Cisco 300-375 - Securing Wireless Enterprise Networks Exam
Page: 3 / 14
Total 70 questions
Question #11 (Topic: )
An engineer is configuring a new mobility anchor for a WLAN on the CLI with the config
wlan mobility anchor add 3 10.10.10.10 command, but the command is failing. Which two
conditions must be met to be able to enter this command? (Choose two.)
wlan mobility anchor add 3 10.10.10.10 command, but the command is failing. Which two
conditions must be met to be able to enter this command? (Choose two.)
A. The anchor controller IP address must be within the management interface subnet.
B. The anchor controller must be in the same mobility group.
C. The WLAN must be enabled.
D. The mobility group keepalive must be configured.
E. The indicated WLAN ID must be present on the controller.
Answer: A,B
Question #12 (Topic: )
Which three items must be configured on a Cisco WLC v7.0 to allow implementation of
isolated bonding network? (Choose three.)
isolated bonding network? (Choose three.)
A. RADIUS server IP address
B. DHCP IP address
C. SNMP trap receiver IP address
D. interface name
E. SNMP community name
F. ACL name
Answer: A,D,F
Question #13 (Topic: )
WPA2 Enterprise with 802.1x is being used for clients to authenticate to a wireless network
through an ACS server. For security reasons, the network engineer wants to ensure only
PEAP authentication can be used. The engineer sent instructions to clients on how to
configure their supplicants, but users are still in the ACS logs authentication using EAP-
FAST. Which option describes the most efficient way the engineer can ensure these users
cannot access the network unless the correct authentication mechanism is configured?
through an ACS server. For security reasons, the network engineer wants to ensure only
PEAP authentication can be used. The engineer sent instructions to clients on how to
configure their supplicants, but users are still in the ACS logs authentication using EAP-
FAST. Which option describes the most efficient way the engineer can ensure these users
cannot access the network unless the correct authentication mechanism is configured?
A. Enable AAA override on the SSID, gather the usernames of these users, and disable their RADIUS accounts until they make sure they correctly configured their devices.
B. Enable AAA override on the SSID and configure an access policy in ACS that denies access to the list of MACs that have used EAP-FAST.
C. Enable AAA override on the SSID and configure an access policy in ACS that allows access only when the EAP authentication method is PEAP.
D. Enable AAA override on the SSID and configure an access policy in ACS that puts clients that authenticated using EAP-FAST into a quarantine VLAN.
Answer: D
Question #14 (Topic: )
How many mobility peers can a Cisco Catalyst 3850-MC node have?
A. 8
B. 2
C. 6
D. 16
E. 4
Answer: A
Question #15 (Topic: )
A Cisco WLC has been added to the network and Cisco ISE as a network device, but
authentication is failing. Which configuration within the network device configuration should
be verified?
authentication is failing. Which configuration within the network device configuration should
be verified?
A. shared secret
B. device ID
C. SNMP RO community
D. device interface credentials
Answer: A