300-430 Sample Questions & Answers
802.1X and web authentication for wireless clients carry the top weight, alongside FlexConnect components, QoS tuning, analytics for location tracking, multicast support on wireless, monitoring through PI and DNA Center, and controller hardening.
Launch the full 300-430 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Device Hardening · Implement CPU ACLs on the controller
To protect a Cisco Catalyst 9800 WLC from denial-of-service attacks, an administrator needs to create an access control list that filters traffic destined for the controller's CPU itself. This ACL should be applied to all traffic arriving at the controller, regardless of the ingress interface. Which type of ACL must be configured for this purpose?
Show answer & explanation
Correct answer: C
A Control Plane ACL is specifically designed to protect the CPU of a network device like a WLC or router. It filters traffic that is punted to the control plane for processing, such as management traffic (SSH, SNMP, HTTPS) and routing protocol updates. Applying a Control Plane ACL is a best practice for hardening the controller against DoS attacks and unauthorized access attempts directed at the device itself.
- Question 2Intermediate
QoS on a Wireless Network · Implement QoS for wireless clients
A network engineer is configuring Quality of Service (QoS) on a Catalyst 9800 WLC to support voice over Wi-Fi clients. The corporate policy requires that all voice traffic originating from wireless clients be marked with a DSCP value of EF (46). Which configuration item within the C9800's policy model is used to apply this DSCP marking to the upstream traffic?
Show answer & explanation
Correct answer: C
In the Catalyst 9800's policy model, the Policy Profile is where QoS settings for wireless clients are defined. Within the Policy Profile, under the QoS tab, you can configure both upstream (client to AP) and downstream (AP to client) QoS mappings. To mark traffic from the client with DSCP EF, you would configure the 'UP QoS Map' to map the WMM UP value for voice (typically 6) to a DSCP value of EF (46).
- Question 3Intermediate
Location Services · Implement location services
A warehouse is deploying an RFID asset tracking system that uses active Wi-Fi RFID tags. The tags associate with the wireless network to send their location data. The network is managed by a Cisco WLC and Cisco CMX. To ensure that CMX can accurately track these tags without requiring them to fully authenticate as data clients, which feature must be enabled on the WLC?
Show answer & explanation
Correct answer: D
RLDP (Rogue Location Discovery Protocol) is a dual-purpose feature. While primarily for locating rogue devices, it also enables the tracking of Wi-Fi RFID tags. When RLDP is enabled, the WLC can instruct associated APs to send special frames to the RFID tag. The tag's response is heard by multiple APs, and this information is forwarded via NMSP to CMX, which then calculates the tag's location without requiring the tag to be a fully authenticated data client.
- Question 4Beginner
Multicast · Implement mDNS
During a wireless network deployment, an engineer observes that Bonjour services, such as AirPrint, are not discoverable across different VLANs. The network consists of a Catalyst 9800 WLC, and clients are on a different VLAN than the Bonjour service providers. Which feature must be enabled on the WLC to facilitate this cross-subnet discovery?
Show answer & explanation
Correct answer: B
Bonjour uses multicast DNS (mDNS), which relies on link-local multicast addresses (224.0.0.251) that are not routable. To allow discovery across different VLANs (subnets), the WLC must act as an mDNS Gateway. When this feature is enabled, the WLC listens for mDNS advertisements on one VLAN, caches them, and then responds to mDNS queries from clients on other VLANs, effectively bridging the service discovery process across Layer 3 boundaries.
- Question 5Intermediate
FlexConnect · Deploy FlexConnect capabilities
True or False: When a FlexConnect AP is in standalone mode due to a WAN outage, it can perform 802.1X authentication for new clients if FlexConnect Local Authentication is enabled, even if the central RADIUS server (ISE) is unreachable.
Show answer & explanation
Correct answer: A
This is true. When FlexConnect Local Authentication is configured, the WLC pushes the user credentials or certificate information for currently associated clients to the FlexConnect AP. If the AP enters standalone mode, it can use this cached information to act as a limited RADIUS server and authenticate new or re-authenticating clients without needing to contact the central ISE server. This provides a high degree of fault tolerance.
- Question 6Intermediate
Security for Wireless Client Connectivity · Implement BYOD and guest
A financial firm wants to implement a guest wireless network using Cisco ISE. The security policy requires that guests self-register through a portal, but their access must be approved by a designated company sponsor before network access is granted. Which type of guest portal should be configured in Cisco ISE to meet this requirement?
Show answer & explanation
Correct answer: C
The Sponsored Guest Portal in Cisco ISE is designed for this exact workflow. A guest initiates the registration process on their own, providing their details and the email address of their internal sponsor. ISE then sends an approval request to the sponsor. Only after the sponsor approves the request does ISE grant network access to the guest, fulfilling the company's security policy.
- Question 7Intermediate
Device Hardening · Implement access point authentication (including 802.1X)
To harden a Cisco wireless network, an administrator must ensure that all lightweight access points authenticate to the Catalyst 9800 WLC using a secure, certificate-based method before being allowed to join the controller. Which technology must be implemented to achieve this?
Show answer & explanation
Correct answer: C
802.1X AP Authentication provides the most secure method for authenticating APs to a WLC. In this model, the AP acts as a supplicant and the WLC acts as an authenticator, proxying the request to a RADIUS server (like ISE). Modern Cisco APs use their built-in Secure Unique Device Identifier (SUDI) certificate for this process, ensuring that only legitimate, company-owned APs can join the controller.
- Question 8Beginner
FlexConnect · Implement Office Extend
A company has deployed Cisco OfficeExtend APs (OEAPs) for its remote workers. The security team is concerned about potential security breaches if a remote worker's home network is compromised. To mitigate this risk, they want to prevent traffic from the corporate SSID from reaching the remote worker's local home network. Which feature, when disabled, accomplishes this goal?
Show answer & explanation
Correct answer: B
Split Tunneling is the feature that controls whether traffic from a client connected to an OfficeExtend AP can access the local network. When enabled, traffic destined for the corporate network is tunneled back to the WLC, while other traffic (like internet or local printer access) is switched locally onto the home network. By disabling split tunneling, all traffic from the corporate SSID is forced through the secure CAPWAP tunnel to the corporate WLC, effectively isolating corporate devices from the local home network.
- Question 9Advanced
Monitoring · Troubleshoot client connectivity
A network administrator is troubleshooting an issue where wireless clients are unable to get an IP address from a DHCP server. The clients are associated with a WLAN that uses central switching on a FlexConnect AP. The administrator suspects an ACL is blocking the traffic. The following ASCII diagram shows the traffic flow.
[Client] --(DHCP Discover)--> [Flex AP] --(CAPWAP)--> [WLC] --(DHCP Relay)--> [DHCP Server] ^ |--(DHCP Offer)-- [WLC] --(CAPWAP)--> [Flex AP]Where must the administrator check for an ACL that could be blocking the DHCP traffic?
Show answer & explanation
Correct answer: B
In a central switching scenario, client traffic is tunneled from the FlexConnect AP to the WLC inside a CAPWAP tunnel. The WLC then decapsulates the traffic and places it onto a VLAN or interface. Any ACLs applied to this specific VLAN/interface on the WLC will filter the client's traffic. Since DHCP is fundamental client traffic, an ACL on this interface is the most likely place for the block to occur.
- Question 10AdvancedSelect 2
Advanced Location Services · Implement location-aware guest services using custom portal and Facebook Wi-Fi
A large venue wants to offer location-aware guest services through a custom portal. When a guest connects to the Wi-Fi, they should be redirected to a portal that displays a map of their current location within the venue. This functionality is being implemented with Cisco CMX. Which two components are essential for CMX to determine the guest's location and trigger the appropriate portal redirect? (Select TWO)
Show answer & explanation
Correct answers: A, D
Ready for the real thing?
The full 300-430 simulator has every exam-style question, timed mode, and instant scoring.