300-430 Question 244
Select 2A network administrator is managing a Cisco wireless network and notices several rogue access points (APs) being reported in the Cisco Wireless LAN Controller (WLC). The administrator wants to ensure that legitimate APs are not mistakenly classified as rogue APs. Which two actions can the administrator take to prevent false-positive rogue AP detection?
- A
Add the legitimate APs to the WLC's MAC filter list as friendly APs.
- B
Disable rogue AP detection on the WLC.
- C
Configure the WLC's rogue detection sensitivity to a less aggressive setting.
- D
Use a location-based policy to identify and classify legitimate APs.
- E
Manually classify all detected APs as rogue to prevent errors.
Show answer and explanation
Correct answers: A, D
Explanation
To prevent false-positive rogue AP detection, the administrator can add legitimate APs to the MAC filter list as friendly APs, ensuring they are not classified as rogue. Additionally, using a location-based policy provides further accuracy by checking the physical location of APs to differentiate between legitimate and rogue devices. These actions maintain the integrity of rogue AP detection without compromising security.
- A. Correct.
Adding legitimate APs to the WLC's MAC filter list as friendly APs prevents the WLC from mistakenly classifying them as rogue APs.
- B. Incorrect.
Disabling rogue AP detection is not recommended because it will entirely disable the system's ability to detect rogue APs, which is a critical security feature.
- C. Incorrect.
Adjusting the rogue detection sensitivity may affect the detection of actual rogue APs and is not the best method to prevent false positives.
- D. Correct.
Using location-based policies helps the WLC accurately identify legitimate APs based on their position in the network, reducing false-positive detections.
- E. Incorrect.
Manually classifying all detected APs as rogue is counterproductive and contradicts the goal of preventing false-positive detection.