Advanced location services
Security for client connectivity
Device hardening

Cisco 300-430 Exam Information

300-430 is the Implementing Cisco Enterprise Wireless Networks exam code, ENWLSI is the abbreviated name for the Implementing Cisco Enterprise Wireless Networks exam, see below for more information:

Vendor: Cisco
Exam Code: 300-430
Exam Name: Implementing Cisco Enterprise Wireless Networks (ENWLSI)
Certification: CCNP Enterprise
Duration: 90 minutes
Languages: English and Japanese
Price: $300 USD

Exam Core:

  • FlexConnect
  • QoS
  • Multicast
  • Advanced location services
  • Security for client connectivity
  • Monitoring
  • Device hardening

Read 300-430 ENWLSI Free Dumps First

Question 1:


The network management team in a large shopping center has detected numerous rogue APs from local coffee shops that are broadcasting SSIDs. All of these SSIDs have names starting with ATC (for example, ATC302, ATC011, and ATC566). A wireless network engineer must appropriately classify these SSIDs using the Rogue Rules feature. Drag and drop the options from the left onto the categories in which they must be used on the right. Not all options are used.

Select and Place:

Correct Answer:

Question 2:

A wireless engineer must implement a corporate wireless network for a large company in the most efficient way possible. The wireless network must support 32 VLANs for 300 employees in different departments. Which solution must the engineer choose?

A. Configure a second WLC to support half of the APs in the deployment.

B. Configure one single SSID and implement Cisco ISE for VLAN assignment according to different user roles.

C. Configure different AP groups to support different VLANs, so that all of the WLANs can be broadcast on both radios.

D. Configure 16 WLANs to be broadcast on the 2.4-GHz band and 16 WLANs to be broadcast on the 5.0- GHz band.

Correct Answer: B

Question 3:

A corporation has recently implemented a BYOD policy at their HQ. Which two risks should the security director be concerned about? (Choose two.)

A. network analyzers

B. malware

C. lost and stolen devices

D. keyloggers

E. unauthorized users

Correct Answer: BC

https://ccbtechnology.com/byod-5-biggest-security-risks/ https://blogs.cisco.com/security/byod-many-call-it-bring-your-own-malware-byom

Question 4:

Which two restrictions are in place with regards to configuring mDNS? (Choose two.)

A. mDNS uses only UDP port 5436 as a destination port.

B. mDNS cannot use UDP port 5353 as the destination port.

C. mDNS is not supported on FlexConnect APs with a locally switched WLAN.

D. Controller software must be newer than 7.0.6+.

E. mDNS is not supported over IPv6.

Correct Answer: CE

Question 5:

An engineer configures the wireless LAN controller to perform 802.1x user authentication. Which configuration must be enabled to ensure that client devices can connect to the wireless, even when WLC cannot communicate with the RADIUS?

A. pre-authentication

B. local EAP

C. authentication caching

D. Cisco Centralized Key Management

Correct Answer: B

Question 6:

Which QoS level is recommended for guest services?

A. gold

B. bronze

C. platinum

D. silver

Correct Answer: B

Question 7:

Which two statements about the requirements for a Cisco Hyperlocation deployment are true? (Choose two.)

A. After enabling Cisco Hyperlocation on Cisco CMX, the APS, and the wireless LAN controller must be restarted.

B. NTP can be configured, but that is not recommended.

C. The Cisco Hyperlocation feature must be enabled on the wireless LAN controller and Cisco CMX.

D. The Cisco Hyperlocation feature must be enabled only on the wireless LAN controller.

E. If the Cisco CMX server is a VM, a high-end VM is needed for Cisco Hyperlocation deployments.

Correct Answer: CE

https://www.cisco.com/c/en/us/products/collateral/wireless/mobility-services-engine/datasheet-c78- 734648.html

Question 8:

An engineer must use Cisco AVC on a Cisco WLC to prioritize Cisco IP cameras that use the wireless network. Which element do you configure in a rule?

A. permit-ACL

B. WMM required

C. mark

D. rate-limit

Correct Answer: C

Question 9:

An engineer wants to configure WebEx to adjust the precedence and override the QoS profile on the WLAN. Which configuration is needed to complete this task?

A. Change the WLAN reserved bandwidth for WebEx

B. Create an AVC profile for WebEx

C. Create an ACL for WebEx

D. Change the AVC application WebEx-app-sharing to mark

Correct Answer: B


Question 10:

Which three properties are used for client profiling of wireless clients? (Choose three.)

A. HTTP user agent



D. hostname

E. OS version

F. IP address

Correct Answer: ABC

Reference: https://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/7-5/NativeProfiling75.html

Question 11:

Which command set configures a Cisco Catalyst 9800 Series Wireless Controller so that the client traffic enters the network at the AP switch port?

A. Option A

B. Option B

C. Option C

D. Option D

Correct Answer: D

Note: To enable Local switching, you have to disable central switching

Question 12:

What is the difference between PIM sparse mode and PIM dense mode?

A. Sparse mode supports only one switch. The dense mode supports multiswitch networks.

B. Sparse mode floods. The dense mode uses distribution trees.

C. Sparse mode uses distribution trees. Dense mode floods.

D. Sparse mode supports multiswitch networks. The dense mode supports only one switch.

Correct Answer: C

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipmulti_pim/configuration/xe-16/imc-pim-xe-16-book/ imc-tech-oview.html

Question 13:

Refer to the exhibit.

Which two items must be supported on the VoWLAN phones to take full advantage of this WLAN configuration? (Choose two.)



C. 802.11e



Correct Answer: CD

Question 14:

A user is trying to connect to a wireless network that is configured for WPA2-Enterprise security using a corporate laptop. The CA certificate for the authentication server has been installed on the Trusted Root Certification Authorities store on the laptop. The user has been prompted to enter the credentials multiple times, but the authentication has not succeeded. What is causing the issue?

A. There is an IEEE invalid 802.1X authentication policy on the authentication server.

B. The user Active Directory account is locked out after several failed attempts.

C. There is an invalid 802.1X authentication policy on the authenticator.

D. The laptop has not received a valid IP address from the wireless controller.

Correct Answer: A

https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_199/Dot1X_Deploy ment/ Dot1x_Dep_Guide.html

Question 15:

A new MSE with wIPS service has been installed and no alarm information appears to be reaching the MSE from controllers. Which protocol must be allowed to reach the MSE from the controllers?





Correct Answer: B

https://www.cisco.com/c/en/us/td/docs/wireless/mse/7-6/MSE_wIPS/MSE_wIPS_7_6/ MSE_wIPS_7_5_chapter_01000.html


