Cisco® 300-375 Exam Practice Questions (P. 1)
- Full Access (53 questions)
- Six months of Premium Access
- Access to one million comments
- Seamless ChatGPT Integration
- Ability to download PDF files
- Anki Flashcard files for revision
- No Captcha & No AdSense
- Advanced Exam Configuration
Question #1
Which two considerations must a network engineer have when planning for voice over wireless roaming? (Choose two.)
- ARoaming with only 802.1x authentication requires full reauthentication.
- BRoaming time increases when using 802.1x + Cisco Centralized Key Management.
- CFull reauthentication introduces gaps in a voice conversation.
- DRoaming occurs when the phone has reached -80 dBs or below.
- ERoaming occurs when the phone has seen at least four APs.
Correct Answer:
AC
In the absence of CCKM, a WPA/WPA2 client must perform a full EAP authentication to a remote AAA/RADIUS server, followed by a WPA/WPA2 4- way handshake whenever it roams. This process can take more than one second. With CCKM, the roaming client and WLC can use pre-established keying material to immediately establish a PTKnormally within a few ten of milliseconds.
AC
In the absence of CCKM, a WPA/WPA2 client must perform a full EAP authentication to a remote AAA/RADIUS server, followed by a WPA/WPA2 4- way handshake whenever it roams. This process can take more than one second. With CCKM, the roaming client and WLC can use pre-established keying material to immediately establish a PTKnormally within a few ten of milliseconds.
send
light_mode
delete
Question #2
Which two 802.11 methods can be configured to protect card holder data? (Choose two.)
- ACCMP
- BWEP
- CSSL
- DTKIP
- EVPN
Correct Answer:
CE
Reference: http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Compliance/Compliance_DIG/Compliance_DIG/PCI_AppC.html (Section: Build & Maintain a
Secure Network)
CE
Reference: http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Compliance/Compliance_DIG/Compliance_DIG/PCI_AppC.html (Section: Build & Maintain a
Secure Network)
send
light_mode
delete
Question #3
An engineer is changing the authentication method of a wireless network from EAP-FAST to EAP-TLS. Which two changes are necessary? (Choose two.)
- ACisco Secure ACS is required.
- BA Cisco NAC server is required.
- CAll authenticating clients require their own certificates.
- DThe authentication server now requires a certificate.
- EThe users require the Cisco AnyConnect client.
Correct Answer:
CD
Reference: http://www.cisco.com/c/en/us/products/collateral/wireless/aironet-1300-series/prod_qas09186a00802030dc.html
CD
Reference: http://www.cisco.com/c/en/us/products/collateral/wireless/aironet-1300-series/prod_qas09186a00802030dc.html
send
light_mode
delete
Question #4
Which mobility mode must a Cisco 5508 Wireless Controller be in to use the MA functionality on a Cisco Catalyst 3850 Series Switch with a Cisco 5508 Wireless
Controller as an MC?
Controller as an MC?
- Aclassic mobility
- Bnew mobility
- Cconverged access mobility
- Dauto-anchor mobility
Correct Answer:
C
Reference: http://www.cisco.com/c/en/us/products/collateral/switches/catalyst-3850-series-switches/product_bulletin_c25-720777.html
C
Reference: http://www.cisco.com/c/en/us/products/collateral/switches/catalyst-3850-series-switches/product_bulletin_c25-720777.html
send
light_mode
delete
Question #5
WPA2 Enterprise with 802.1x is being used for clients to authenticate to a wireless network through an ACS server. For security reasons, the network engineer wants to ensure only PEAP authentication can be used. The engineer sent instructions to clients on how to configure their supplicants, but users are still in the
ACS logs authenticating using E-FAST. Which option describes the most efficient way the engineer can ensure these users cannot access the network unless the correct authentication mechanism is configured?
ACS logs authenticating using E-FAST. Which option describes the most efficient way the engineer can ensure these users cannot access the network unless the correct authentication mechanism is configured?
- AEnable AAA override on the SSID, gather the usernames of these users, and disable their RADIUS accounts until they make sure they correctly configured their devices.
- BEnable AAA override on the SSID and configure an access policy in ACS that denies access to the list of MACs that have used EAP-FAST.
- CEnable АAА override on the SSID and configure an access policy in ACS that allows access only when the EAP authentication method is PEAP.
- DEnable AAA override on the SSID and configure an access policy in ACS that puts clients that authenticated using EАР-FAST into a quarantine VLAN.
Correct Answer:
D
D
send
light_mode
delete
All Pages