for Cisco certification, Real Success Guaranteed with Updated . 100% PASS 300-375 Securing Cisco Wireless Enterprise Networks exam Today!
Cisco 300-375 Free Dumps Questions Online, Read and Test Now.
NEW QUESTION 1
You are configuring the social login for a guest network. Which three options are configurable social connect in Cisco CMS visitor connect? (Choose three.)
- A. Linkedin
- B. Pinterest
- C. Medium
- D. Google+
- E. Facebook
- F. MySpace
Answer: ADE
Explanation:
NEW QUESTION 2
A customer has deployed PEAP authentication with a Novell eDirectory LDAP Server. Which authentication method must be configured on the client to support this deployment?
- A. PEAP(EAP-MSCHAPv2)
- B. PEAP(EAP-TTLS)
- C. PEAP(EAP-GTC)
- D. PEAP(EAP-WPA)
Answer: C
Explanation:
NEW QUESTION 3
An engineer has configured central web authentication on the wireless network, but clients are receiving untrusted certificate errors on their internet browsers when directed to the guest splash page. Which file must be provided to an approved trusted certificate authority to fix this issue?
- A. EAP-TLS certificate generate by WLC
- B. CSR generated by identity Service Engine
- C. CSR generated by the WLC
- D. EAP-TLS certificate generated by the access point
Answer: B
Explanation:
NEW QUESTION 4
An engineer is preparing to implement a BYOD SSID at remote offices using local switching and wants to ensure that Wi-Fi Direct clients can communicate after the SSID is deployed. The engineer is planning on implementing the config wlan wifidirect allow 1 command. Which Wi-Fi Direct Client Policy consideration is applicable?
- A. Policy is applicable only with central switched WLANs on FlexConnect Aps.
- B. Policy is applicable only when P2P is set to disabled.
- C. Policy is applicable only to APs in FlexConnect mode only.
- D. Policy is applicable only on WLANs that have APs in local mode onl
Answer: A
Explanation:
NEW QUESTION 5
Clients are failing EAP authentication. A debug shows that an EAPOL start is sent and the clients are then de-authenticated. Which two issues can cause this problem? (Choose two.)
- A. The WLC certificate has changed.
- B. The WLAN is not configured for the correct EAP supplicant type.
- C. The shared secret of the WLC and RADIUS server do not match.
- D. The WLC has not been added to the RADIUS server as a client.
- E. The clients are configured for machine authentication, but the RADIUS server is configured for user authentication.
Answer: CD
Explanation:
NEW QUESTION 6
Which option determines which RADIUS server is preferred the most by the Cisco WLC?
- A. the Server Index (Priority) drop-down list
- B. the server status
- C. the server IP address
- D. the port number
Answer: A
Explanation:
NEW QUESTION 7
Regarding the guidelines for using MFP, under what circumstances will a client without Cisco compatible Extensions v5 be able to associate to a WLAN?
- A. The DHCP Required box is unchecked.
- B. AAA override is configured for the WLAN
- C. Client MFP is disabled or optional.
- D. WPA2 is enabled with TKIP or AE
Answer: D
Explanation:
NEW QUESTION 8
Which two statements describe the requirements for EAP-TLS?
- A. It requires client-side and server-side certificates.
- B. It uses PAC on the client.
- C. It requires PKI.
- D. It requires a server side digital certificate on only the RADIUS server
- E. It must use AES for encryption and cannot use TKIP for encryptio
Answer: AB
Explanation:
NEW QUESTION 9
After receiving an alert regarding a rogue AP, a network engineer logs into Cisco Prime and looks at the floor map where the AP that detected the rogue is located. The map is synchronized with a mobility services engine that determines the rogue device is actually inside the campus. The engineer determines the rogue to be a security threat and decides to stop it from broadcasting inside the enterprise wireless network. What is the fastest way to disable the rogue?
- A. Go to the location the rogue device is indicated to be and disable the power.
- B. Create an SSID on WLAN controller resembling the SSID of the rogue to spoof it and disable clients from connecting to it.
- C. Classify the rogue as malicious in Cisco Prime.
- D. Update the status of the rogue in Cisco Prime to containe
Answer: C
Explanation:
NEW QUESTION 10
An engineer has determined that the source of an authentication issue is the client laptop. Which three items must be verified for EAP-TLS authentication? (Choose three.)
- A. The client certificate is formatted as X 509 version 3
- B. The validate server certificate option is disabled.
- C. The client certificate has a valid expiration date.
- D. The user account is the same in the certificate.
- E. The supplicant is configured correctly.
- F. The subject key identifier is configured correctl
Answer: ADF
Explanation:
NEW QUESTION 11
WPA2 Enterprise with 802.1x is being used for clients to authenticate to a wireless network through
an ACS server. For security reasons, the network engineer wants to ensure only PEAP authentication can be used. The engineer sent instructions to clients on how to configure their supplicants, but users are still in the ACS logs authentication using EAP-FAST. Which option describes the most efficient way the engineer can ensure these users cannot access the network unless the correct authentication mechanism is configured?
- A. Enable AAA override on the SSID, gather the usernames of these users, and disable their RADIUS accounts until they make sure they correctly configured their devices.
- B. Enable AAA override on the SSID and configure an access policy in ACS that denies access to the list of MACs that have used EAP-FAST.
- C. Enable AAA override on the SSID and configure an access policy in ACS that allows access only when the EAP authentication method is PEAP.
- D. Enable AAA override on the SSID and configure an access policy in ACS that puts clients that authenticated using EAP-FAST into a quarantine VLAN.
Answer: D
Explanation:
NEW QUESTION 12
Which CLI command do you use on Cisco IOS XE Software to put the AP named Floor1_AP1 back in the default AP group?
- A. ap Floor1_AP1 ap-groupname default-group
- B. ap name Floor1_AP1 apgroup default-group
- C. ap name Floor1_AP1 ap-groupname default-group
- D. ap name Floor1_AP1 ap-groupname default
Answer: C
Explanation:
NEW QUESTION 13
Client Management Frame Protection is supported on which Cisco Compatible Extensions version clients?
- A. v2 and later
- B. v3 and later
- C. v4 and later
- D. v5 only
Answer: D
Explanation:
NEW QUESTION 14
A new MSE with wIPS service has been installed and no alarm information appears to be reaching
the MSE from controllers.
What protocol must be allowed to reach the MSE from the controllers?
- A. NMSP
- B. SOAP/XML
- C. SNMP
- D. CAPWAP
Answer: B
Explanation:
NEW QUESTION 15
When a supplicant and AAA server are configured to use PEAP, which mechanism is used by the client to authenticate the AAA server in Phase One?
- A. PMK
- B. shared secret keys
- C. digital certificate
- D. PAC
Answer: C
Explanation:
NEW QUESTION 16
Refer to the exhibit.
An engineer has configured a BYOD policy that allows for printing on the WLAN utilizing Bonjour
services. However, the engineer cannot get printing working. The WLC firmware is 8.x. the printer is connected on the wired network where a few of the access points are also connected.
Which reason that printing is not working is true?
- A. Location-specific service is not enabled on the WLC.
- B. Secure Web Mode Cipher-Option SSLv2 is not enabled.
- C. mBNS and IGMP snooping is not enabled on the WLC.
- D. IGMP Query Interval value is too low.
- E. The number of mDNS services exceeds firmware limits.
Answer: A
Explanation:
NEW QUESTION 17
Refer to the exhibit.
A client reports being unable to log into the wireless network, which uses PEAPv2. Which two issues appear in the output? (Choose two.)
- A. There is a problem with the client supplicant.
- B. The AP has the incorrect RADIUS server address.
- C. The AP has lost IP connectivity to the authentication server.
- D. The EAP client timeout value should be increased.
- E. The authentication server is misconfigured on the controller.
- F. The authentication server is misconfigured in the WLA
Answer: AD
Explanation:
Thanks for reading the newest 300-375 exam dumps! We recommend you to try the PREMIUM Surepassexam 300-375 dumps in VCE and PDF here: https://www.surepassexam.com/300-375-exam-dumps.html (124 Q&As Dumps)