400-351 Exam Questions - Online Test


400-351 Premium VCE File

Learn More 100% Pass Guarantee - Dumps Verified - Instant Download
150 Lectures, 20 Hours

certleader.com

Your success in Cisco 400-351 is our sole target and we develop all our 400-351 braindumps in a way that facilitates the attainment of this target. Not only is our 400-351 study material the best you can find, it is also the most detailed and the most updated. 400-351 Practice Exams for Cisco 400-351 are written to the highest standards of technical accuracy.

Online 400-351 free questions and answers of New Version:

NEW QUESTION 1
Which two effects does TSPEC-based admission control have as it relates to WMM clients?(Choose two.)

  • A. Deny clients access to the VLAN that do not support WMM.
  • B. Allow access only for VoWLAN traffic when interference is detected.
  • C. Enforce airtime entitilement for wireless voice applications.
  • D. Ensure that call quality does not degrade for existing VoWLAN calls.
  • E. Deny clients access to the WLAN if they do not comply with the TERP standar

Answer: BE

NEW QUESTION 2
Which two IETF RADIUS attributes sent by the Cisco WLC can be used to differentiate authentication requests based on the user location?(Choose two.)

  • A. RADIUS attribute [31] Calling-Station-ld
  • B. RADIUS attribute [4] NAS-IP-Address
  • C. RADIUS attribute [95] NAS-IPv6-Address
  • D. RADIUS attribute [32] NAS-ldentifier
  • E. RADIUS attribute [303] Source-IP
  • F. RADIUS attribute [30] Called-Station-ld

Answer: DF

Explanation:
400-351 dumps exhibit
https://supportforums.cisco.com/sites/default/files/ise_location-based_web_portals-v2.pdf

NEW QUESTION 3
You have received a new Cisco 5760 Controller and have gone through the initial startup wizard. You are now trying to add APs to the controller, but these are not joining.
Which three checks should you do next? (Choose three.)

  • A. Check that the radios are not in a shutdown state.
  • B. Check the country code of the controlle
  • C. The APs do not join the controller if the country code does not match.
  • D. Check that the correct time is set on the controller.
  • E. Check that option 53 has been set in the DHCP scope.
  • F. Check that the controller has enough AP licenses.
  • G. Check that the controller has been configured with the correct hostnam
  • H. Otherwise, DNS resolution fails.

Answer: BCE

Explanation:
400-351 dumps exhibit

NEW QUESTION 4
Compared to an active survey, which three types of information are lost when performing a passive survey? (Choose three.)

  • A. retransmissions
  • B. uplink information
  • C. PHY rate
  • D. RSSI
  • E. TxBF
  • F. SNR
  • G. rogues

Answer: ABC

NEW QUESTION 5
Which AireOS release is the first to support New Mobility on the Cisco 2504 WLC?

  • A. 8.0x
  • B. 8.1x
  • C. 7.6x
  • D. 7.4

Answer: A

Explanation:
http://www.cisco.com/c/en/us/td/docs/wireless/compatibility/matrix/compatibility-matrix.html http://www.cisco.com/c/en/us/support/docs/wireless/2500-series-wireless-controllers/113034- 2500-deploy-guide-00.html

NEW QUESTION 6
How do the characteristics that are available on the Cisco WCS for Linux version differ from those of the Cisco WCS for Windows version?

  • A. Assuming that there are no differences in hardware, a Cisco WCS for Linux can support up to 750 wireless LAN controller
  • B. A Cisco WCS for Windows can support up to 250 wireless LAN controllers.
  • C. Cisco WCS for Linux is required for deployments.
  • D. There are no differences in features between the Linux and Windows versions of Cisco WCS.
  • E. Cisco WCS for Windows includes support for Cisco Spectrum Expert client
  • F. Cisco WCS for Linux does not support Cisco Spectrum Expert clients.

Answer: C

NEW QUESTION 7
Refer to the exhibit. A wireless engineer at ACME Company is troubleshooting a wireless client that is unable to associate to a WLAN. What is likely the cause of the problem?
400-351 dumps exhibit

  • A. The AP CAPWAP tunnel is down, and is unable to handle any new connections.
  • B. The client is providing a wrong credential for dot1x authentication.
  • C. The WPA PSKs do not match.
  • D. The client uses WPA, but the AP is advertising only WPA2 support.
  • E. A firewall is blocking the ports that are necessary for the AP to join the WL

Answer: B

NEW QUESTION 8
Your customer needs the list of all the guest client that connected to Wi-Fi successfully but have not yet authenticated. The customer decides to create an advanced filter in Cisco Pounder monitor
>client and user which two conditions should be included in the filter? (Choose two)

  • A. PEM state =WebauthReqD
  • B. On Network= Yes
  • C. Status =Associated
  • D. Type =Lightweight client

Answer: CD

NEW QUESTION 9
What are the three fundamental properties that are provided by the antenna of an AP? (Choose three.)

  • A. frequency
  • B. gain
  • C. dB loss
  • D. polarization
  • E. direction
  • F. modulation

Answer: BDF

NEW QUESTION 10
Which option in the cisco identity service engine allows for authorization based on Active Directory user and domain computer login?

  • A. Machine access restriction
  • B. Active directory group
  • C. Active directory attributes
  • D. Identity source sequences

Answer: A

NEW QUESTION 11
Which action is needed to edit the settings of an RF profile?

  • A. RF profiles cannot be edite
  • B. They must be removed and recreated with the desired values.
  • C. Disable the network that will be affected by the changes that you will be making either for 80Z11a or 802 11b
  • D. If the RF Profile has been applied to multiple AP Groups, remove the desired RF profile from just the AP group that affects the APs whose RF behavior you want to see modified
  • E. Disable custom power level settings for all APs within the group to which the profile is linked

Answer: B

NEW QUESTION 12
Which three statements about the high availability configuration on the Cisco 5760 WLCs are true? (Choose three.)

  • A. Cisco WLC with more reboots is elected as active when the default stack priority is in use.
  • B. EtherChannel bundles all ports on both active and standby Cisco WLC on a logical port.
  • C. Cisco 5760 WLC uses a dedicated high availability port for high availability and configuration synchronization.
  • D. High availability switchover is triggered when one of the ports on the active Cisco WLC EtherChannel bundle fails.
  • E. Active Cisco WLCs in a pair can be identified using LED state without issuing any command on the Cisco WLC console.
  • F. Cisco WLC with the highest priority in a stack are elected as the active Cisco WLC during the election process.
  • G. All configuration including certificates are automatically synced between active and standby Cisco WLC.

Answer: BEF

Explanation:
http://www.cisco.com/c/en/us/td/docs/wireless/technology/5760_deploy/CT5760_Controller_Depl oyment_Guide/High_Availability.html

NEW QUESTION 13
Which two statements are true about adding Identity Services Engines 1.3 to Prime Infrastructure 2.2?(Choose two.)

  • A. You need to use super user credentials on ISE for PI integration to work.
  • B. If you add two ISEs, one should be primary and the other should be standby.
  • C. Configuration templates within PI can be used to set up ISE.
  • D. A maximum of three ISEs can be added to P

Answer: AB

Explanation:
400-351 dumps exhibit
400-351 dumps exhibit
http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/2-2/user/guide/pi_ug.pdf

NEW QUESTION 14
Which option is the common primary use case for tools such as Puppet. Chef. Ansible, and Salt?

  • A. network function visualization
  • B. policy assurance
  • C. Configuration management.
  • D. network orchestratio

Answer: C

NEW QUESTION 15
400-351 dumps exhibit
Refer to the exhibit. What is the best way to resolve this issue?

  • A. Install a server certificate signed by a well-know public CA on the WLC.
  • B. Disable certificate checks on the client.
  • C. Install a server certificate signed by a well-known public CA on the Radius Server.
  • D. Use the certificate authority on the Cisco Identity Services Engin

Answer: C

Explanation:
12321 PEAP failed SSL/TLS handshake because the client rejected the ISE Local - certificate
Cisco ISE authentication failed because client reject certificate | AAA, Identity and NAC | Cisco Support Community
https://supportforums.cisco.com/discussion/11697966/cisco-ise-authentication-failed-becauseclient- reject-certificate
The error you are seeing in ISE is pointing to your client, if you have the eap settings set to "validate server certificate" then you must manually set it to trust the rootCA that signed the ISE certificate, or you can disable this option for testing. You can try to remove this wireless network profile, and recreate it and see if the pop up appears which asks you to validate the server's identity.
Possible Causes for this issue
The supplicant or client machine is not accepting the certificate from Cisco ISE.
The client machine is configured to validate the server certificate, but is not configured to trust the Cisco ISE certificate.
Note [This is an indication that the client does not have or does not trust the Cisco ISE certificates. Possible Causes The supplicant or client machine is not accepting the certificate from Cisco ISE.
The client machine is configured to validate the server certificate, but is not configured to trust the Cisco ISE certificate.
Resolution The client machine must accept the Cisco ISE certificate to enable authentication.

NEW QUESTION 16
You need to open the appropriate firewall port for RLDP. Which port must you open?

  • A. UDP 6352
  • B. UDP 5246
  • C. TCP 37540
  • D. TCP 8443
  • E. TCP 16113
  • F. UDP 16666

Answer: A

Explanation:
Rogue Location Discovery Protocol (RLDP) is an active approach, which is used when rogue AP has no authentication (Open Authentication) configured. This mode, which is disabled by default, instructs
an active AP to move to the rogue channel and connect to the rogue as a client. During this time, the active AP sends de-authentication messages to all connected clients and then shuts down the radio interface. Then, it associates to the rogue AP as a client. The AP then tries to obtain an IP address from the rogue AP and forwards a User Datagram Protocol (UDP) packet (port 6352) that contains the local AP and rogue connection information to the controller through the rogue AP. If the controller receives this packet, the alarm is set to notify the network administrator that a rogue AP was discovered on the wired network with the RLDP feature.

NEW QUESTION 17
Which two options are correct according to debug output presented in the following exhibit ? (Choose two.)
Exhibit:
400-351 dumps exhibit

  • A. The wireless client "hangs" in probes (does not proceed with 802.11 authentication and association). It is likely that the "encryption" or "key-management" advertised in the probe response does not match.
  • B. Since the AP receives a probe request from the wireless client, the Access Point Functions state for the machine changes from "Idle" to "Probe."
  • C. The wireless client uses a static IP address, so "0.0.0.0 START (0)" can be found in the logs.
  • D. The wireless client has been successfully authenticated.Reauthentication is set to occur on an extremely aggressive schedule (every five seconds).

Answer: AB

NEW QUESTION 18
You are the wireless administrator for ACME corporation. You must configure a Cisco Catalyst 3850 Series Switch to work as mobility agent to allow access point association to this switch. Which statement about this scenario is true?

  • A. Access points must be connected to an access port that has the access VLAN configured to be the same as the service port VLAN on the Catalyst 3850 switch.Access points must be connected to a trunk port with the native VLAN set to 1 in order to join the WLC on the Catalyst 3850 switch.
  • B. Access points must be connected to an access port with the access VLAN configured to the same as the wireless management VLAN on the Catalyst 3850 switch.
  • C. Access points must be connected to an access port that has the access VLAN configured to be the same as the management VLAN for the switch stack.
  • D. Access points must be connected to an access port with the access VLAN configured to be any VLAN that has a Layer 3 interface (SVI) on the Catalyst 3850 switch.

Answer: C

Explanation:
https://mrncciew.com/2013/09/29/getting-started-with-3850/
400-351 dumps exhibit
400-351 dumps exhibit
400-351 dumps exhibit
https://supportforums.cisco.com/document/146996/getting-started-wlc-5760-and-3850

NEW QUESTION 19
Which statement about ACLs used on a Cisco WLC is true?

  • A. A WLAN ACL will override an interface access-list.
  • B. An interface ACL will override a WLAN ACL.
  • C. A WLAN ACL will get applied first followed by an interface ACL.
  • D. An interface ACL will get applied first followed by a WLAN AC

Answer: A

NEW QUESTION 20
You are the network administrator for ACME corporation. Your organization has deployed a single Cisco 5500 Series Wireless Controller with 100 Cisco Aironet 3500 Series Aps. A new IT member is worried that most of these Aps are working at a power Ievel3 on the 5GHz radio specially. As this power level setting is causing issues in your wireless network. Which option describes the likely cause of this behavior?

  • A. The WLC has been recently rebooted, which causes the TPC algorithm to set power level 3 on all APs for 90 seconds.
  • B. The controller TPC algorithm seems to have a proble
  • C. It might have been set to work in TPCv2 mode instead of TPCvl.
  • D. The WLC is misconfigured because the static power of level 3 has been set for all the APs under TPC settings.
  • E. Cisco 7925 wireless IP Phones are in use and the DTPC feature is enabled on the 5 GHz radi

Answer: D

Explanation:
Tx Power
Num Of Supported Power Levels 5
Tx Power Level 1 .......................... 18 dBm
Tx Power Level 2 .......................... 15 dBm
Tx Power Level 3........................... 12 dBm
Tx Power Level 4 .......................... 9 dBm
Tx Power Level 5 .......................... 6 dBm
https://supportforums.cisco.com/discussion/11635606/power-level-wlc

NEW QUESTION 21
While troubleshooting a failed central web authentication configuration on Cisco WLC, you discover that the Cisco WLC Policy Manager State is showing RUN for new clients and not CENTRAL_WEB_AUTH. Which of the below is most likely causing this issue?

  • A. The WLAN NAC state should be set to RADIUIS NAC.
  • B. The WLAN Layer 2 security should be set to WPA+WPA2.
  • C. The WLAN Layer 3 security should be set to Web Policy with Conditional Web Redirect.
  • D. The Web Login Page under the Cisco WLC security settings should be set to External(Redirect to external server).

Answer: A

Explanation:
400-351 dumps exhibit
http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-webauth- 00.html
http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/69340-web-authconfig. html

NEW QUESTION 22
A user is presented with the underlying hardware and software needed to develop and offer applications via the Internet from a cloud service provider. Which cloud model is this user consuming?

  • A. Software as a Service
  • B. Platform as a Service
  • C. Application as a Service
  • D. Infrastructure as a Service

Answer: A

Explanation:
Cloud computing - Wikipedia, the free encyclopedia
https://en.wikipedia.org/wiki/Cloud_computing#Service_models
400-351 dumps exhibit

NEW QUESTION 23
An autonomous AP is configured with the infrastructure –client command. What is this command used for?

  • A. to allow more than 20 client associations
  • B. to send reliable multicast traffic
  • C. to enable multiple VLANs to cross the bridge link
  • D. to allow only infrastructure device associations

Answer: B

NEW QUESTION 24
Which two statement about LAG in the Cisco wireless LAN controller running Aire OS 8.0 are true?(choose two)

  • A. LAG bundles all of the crsco WLC distribution system ports into a single 802.3ad port channel.
  • B. There can be only one AP-manager interface if LAG is enabled
  • C. LAG configuration change take effect immediately after they are configured
  • D. Channel negotiation LACP and PAgP are supported

Answer: AB

NEW QUESTION 25
Refer to the exhibit.
400-351 dumps exhibit
You are configuring a MAC-based ACL on a root bridge. You must ensure that only one WGB can associate to the root Which command or set of commands must you use?

  • A. access-list 700 permit 001b.d43e.6d52 ffff.ffff.ffff access-list 700 deny 0000.0000.0000 0000.0000.0000
  • B. access-list 700 permit 001b.d43e.6d52 0000.0000.0000access-list 700 deny 0000.0000.0000 ffff.ffff.ffff
  • C. access-list 700 permit 001b.2bab.68d0 0000.0000.0000access-list 700 deny 0000.0000.0000 ffff.ffff.ffff
  • D. access-list 700 permit 001b.2bab.68d0 0000.0000.0000

Answer: D

NEW QUESTION 26
......

P.S. Easily pass 400-351 Exam with 393 Q&As DumpSolutions Dumps & pdf Version, Welcome to Download the Newest DumpSolutions 400-351 Dumps: https://www.dumpsolutions.com/400-351-dumps/ (393 New Questions)