350-401 exam dumps

350-401 practice question 266 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 266

Select 2

A network administrator is tasked with securing a wireless network in a corporate environment. The security policy mandates that unauthorized devices should not connect to the network, and all communications must be encrypted. Which wireless security features should the administrator configure to meet these requirements?

  1. A

    WPA3-Personal for strong encryption

  2. B

    WPA2-Enterprise with 802.1X authentication

  3. C

    MAC filtering for device access control

  4. D

    Open authentication for easier device onboarding

  5. E

    Configuring a pre-shared key (PSK) for all users

Show answer and explanation

Correct answers: B, C

Explanation

To meet the corporate security policy's requirements, the administrator should configure WPA2-Enterprise with 802.1X authentication to ensure encryption and centralized authentication for authorized users. MAC filtering can be added to restrict access to known devices, further enhancing security. WPA3-Personal, Open authentication, and PSK do not align with the corporate-grade security needs outlined in the policy.

  • A. Incorrect.

    WPA3-Personal is a strong encryption method, but it is primarily used in personal or small office environments. It lacks the centralized authentication required in a corporate environment.

  • B. Correct.

    WPA2-Enterprise with 802.1X provides strong encryption and uses a RADIUS server for centralized authentication, meeting the corporate security policy requirements.

  • C. Correct.

    MAC filtering can be used to restrict access to authorized devices by their MAC addresses, adding another layer of device-specific access control.

  • D. Incorrect.

    Open authentication allows any device to connect without credentials, which does not comply with the security policy's requirement to prevent unauthorized access.

  • E. Incorrect.

    A pre-shared key (PSK) can be used for authentication but is not scalable or secure enough for corporate environments as it lacks individual user accountability.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam