300-425 exam dumps

300-425 practice question 123 of 324

Designing Cisco Enterprise Wireless Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-425 Question 123

Select 3

A network administrator has noticed unauthorized access points connected to the corporate network. The administrator wants to identify and mitigate these rogue access points using Cisco's wireless infrastructure. Which steps should the administrator take to effectively detect and contain rogue APs?

  1. A

    Enable rogue detection on Cisco wireless controllers and monitor alerts.

  2. B

    Configure the Rogue Location Discovery Protocol (RLDP) to actively detect rogue APs.

  3. C

    Disable SSID broadcasting on all authorized access points to confuse rogue APs.

  4. D

    Use containment policies on the Cisco wireless controller to deactivate rogue APs.

  5. E

    Set up access control lists (ACLs) to block traffic from unauthorized MAC addresses.

  6. F

    Manually scan the corporate environment using a Wi-Fi scanning tool to identify rogue APs.

Show answer and explanation

Correct answers: A, B, D

Explanation

To effectively detect and mitigate rogue APs, administrators should leverage Cisco wireless infrastructure features such as rogue detection and the Rogue Location Discovery Protocol (RLDP). These mechanisms provide automated and efficient methods for identifying rogue APs. Additionally, containment policies on Cisco controllers can disrupt rogue AP functionality by deauthenticating connected clients, which is a proactive mitigation technique. Disabling SSID broadcasting or using ACLs is either ineffective or impractical, and manual scanning is less efficient compared to built-in wireless security mechanisms.

  • A. Correct.

    Enabling rogue detection on Cisco wireless controllers is a critical step to automatically identify rogue APs and receive alerts in real-time.

  • B. Correct.

    The Rogue Location Discovery Protocol (RLDP) is a Cisco-specific feature designed to detect rogue APs by attempting to communicate with them and identify their connection to the corporate network.

  • C. Incorrect.

    Disabling SSID broadcasting on authorized APs does not prevent rogue APs from appearing and does not contribute to detecting or mitigating the threat.

  • D. Correct.

    Using containment policies allows Cisco wireless controllers to send deauthentication frames to rogue APs, effectively disrupting their functionality.

  • E. Incorrect.

    Setting up ACLs to block traffic from unauthorized MAC addresses is not a scalable or practical approach for rogue AP management, as rogue APs can spoof MAC addresses.

  • F. Incorrect.

    While manual scanning can identify rogue APs, it is time-consuming and inefficient compared to automated detection systems integrated into Cisco wireless infrastructure.

Timed practice exam

Take a 300-425 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam