300-430 Exam - Free Actual Q&As, Page 4 - ExamTopics
300-430 Exam - Free Actual Q&As, Page 4 - ExamTopics
com/exams/cisco/300-430/view/4/
A network engineer must segregate all IPads on the guest WLAN to a separate VLAN. How does the engineer accomplish this task without using
Cisco ISE?
In a Cisco WLAN deployment, it is required that all Aps from branch1 remain operational even if the control plane CAPWAP tunnel is down because
of a WAN failure to headquarters. Which operational mode must be con�gured on the APs?
A. disconnected
B. standalone
C. lightweight
D. connected
An engineer added more APs to newly renovated areas in building. The engineer is now receiving Out-of-Sync alarms on Cisco Prime
Infrastructure. Which two actions resolve this issue? (Choose two.)
1 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
A wireless administrator must assess the different client types connected to Cisco Catalyst 9800 Series Wireless Controller without using any
external servers.
Which con�guration must be added to the controller to achieve this assessment?
A. native pro�le
B. MAC classi�cation
C. local pro�le
D. device classi�cation
A customer is concerned that their wireless network is detecting spurious threats from channels that are not being used by their wireless
infrastructure. Which two technologies must they deploy? (Choose two.)
A. FlexConnect mode
B. monitor mode
A network engineer created a new wireless network that will be used for guest access. The corporate network must utilize all rates. The guest
network must use only lower rates instead of 802.11n data rates. To what must the WMM policy of the WLAN be set to accomplish this task?
A. required
B. allowed
C. disabled
D. mandatory
2 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Refer to the exhibit. An engineer implemented the CPU ACL on your Cisco 5520 Series Wireless LAN Controller, and the controller is no longer
manageable via the network. What must be changes on this CPU ACL to enable it to manage the controller again?
A. Permit statements must be added to the top of the ACL in both directions, which specify the network to be managed from and the virtual
interface of the controller.
C. Permit statements must be added to the top of the ACL, which specify the network to be managed from.
A hospital wants to offer indoor directions to patient rooms utilizing its existing wireless infrastructure. The wireless network has been using
location services speci�cations. Which two components must be installed to support this requirement? (Choose two.)
A. WIPS
B. Cisco MSE
3 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
When con�guring a large, high-availability wireless network, which change to a mobility group creates less load on the controllers and maintains
the same mobility messages?
C. Con�gure the controllers into separate RF groups from the mobility groups.
A healthcare organization notices many rogue APs and is concerned about a honeypot attack. Which con�guration must a wireless network
engineer perform in
Cisco Prime Infrastructure to prevent these attacks most e�ciently upon detection?
A. Set the auto containment level to 0 and select the Using Our SSID containment option.
B. Set the manual containment level to 4 and select the Ad Hoc Rogue AP containment option.
C. Set the auto containment level to 0 and select the Ad Hoc Rogue AP containment option.
D. Set the auto containment level to 4 and select the Using Our SSID containment option.
An engineer is con�guring a new wireless network for guest access. The Facebook page of the company must be viewed by the guest users
before they get access to the network. A Cisco MSE is used as a wireless component. Which URL must be used in the con�guration as the external
redirection URL?
A. http://<MSE>:8083/visitor/login.do
B. http://<MSE>:8083/fbwi�/forward
C. http://<MSE>:8084/visitor/login.do
D. http://<MSE>:8084/fbwi�/forward
An IT administrator deployed an OEAP to the home of a remote user, but the OEAP cannot reach the WLC. Which two con�guration settings must
be completed before an OEAP is deployed successfully? (Choose two.)
A. Con�gure Secondary Controller Name and Management IP address in the High Availability tab.
C. Con�gure the AP mode to FlexConnect and check the box for O�ce Extend AP.
E. Con�gure Primary Controller Name and Management IP address in the High Availability tab.
4 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
An IT administrator deploys Cisco 2802i APs in all o�ce locations, including main campus and branch o�ces. The WLC that manages the APs is
located at the data center on the main campus. The APs on the main campus are con�gured to use Local mode and the APs in the branches use
FlexConnect mode. Which con�guration must be applied to the APs for corporate devices on the main campus to be mapped to the local LAN
switch on different VLANs according to the
VLAN tag ID and WLAN?
An engineer is in the process of implementing Fastiane on a wireless network with a Mobility Express AP installed and Apple end-user devices.
Due to a security concern, the IT department has updated all the iPads to version 14.5.423551943. Which QoS pro�le must the engineer con�gure
on the user WLAN?
A. Platinum
B. Best Effort
C. Bronze
D. Silver
An engineer wants to upgrade the APs in a Cisco FlexConnect group. To accomplish this upgrade, the FlexConnect AP Upgrade setting will be
used. One AP of each model with the lowest MAC address in the group must receive the upgrade directly from the controller. Which action
accomplishes this direct upgrade?
5 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Refer to the exhibit. An administrator notices slower location updates from the controller to Cisco CMX. Which command must be con�gured to
get an update every 5 seconds for rogues?
Refer to the exhibit. An engineer is con�guring a Cisco wireless LAN controller and needs wireless multicast to use the 54Mbps rates. Which
action meets this requirement?
6 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
DRAG DROP
-
A network engineer must get an autonomous AP to authenticate to the upstream switch via IEEE 802.1 X. Drag and drop the commands from the
left onto the right to complete the con�guration.
A network administrator managing a Cisco Catalyst 9800 WLC must place all iOS connected devices to the guest SSID on VLAN 101. The rest of
the clients must connect on VLAN 102 distribute load across subnets. To achieve this con�guration, the administrator con�gures a local policy on
the WLC. Which two con�gurations are required? (Choose two.)
An engineer is planning an image upgrade of the WLC, and hundreds of APs are spread across remote sites with limited WAN bandwidth. The
engineer must minimize the WAN utilization for this upgrade. Which approach must be used for the AP image upgrade?
7 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Refer to the exhibit. An engineer con�gured a BYOD policy that allows for printing on the WLAN using Bonjour services. However, the engineer
cannot get printing to work. The WLC �rmware is 8.x. What must be implemented on the controller?
A network administrator just completed the basic implementation of Cisco CMX and tries to implement location tracking. The administrator is
having trouble establishing connectivity between one of the WLCs through NMSP. What must be con�gured to establish this connectivity? (Choose
two.)
B. Allow on the �rewall port 16113 between Cisco CMX and the WLC.
D. Reboot Cisco CMX after adding the WLC for the �rst time.
E. Add to the WLC the MAC address and SSC key for the Cisco CMX server.
8 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Refer to the exhibit. An engineer must provide a position of rogue APs on a �oor map using Cisco PI 3.0, but no rogue AP options are showing on
the left-hand navigation menu under Maps. What is the reason for this omission?
WPA2 Enterprise with 802.1X is being used for clients to authenticate to a wireless network through a Cisco ISE server. For security reasons, the
network engineer wants to ensure that only PEAP authentication is used. The engineer sent instructions to clients on how to con�gure the
supplicants, but the ISE logs still show users authenticating using EAP-FAST. Which action ensures that access to the network is restricted for
these users unless the correct authentication mechanism is con�gured?
A. Enable AAA override on the SSID, gather the usernames of these users, and disable the RADIUS accounts until the devices are correctly
con�gured.
B. Enable AAA override on the SSID and con�gure an ACL on the WLC that allows access to users with IP addresses from a speci�c subnet.
C. Enable AAA override on the SSID and con�gure an access policy in Cisco ISE that denies access to the list of MACs that have used EAP-
FAST.
D. Enable AAA override on the SSID and con�gure an access policy in Cisco ISE that allows access only when the EAP authentication method
is PEAP.
9 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Refer to the exhibit. What is the reason that the wireless client cannot get the RUN state?
D. Because of central switching, the AP must reach the Cisco ISE directly.
A wireless engineer deployed all remote sites as FlexConnect. The client VLAN assignment on these sites is con�gured manually mapped by
WLAN and using local switching. Dynamic VLAN assignment is provided by the newly deployed Cisco ISE. Which IETF attribute must be con�gured
on the AAA server to send that VLAN ID?
A. Tunnel-Medium-Type
B. Tunnel-Client-Endpoint
C. Tunnel-Assignment-ID
D. Tunnel-Private-Group-ID
10 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Refer to the exhibit. An engineer has deployed the Cisco CMX solution to track and detect the number of users who visit the o�ce each day. The
CMX dashboard is not showing any data. Which action resolves this issue?
Refer to the exhibit. A network architect con�gured the Cisco Catalyst 9800 Series Controller to �nd out information on client types in the wireless
network. RADIUS pro�ling is enabled so that the controller forwards the information about clients to a Cisco ISE server through vendor-speci�c
RADIUS attributes. The ISE server is not pro�ling any data from the controller. Which con�guration must be added in the blank in the code to
accomplish the pro�ling on the Cisco 9800 Series controller?
11 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Company XYZ recently migrated from AireOS to IOS XE 9800 WLCs. The Internet bandwidth must be limited to 5 Mbps for each guest client as per
the global standard. In which con�guration on the Cisco Catalyst 9800 WLC must the QoS requirement be added?
A. table map
B. policy map
C. service policy
D. class map
An engineer needs read/write access to rename access points and add them to the correct AP groups on a wireless controller. Using Cisco ISE
TACACS, which custom attributes is the minimum required?
A. role1=WLAN
B. role1=WLAN role2=SECURITY
C. role1=WLAN
role2=WIRELESS
D. role1=WIRELESS
An engineer set up a VoWLAN with QoS on the WLC and a class map on the switch, but the markings are not being preserved correctly in the end-
to-end tra�c �ow. Which two con�gurations on the wired network ensure end-to-end QoS? (Choose two.)
A. trust boundaries
B. access lists
C. policy maps
D. QoS licenses
E. NetFlow
An engineer is in the process of implementing Fastlane on a wireless network with a Mobility Express AP installed. The network must support
voice and video applications for Apple devices. Due to a security concern, all iPhones are updated to version 14.5.432302546. Which QoS pro�le
must the engineer con�gure on the user WLAN?
A. Bronze
B. Best Effort
C. Silver
D. Platinum
12 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Refer to the exhibit. An ACL is con�gured to restrict access for BYOD clients. The ACL must redirect devices to the guest portal. To which two
devices on the local network must the ACL allow access other than the DHCP server? (Choose two.)
A. RADIUS server
B. DNS server
C. Cisco ISE
D. SNMP server
E. WLC
A wireless administrator receives this information to complete a CMX deployment in high availability by using version 10.6 to gather analytics.
Enabling high availability fails when these parameters are used. Which action resolves the issue?
B. Use IP protocol 4242 for the controller to reach the CMX server.
13 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
Which role does an engineer con�gure for administrative access to the wireless infrastructure, using Cisco ISE, to allow con�guration of the WLC
syslog con�guration?
A. MANAGEMENT
B. SECURITY
C. CONTROLLER
D. WIRELESS
Refer to the exhibit. An engineer is troubleshooting a client connectivity issue. The client is in the RUN state, and no tra�c is passed after
authenticating by using Cisco ISE. Which action resolves the problem?
14 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
An engineer is in the process of implementing Fastlane on a wireless network with a Mobility Express AP installed. The network must support
voice and video applications for Apple devices. Due to a security concern, all iPhones are updated to version 14.5.434879777. Which QoS pro�le
must the engineer con�gure on the user WLAN?
A. Bronze
B. Platinum
C. Best Effort
D. Silver
An engineer manages the wireless network for a government agency. The wireless network is used for access to the corporate network. The
wireless network must include the latest wIPS/wIDS detection de�nitions. Which action does the engineer take to ensure that this requirement is
met?
D. Con�gure the Cisco WLC to repoll the Cisco MSE for update de�nitions.
A request has come in to use dynamic VLAN assignment on an autonomous AP. After the AP is con�gured, which RADIUS attribute must an
engineer use to pass the VLAN ID to the AP?
A. Tunnel-Medium-Type
B. Tunnel-Private-Group-ID
C. Tunnel-Assignment-ID
D. Tunnel-Type
An engineer is setting up web authentication for the public Wi-Fi. The installation will take place in a retail store. The existing Facebook page to
log in to the captive portal must be used. The engineer already paired the Cisco MSE to the Facebook page. Which two actions complete the
con�guration? (Choose two.)
15 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
A customer must provide a secure wireless network from a Cisco Catalyst 9800 Series Wireless Controller to a Cisco AP to remote users. The
corporate WLAN must be provided over the Internet to speci�c locations and support a locally-installed IP phone. Which two actions accomplish
this con�guration? (Choose two.)
A network engineer performed a new deployment of Cisco DNA Center. The engineer discovered and provisioned all APs and converted them to
fabric. The SSIDs were created, and the APs were allocated to the respective �oors, but the SSIDs are not being seen on the �oors. What must be
con�gured to establish this connectivity?
As part of a PCI audit, an engineer is gathering information on a Cisco Uni�ed Wireless Network environment. The report must include any security
weaknesses in the system. Where does the engineer �nd the related information?
An engineer deploys APs to a branch o�ce. All AP control and management-related tra�c must be tunneled to a centralized WLC via CAPWAP. All
user tra�c must utilize the local Internet line. What should be con�gured?
16 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
A WLAN on the WLC is con�gured for web authentication as the Layer 3 Security policy with the web-auth type External. Which two elements are
required as part of the con�guration? (Choose two.)
An engineer manages a wireless network for an enterprise. The o�ces of the enterprise are in a multistory building with other companies. To
avoid service loss of the wireless network, jamming devices must be monitored and an alert must be raised when one enters the airspace. Which
two parameters must be con�gured for this alarm to happen? (Choose two.)
More people are working from home, so an engineer must con�gure OEAPs to support the users. The security team already con�gured NAT with a
public IP address that points to the internal WLC IP address. The APs also have been con�gured with the public WLC IP address, but APs cannot
join the controller yet. Which action resolves this issue?
A network engineer is con�guring a Cisco FlexConnect AP to allow Cisco ISE to dynamically assign the subnet of a user based on their
credentials. Which controller mapping must be modi�ed for this feature?
A. WLAN VLAN
B. VLAN ACL
C. RF group
D. AP group
17 of 18 05/10/2024, 9:34 PM
300-430 Exam - Free Actual Q&As, Page 4 | ExamTopics https://www.examtopics.com/exams/cisco/300-430/view/4/
An engineer must implement Video Stream on a Cisco Wireless Network for a single SSID deployment model. Which feature must be enabled on
Cisco Catalyst 9800 Series WLC?
A. Video CAC
B. mDNS Policy
C. IGMP Snooping
D. Multicast Direct
An engineer enabled Cisco Centralized Key Management (CKM) on a WLAN with local and FlexConnect mode APs. The engineer notices that Cisco
CKM is not working for the FlexConnect APs when looking at roaming, but it works for local mode APs. Which change must be made on the
controller for the con�guration to work properly?
18 of 18 05/10/2024, 9:34 PM