Which two restrictions are in place with regards to configuring DNS? (Choose two.)

A. mDNS uses only UDP port 5436 as a destination port.
B. mDNS cannot use UDP port 5353 as the destination port.
C. mDNS is not supported on FlexConnect APs with a locally switched WLAN.
D. Controller software must be newer than 7.0.6+.
E. mDNS is not supported over IPv6.
Correct Answer: CE


A company is collecting the requirements for an on-premises event. During the event, a wireless client connected to a
dedicated WLAN will run a video application that will need to average 300000000 bits per second to function properly.
What is the QoS marketing that needs to be applied to that WLAN?

A. Bronze
B. Platinum
C. Silver
D. Gold
Correct Answer: D


A network engineer has been hired to perform a new MSE implementation on an existing network. The MSE must be
installed in a different network than the Cisco WLC. Which configuration allows the devices to communicate over

A. Allow UDP/16113portonthe central switch.
B. Allow TCP/16666 port on the router.
C. Allow TCP/16113 port on the firewall.
D. Allow UDP/16666 port on the VPN router.
Correct Answer: C AS.html


An engineer is configuring multicast for two WLCs. The controllers are in different physical locations and each handles
around 500 wire clients. How should the CAPWAP multicast group address be assigned during configuration?

A. Each WLC must be assigned a unique multicast group address
B. Each WLC management address must be in the same multicast group
C. Each WLC management address must be in a different multicast group
D. Both WLCs must be assigned the same multicast group address
Correct Answer: C


Branch wireless users report that they can no longer access services from head office but can access services locally at the site. New wireless users can associate with the wireless while the WAN is down. Which three elements (Cisco FlexConnect state, operation mode, and authentication method) are seen in this scenario? (Choose three.)

A. authentication-local/switch-local
B. WPA2 personal
C. authentication-central/switch-central
D. lightweight mode
E. standalone mode
F. WEB authentication
Correct Answer: ABE


Refer to the exhibit.

A network administrator deploys the DHCP profiler service in two ISE servers: and All BYOD
devices connecting to WLAN on VLAN63 have been incorrectly profiled and are assigned as unknown profiled
endpoints. Which action efficiently rectifies the issue according to Cisco recommendations?

A. Nothing needed to be added on the Cisco WLC or VLAN interface. The ISE configuration must be fixed.
B. Disable DHCP proxy on the Cisco WLC.
C. Disable DHCP proxy on the Cisco WLC and run the IP helper-address command under the VLAN interface to point to
DHCP and the two ISE servers.
D. Keep DHCP proxy enabled on the Cisco WLC and define helper-address under the VLAN interface to point to the
two ISE servers.

Correct Answer: C controllers/110865-DHCP- wlc.html


An engineer must implement rogue containment for an SSID. What is the maximum number of APs that should be used for containment?

A. 1
B. 2
C. 3
D. 4
Correct Answer: D


A customer wants Apps in the CEO\\’s office to have different usernames and passwords for administrative support
than the other APs deployed through the facility. Which feature must be enabled on the WLC and Apps to achieve this

A. Override global credentials
B. 802.1X supplicant credentials
C. Local management users
D. HTTPS access
Correct Answer: B


Refer to the exhibit.

An engineer tries to manage the rogues on the Cisco WLC. Based on the configuration, which AP is marked as
malicious by the controller?
A. rogue AP with SSlD admin seen for 4000 seconds and heard at -60 dBm
B. rogue AP with SSID admin seen for 3000 seconds and heard at -70 dBm
C. rogue AP with SSlD admin seen for 4000 seconds and heard at -70 dBm
D. rogue AP with SSID admin seen for 3000 seconds and heard at -60 dBm
Correct Answer: B


A wireless network has been implemented to enable multicast video to be streamed reliably over the wireless link to the wireless users. After a client reports that the video is unable to stream the administrator determines that
the client is connecting a data rate of 12 Mbps and is trying to stream to avoid multicast address on the network. Which two actions must be applied? (Choose two.)

A. Allow RTSP to stream the video due to wireless multicast not using acknowledgments.
B. Allow multicast direct to work correctly and multicast-direct to be enabled globally.
C. Change the WLAN QoS value to Bronze for the WLANs on the controller.
D. Turn off IGMP snooping for all the configured WLANS on the controller.
E. Implement video stream for the multicast video on the controller
Correct Answer: BE


What is the maximum time range that can be viewed on the Cisco DNA Center issues and alarms page?

A. 3 hours
B. 24 hours
C. 3 days
D. 7 days
Correct Answer: D

7 Days is the max, you can select)’


An engineer is following the proper upgrade path to upgrade a Cisco AireOS WLC from version 7.3 to 8.9. Which two
ACLs for Cisco CWA must be configured when upgrading from the specified codes? (Choose two.)

A. Permit UDP any any
B. Permit any DNS any
C. Permit UDP DNS any
D. Permit UDP any DNS
E. Permit any any any
Correct Answer: CD 00.html


All APs are receiving multicast traffic, instead of only the APs that need it. What is the cause of this problem?

A. The multicast group includes all APs
B. The wrong multicast address was used
C. The multicast group is assigned the wrong VLAN
D. Multicast IGMP snooping is not enabled
Correct Answer: D


Refer to the exhibit.

An engineer deployed a Cisco WLC using local EAP. Users who are configured for EAP-PEAP cannot connect to the
network. Based on the local EAP debug controller provided, why is the client unable to connect?

A. The client is failing to accept the certificate.
B. The Cisco WLC is configured for the incorrect date.
C. The user is using invalid credentials.
Correct Answer: A


A network engineer observes a spike in controller CPU overhead and overall network utilization after multicast is
enabled on a controller with 500 APs. Which feature connects the issue?

A. controller IGMP snooping
B. multicast AP multicast mode
C. broadcast forwarding
D. unicast AP multicast mode
Correct Answer: D
Note: The question is about the reason behind the CPU hike, it is not asking the solution for the issue https://

