNMP traffic only before authentication and block all the traffic.


Expert Solution
Questions # 30:

An engineer must implement Cisco Identity-Based Networking Services at a remote site using ISE to dynamically assign groups of users to specific IP subnets. If the subnet assigned to a client is available at the remote site, then traffic must be offloaded locally, and subnets are unavailable at the remote site must be tunneled back to the WLC. Which feature meets these requirements?

Options:

A.

learn client IP address


B.

FlexConnect local authentication


C.

VLAN-based central switching


D.

central DHCP processing


Expert Solution
Viewing page 3 out of 9 pages
Viewing questions 21-30 out of questions