300-430 exam dumps

300-430 practice question 124 of 324

Implementing Cisco Enterprise Wireless Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-430 Question 124

Select 3

An enterprise network administrator notices several unauthorized wireless access points within the corporate network. These rogue APs are broadcasting SSIDs similar to the organization's official SSID. What actions can the administrator take using Cisco Wireless LAN Controller (WLC) to mitigate this threat?

  1. A

    Enable rogue containment to automatically disable the rogue APs.

  2. B

    Configure rogue detection to classify APs as rogue or friendly based on predefined policies.

  3. C

    Use RADIUS to authenticate rogue APs and prevent unauthorized devices.

  4. D

    Deploy CleanAir technology to detect and mitigate rogue AP interference.

  5. E

    Manually add the MAC addresses of rogue APs to the WLC’s blocked list.

Show answer and explanation

Correct answers: A, B, E

Explanation

Rogue APs pose a significant security threat to enterprise wireless networks. Cisco WLC provides several tools to detect and mitigate these threats, including rogue containment, detection policies, and manual blocking via MAC addresses. Enabling rogue containment ensures automatic actions, while detection policies help classify APs correctly. Adding rogue AP MAC addresses to the blocked list further improves control. However, technologies like RADIUS and CleanAir are not specifically designed to manage rogue APs.

  • A. Correct.

    This is correct. Rogue containment on the WLC can be enabled to take automated actions such as de-authenticating clients connected to rogue APs.

  • B. Correct.

    This is correct. Rogue detection allows the WLC to classify and differentiate authorized and unauthorized access points, which is crucial for mitigation.

  • C. Incorrect.

    This is incorrect. RADIUS is primarily used for client authentication and is not directly relevant to managing rogue APs.

  • D. Incorrect.

    This is incorrect. While CleanAir can detect RF interference, it is not designed to specifically address rogue AP threats.

  • E. Correct.

    This is correct. Adding rogue AP MAC addresses to the WLC’s blocked list ensures they are targeted for mitigation actions.

Timed practice exam

Take a 300-430 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam