300-430 Question 241
Select 3A network administrator notices an influx of rogue APs being detected in a company's wireless network. To address this issue using Cisco Wireless LAN Controller (WLC), which steps should the administrator take to classify and mitigate these rogue devices effectively?
- A
Manually classify rogue APs as Malicious, Friendly, or Unclassified based on their behavior and location.
- B
Enable Rogue Management on the WLC and configure automatic rogue classification rules.
- C
Physically locate the rogue APs using RF triangulation tools and disable them.
- D
Configure the WLC to deauthenticate clients connected to rogue APs marked as Malicious.
- E
Ignore rogue alerts, as they are likely false positives and do not impact the network.
Show answer and explanation
Correct answers: A, B, D
Explanation
To manage rogue APs effectively, administrators should use the WLC's capabilities to classify detected rogue devices, automate their management through rules, and mitigate their impact by deauthenticating clients connected to malicious rogues. Ignoring rogue alerts or relying solely on physical location is inadequate for maintaining a secure wireless network.
- A. Correct.
Manually classifying rogue APs allows administrators to specifically identify and categorize devices as Malicious, Friendly, or Unclassified, which is an important step in rogue management.
- B. Correct.
Enabling Rogue Management and configuring automatic classification rules simplifies the detection and handling of rogue APs, ensuring timely mitigation.
- C. Incorrect.
While physically locating rogue devices can help, it is not always feasible or required for managing rogues effectively within the WLC software.
- D. Correct.
Deauthenticating clients from rogue APs marked as Malicious helps minimize the impact on network performance and security.
- E. Incorrect.
Ignoring rogue alerts is not recommended, as rogue devices can pose a significant threat to the network's security and performance.