We provide which are the best for clearing 300-375 test, and to get certified by Cisco Securing Cisco Wireless Enterprise Networks. The covers all the knowledge points of the real 300-375 exam. Crack your Cisco 300-375 Exam with latest dumps, guaranteed!
Online Cisco 300-375 free dumps demo Below:
NEW QUESTION 1
A Customer is concerned about denial of service attacks that impair the stable operation of the corporate wireless network. The customer wants to purchase mobile devices that will operate on the corporate wireless network. Which IEEE standard should the mobile devices support to address the customer concerns?
- A. 802.11w
- B. 802.11k
- C. 802.11r
- D. 802.11h
Answer: A
Explanation:
NEW QUESTION 2
An engineer is implementing SNMP v3 on a wireless LAN controller and wants to use the combination of authentication and privacy protocols with the highest security available. Which protocols must be configured?
- A. CFB-AES-128 with HMAC-MD5
- B. CBC-DES with HMAC SHA
- C. CFB-AES-128 with HMAC-SHA
- D. CBC-DES with HMAC-MD5
Answer: C
Explanation:
NEW QUESTION 3
An engineer must provide a graphical trending report of the total number of wireless clients on the network. Winch report provides the required data?
- A. Client Summary
- B. Posture Status Count
- C. Client Traffic Stream Metrics
- D. Mobility Client Summary
Answer: D
Explanation:
NEW QUESTION 4
Which two considerations must a network engineer have when planning for voice over wireless roaming? (Choose two.)
- A. Roaming with only 802.1x authentication requires full reauthentication.
- B. Full reauthentication introduces gaps in a voice conversation.
- C. Roaming occurs when e phone has seen at least four APs.
- D. Roaming occurs when the phone has reached -80 dBs or belo
Answer: AB
Explanation:
NEW QUESTION 5
An engineer has configured the wireless controller to authenticate clients on the employee SSID against Microsoft Active Directory using PEAP authentication. Which protocol does the controller use to communicate with the authentication server?
- A. EAP
- B. 802.1x
- C. RADIUS
- D. WPA2
Answer: A
Explanation:
Define the Layer 2 Authentication as WPA2 so that the clients perform EAP-based authentication (PEAP-MS-CHAP v2 in this example) and use the advanced encryption standard (AES) as the encryption mechanism. Leave all other values at their defaults. https://www.cisco.com/c/en/us/support/docs/wireless/5500-series-wireless-controllers/115988-nps-wlc-config-000.html
NEW QUESTION 6
Which three items must be configured on a Cisco WLC v7.0 to allow implementation of isolated bonding network? (Choose three.)
- A. RADIUS server IP address
- B. DHCP IP address
- C. SNMP trap receiver IP address
- D. interface name
- E. SNMP community name
- F. ACL name
Answer: ADF
Explanation:
NEW QUESTION 7
Which EAP types are supported by MAC 10.7 for authentication to a Cisco Unified Wireless Network?
- A. LEAP and EAP-Fast only
- B. EAP-TLS and PEAP only
- C. LEAP, EAP-TLS, and PEAP only
- D. LEAP, EAP-FAST, EAP-TLS, and PEAP
Answer: D
Explanation:
NEW QUESTION 8
Which EAP method can an AP use to authenticate to the wired network?
- A. EAP-GTC
- B. EAP-MD5
- C. EAP-TLS
- D. EAP-FAST
Answer: C
Explanation:
NEW QUESTION 9
Which command is an SNMPv3-specific command that an engineer can use only in Cisco IOS XE?
- A. snmp-server user remoteuser1 group1 remote 10.12.0.4
- B. snmp-server host 172.16.1.33 public
- C. snmp-server community comaccess ro 4
- D. snmp-server enable traps wireless
Answer: A
Explanation:
NEW QUESTION 10
An engineer is changing the authentication method of a wireless network from EAP-FAST to EAP-TLS. Which two changes are necessary? (Choose two.)
- A. Cisco Secure ACS is required.
- B. A Cisco NAC server is required.
- C. All authentication clients require their own certificates.
- D. The authentication server now requires a certificate.
- E. The users require the Cisco AnyConnect clien
Answer: CD
Explanation:
NEW QUESTION 11
Refer to the exhibit. You are configuring an autonomous AP for 802.1x access to a wired infrastructure. What does the command do?
- A. It enables the AP to override the authentication timeout on the RADIUS server.
- B. It configures how long the AP must wait for a client to reply to an EAP/dot1x message before the authentication fails.
- C. It enables the supplicant to override the authentication timeout on the client
- D. It configures how long the RADIUS server must wait for supplicant to reply to an EAP/dot1x message before the authentication fails.
Answer: C
Explanation:
NEW QUESTION 12
When implementing secure PCI wireless networks, which two are specific recommendations in the PCI DSS? (Choose two)
- A. Use a minimum 12-character random passphrase with WPA
- B. Segment logging events with other networking devices within the organization.
- C. Use VLAN based segmentation with MAC filters.
- D. Change default settings.
- E. Implement strong wireless authentication
Answer: DE
Explanation:
Wireless networks that are part of the CDE must comply with all PCI DSS requirements. This includes using a firewall (requirement 1.2.3) and making sure that additional rogue wireless devices have not been added to the CDE (requirement 11.1). In addition, PCI DSS compliance for systems that include WLANs as a part of the CDE requires extra attention to WLAN specific technologies and processes such as:
A. Physical security of wireless devices, B. Changing default passwords and settings on wireless devices, C. Logging of wireless access and intrusion prevention, D. Strong wireless authentication and encryption, E. Use of strong cryptography and security protocols, and F. Development and enforcement of wireless usage policies. This section will cover each of these requirements sequentially. https://www.pcisecuritystandards.org/pdfs/PCI_DSS_Wireless_Guidelines.pdf
NEW QUESTION 13
During the EAP process and specifically related to the logon session, which encrypted key is sent from the RADIUS server to the access point?
- A. WPA key
- B. encryption key
- C. session key
- D. shared secret key
Answer: C
Explanation:
NEW QUESTION 14
An engineer is configuring client MFP. What WLAN Layer 2 security must be selected to use client MFP?
- A. Static WEP
- B. CKIP
- C. WPA+WPA2
- D. 802 1x
Answer: C
Explanation:
NEW QUESTION 15
On which two ports does the RADIUS server maintain a database and listen for incoming authentication and accounting requests? (Choose two.)
- A. UDP 1900
- B. UDP port 1812
- C. TCP port 1812
- D. TCP port 1813
- E. UDP port 1813
Answer: BE
Explanation:
NEW QUESTION 16
What is the maximum number of clients that a small branch deployment using a four-member Cisco Catalyst 3850 stack (acting as MC/MA) can support?
- A. 10000
- B. 1000
- C. 500
- D. 2000
- E. 5000
Answer: E
Explanation:
NEW QUESTION 17
An engineer with ID 338860948 is implementing Cisco Identity-Based Networking on a Cisco AireOS
controller. The engineer has two ACLs on the controller. The first ACL, named BASE_ACL, is applied to the corporate_clients interface on the WLC, which is used for all corporate clients. The second ACL, named HR_ACL, is referenced by ISE in the Human Resources group policy.
Which option is the resulting ACL when a Human Resources user connects?
- A. HR_ACL only
- B. HR_ACL appended with BASE_ACL
- C. BASE_ACL appended with HR_ACL
- D. BASE_ACL only
Answer: A
Explanation:
Recommend!! Get the Full 300-375 dumps in VCE and PDF From Passcertsure, Welcome to Download: https://www.passcertsure.com/300-375-test/ (New 124 Q&As Version)