A user is trying to connect to a wireless network that is configured for WPA2-Enterprise security using a corporate
laptop. The CA certificate for the authentication server has been installed on the Trusted Root Certification Authorities
store on the laptop. The user has been prompted to enter the credentials multiple times, but the authentication has not
succeeded. What is causing the issue?
A. There is an IEEE invalid 802.1X authentication policy on the authentication server.
B. The user Active Directory account is locked out after several failed attempts.
C. There is an invalid 802.1X authentication policy on the authenticator.
D. The laptop has not received a valid IP address from the wireless controller.
Correct Answer: A

The network management team in a large shopping center has detected numerous rogue APs from local coffee shops
that are broadcasting SSIDs. All of these SSIDs have names starting with ATC (for example, ATC302, ATC011, and
ATC566). A wireless network engineer must appropriately classify these SSIDs using the Rogue Rules feature. Drag
and drop the options from the left onto the categories in which they must be used on the right. Not all options are used.
Select and Place:

300-430 exam questions-q2

 Correct Answer:

300-430 exam questions-q2-2


Which two configurations are applied on the WLC to enable multicast, check multicast stream subscriptions, and stream
content only to subscribed clients? (Choose two)
A. Enable IGMP snooping
B. Set the IGMP timeout to 180 seconds
C. Enable broadcast forwarding
D. Enable 802.3x flow control mode.
E. Set the AP multicast to
Correct Answer: AC

A Cisco WLC has been added to the network and Cisco ISE as a network device, but authentication is failing. Which
configuration within the network device configuration should be verified?
A. SNMP RO community
B. device interface credentials
C. device ID
D. shared secret
Correct Answer: D

300-430 exam questions-q4


A wireless engineer must configure access control on a WLC using a TACAS+ server for a company that is
implementing centralized authentication on network devices. Which role must be configured under the shell profile on
the TACAS+ server for a user with ready-only permissions?
Correct Answer: B

An engineer is configuring multicast for wireless for an all-company video meeting on a network using EIGRP and BGP
within a single domain from a single source. Which type of multicast routing should be implemented?
A. Protocol Independent Multicast Dense Mode
B. Source Specific Multicast
C. Multicast Source Discovery Protocol
D. Protocol Independent Multicast Sparse Mode
Correct Answer: D

An engineer must implement rogue containment for an SSID. What is the maximum number of APs that should be used
for containment?
A. 1
B. 2
C. 3
D. 4
Correct Answer: D

300-430 exam questions-q7


An engineer must implement Cisco Identity-Based Networking Services at a remote site using ISE to dynamically assign
groups of users to specific IP subnets. If the subnet assigned to a client is available at the remote site, then traffic must
be offloaded locally, and subnets are unavailable at the remote site must be tunneled back to the WLC. Which feature
meets these requirements?
A. learn client IP address
B. FlexConnect local authentication
C. VLAN-based central switching
D. central DHCP processing
Correct Answer: C

What must be configured on ISE version 2.1 BYOD when using Single SSID?
A. no authentication
C. open authentication
D. 802.1x
Correct Answer: B

300-430 exam questions-q9


An engineer has successfully implemented 10 active RFID tags in an office environment. The tags are not visible when
the location accuracy is tested on the Cisco CMX Detect and Locate window. Which setting on Cisco CMX allows the
engineer to view the tags?
A. Enable hyper location services for RFID.
B. Enable RFID tags in tracking options
C. Enable probing clients for active tags.
D. Define an RFID group globally and add the tags.
Correct Answer: C

The IT manager is asking the wireless team to get a report for all guest user associations during the past two weeks. In
which two formats can Cisco Prime save this report? (Choose two.)
E. plain text
Correct Answer: AB

300-430 exam questions-q11


After looking in the logs, an engineer notices that RRM keeps changing the channels for non-IEEE 802. 11 interferers.
After surveying the area, it has been decided that RRM should not change the channel. Which feature must be enabled
to ignore non-802.11 interference?
A. Avoid Cisco AP Load
B. Avoid Persistent Non-WIFI Interference
C. Avoid Foreign AP Interference
D. Avoid Non-802. 11 Noise
Correct Answer: D

For security purposes, an engineer enables CPU ACL and chooses an ACL on the Security > Access Control Lists >
CPU Access Control Lists menu. Which kind of traffic does this change apply to, as soon as the change is made?
A. wireless traffic only
B. wired traffic only
C. VPN traffic
D. wireless and wired traffic
Correct Answer: D

