Implementing Cisco Enterprise Wireless Networks (ENWLSI) Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 257 questions. Use the simulator for timed and flashcard mode.

Try Simulator

300-430 Sample Questions

  1. Question 1

    Q1

    A hospital is deploying a wireless network to support critical medical devices that use multicast for real-time data streaming. The network uses a Cisco Catalyst 9800-CL WLC and lightweight APs. To ensure reliability, the network administrator must configure the system so that multicast traffic is converted to unicast for each subscribed client. However, they also need to prevent the WLC from being overloaded with IGMP reports from the wired network. Which configuration combination on the Catalyst 9800 WLC achieves these specific goals?

    Show answer & explanation

    Correct answer: B

    The optimal configuration is to enable Multicast-Unicast mode, which ensures reliable delivery by converting multicast frames to unicast frames over the air. Disabling Global IGMP Snooping on the WLC prevents it from processing IGMP reports from the wired side, thus protecting its CPU. The WLC will still snoop IGMP packets from wireless clients to manage multicast group membership for the unicast conversion.

  2. Question 2

    Q2

    A retail company uses Cisco DNA Center Assurance to monitor its wireless network. An alert is generated for a specific AP indicating 'High RF Interference'. An engineer needs to determine the source of this non-Wi-Fi interference. Which feature within Cisco DNA Center Assurance should be used to classify the interfering device, such as a microwave oven or Bluetooth speaker?

    Show answer & explanation

    Correct answer: C

    Cisco DNA Center integrates with Cisco CleanAir technology. When an AP detects non-Wi-Fi interference, the Spectrum Analyzer view can be accessed for that AP. This tool provides detailed information about the RF environment and classifies interference sources based on their signatures, allowing the engineer to identify devices like microwave ovens, cordless phones, or Bluetooth devices.

  3. Question 3

    Q3

    A corporation is securing its wireless network using 802.1X with EAP-TLS. They are using Cisco ISE as the RADIUS server. A new requirement mandates that wireless clients must be validated against a specific value in the Subject Alternative Name (SAN) field of their certificate, in addition to the standard validation checks. Where in the Cisco ISE Authentication Policy is this specific check configured?

    Show answer & explanation

    Correct answer: B

    The Certificate Authentication Profile in Cisco ISE is specifically designed for granular control over certificate-based authentication. Within this profile, you can configure ISE to check specific attributes of a client certificate, such as the Subject, Common Name (CN), or Subject Alternative Name (SAN), and use those values in policy decisions. This is the correct location to enforce a check against a specific SAN value.

  4. Question 4

    Q4Multiple answers

    An engineer is deploying a FlexConnect wireless network for a large distribution center with multiple buildings. The design requires clients to maintain their IP address when roaming between APs connected to different switches, which are in different Layer 3 subnets. The WLCs are centralized in a corporate datacenter. Which two features must be configured to ensure seamless L3 roaming for the clients? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

  5. Question 5

    Q5

    A university is using Cisco CMX for location analytics in its library. To improve the accuracy of client location tracking for generating footfall heatmaps, the administrator plans to implement Cisco Hyperlocation technology. What is the primary hardware component that enables Hyperlocation on compatible Cisco Aironet APs?

    Show answer & explanation

    Correct answer: C

    Cisco Hyperlocation achieves high accuracy by using Angle of Arrival (AoA) technology. This is enabled by a special hardware component, the Hyperlocation Module (e.g., WSM01), which attaches to a compatible AP. This module contains a circular array of 32 antennas that can determine the precise direction from which a client's signal is arriving, significantly improving location accuracy from the standard 5-7 meters down to 1-3 meters.

  6. Question 6

    Q6

    To protect a Cisco Catalyst 9800 WLC from denial-of-service attacks, an administrator needs to create an access control list that filters traffic destined for the controller's CPU itself. This ACL should be applied to all traffic arriving at the controller, regardless of the ingress interface. Which type of ACL must be configured for this purpose?

    Show answer & explanation

    Correct answer: C

    A Control Plane ACL is specifically designed to protect the CPU of a network device like a WLC or router. It filters traffic that is punted to the control plane for processing, such as management traffic (SSH, SNMP, HTTPS) and routing protocol updates. Applying a Control Plane ACL is a best practice for hardening the controller against DoS attacks and unauthorized access attempts directed at the device itself.

  7. Question 7

    Q7

    A network engineer is configuring Quality of Service (QoS) on a Catalyst 9800 WLC to support voice over Wi-Fi clients. The corporate policy requires that all voice traffic originating from wireless clients be marked with a DSCP value of EF (46). Which configuration item within the C9800's policy model is used to apply this DSCP marking to the upstream traffic?

    Show answer & explanation

    Correct answer: C

    In the Catalyst 9800's policy model, the Policy Profile is where QoS settings for wireless clients are defined. Within the Policy Profile, under the QoS tab, you can configure both upstream (client to AP) and downstream (AP to client) QoS mappings. To mark traffic from the client with DSCP EF, you would configure the 'UP QoS Map' to map the WMM UP value for voice (typically 6) to a DSCP value of EF (46).

  8. Question 8

    Q8

    A warehouse is deploying an RFID asset tracking system that uses active Wi-Fi RFID tags. The tags associate with the wireless network to send their location data. The network is managed by a Cisco WLC and Cisco CMX. To ensure that CMX can accurately track these tags without requiring them to fully authenticate as data clients, which feature must be enabled on the WLC?

    Show answer & explanation

    Correct answer: D

    RLDP (Rogue Location Discovery Protocol) is a dual-purpose feature. While primarily for locating rogue devices, it also enables the tracking of Wi-Fi RFID tags. When RLDP is enabled, the WLC can instruct associated APs to send special frames to the RFID tag. The tag's response is heard by multiple APs, and this information is forwarded via NMSP to CMX, which then calculates the tag's location without requiring the tag to be a fully authenticated data client.

  9. Question 9

    Q9

    During a wireless network deployment, an engineer observes that Bonjour services, such as AirPrint, are not discoverable across different VLANs. The network consists of a Catalyst 9800 WLC, and clients are on a different VLAN than the Bonjour service providers. Which feature must be enabled on the WLC to facilitate this cross-subnet discovery?

    Show answer & explanation

    Correct answer: B

    Bonjour uses multicast DNS (mDNS), which relies on link-local multicast addresses (224.0.0.251) that are not routable. To allow discovery across different VLANs (subnets), the WLC must act as an mDNS Gateway. When this feature is enabled, the WLC listens for mDNS advertisements on one VLAN, caches them, and then responds to mDNS queries from clients on other VLANs, effectively bridging the service discovery process across Layer 3 boundaries.

  10. Question 10

    Q10

    True or False: When a FlexConnect AP is in standalone mode due to a WAN outage, it can perform 802.1X authentication for new clients if FlexConnect Local Authentication is enabled, even if the central RADIUS server (ISE) is unreachable.

    Show answer & explanation

    Correct answer: A

    This is true. When FlexConnect Local Authentication is configured, the WLC pushes the user credentials or certificate information for currently associated clients to the FlexConnect AP. If the AP enters standalone mode, it can use this cached information to act as a limited RADIUS server and authenticate new or re-authenticating clients without needing to contact the central ISE server. This provides a high degree of fault tolerance.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the 300-430 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 257 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon