Question No: 11 – (Topic 1)

Which two effects does TSPEC-based admission control have as it relates to WMM clients?(Choose two.)

  1. Deny clients access to the VLAN that do not support WMM.

  2. Allow access only for VoWLAN traffic when interference is detected.

  3. Enforce airtime entitilement for wireless voice applications.

  4. Ensure that call quality does not degrade for existing VoWLAN calls.

  5. Deny clients access to the WLAN if they do not comply with the TERP standard.

Answer: B,E

Question No: 12 – (Topic 1)

Which three statements about the high availability configuration on the Cisco 5760 WLCs are true? (Choose three.)

  1. Cisco WLC with more reboots is elected as active when the default stack priority is in use.

  2. EtherChannel bundles all ports on both active and standby Cisco WLC on a logical port.

  3. Cisco 5760 WLC uses a dedicated high availability port for high availability and configuration synchronization.

  4. High availability switchover is triggered when one of the ports on the active Cisco WLC EtherChannel bundle fails.

  5. Active Cisco WLCs in a pair can be identified using LED state without issuing any command on the Cisco WLC console.

  6. Cisco WLC with the highest priority in a stack are elected as the active Cisco WLC during the election process.

  7. All configuration including certificates are automatically synced between active and standby Cisco WLC.

Answer: B,E,F Explanation:



Question No: 13 – (Topic 1)

If a guest anchor controller is used outside the firewall. Which firewall ports must you open for guest access including SNMP and mobility failover features to work in a Cisco Unified Wireless Network?

  1. UDP 16666. IP protocol 90. UDP 162 163

  2. UDP 16667. IP protocol 97. UDP 500 501

  3. UDP 16666. IP protocol 97. UDP 161 162

  4. UDP 12223. IP protocol 97. UDP 161 162

  5. UDP 12222. IP protocol 90. UDP 161 162

Answer: C Explanation:

http://www.cisco.com/c/en/us/td/docs/wireless/controller/8-0/configuration- guide/b_cg80/b_cg80_chapter_010011.html

Question No: 14 – (Topic 1)

VLAN Trunking Protocol is a Cisco proprietary protocol that propagates the definition of VLANs over the local area network. Which two statements are true?(Choose two.)

  1. VTP requires access mode interfaces to propagate.

  2. VTP requires trunk mode interfaces to propagate.

  3. VTP transparent mode forwards VTP packets and can act as a client or a server.

  4. VTP config revision increases base on switch uptime.

  5. When Cisco switches are started from scratch, they are in server mode and their domain is set to null.

Answer: B,E

Question No: 15 – (Topic 1)

You have added your Active Directory server to the Cisco ISE and see the status as operational. However, when you try to add Active Directory groups to your authorization

policy conditions in the Cisco ISE, no Active Directory groups appear. What is the most likely reason?

  1. You did not add any attributes in the Active Directory join point under the External Identity Sources.

  2. A firewall is blocking TCP port 389 between the Cisco ISE and Active Directory.

  3. You did not add any groups in the Active Directory join point under the External Identity Sources.

  4. The credentials used to join the Cisco ISE to Active Directory do not have sufficient privileges to query Active Directory.

Answer: C Explanation:

http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/ISE-ADIntegrationDoc/b_ISE- ADIntegration.html#ID687

Question No: 16 – (Topic 1)

You have been hired to install new Cisco switches at ACME Corporation. The company has an existing Cisco network comprised of access layer switches that use multiple VLANs and VLAN trunking protocol to distribute the VLANs to the switches throughout the network. Which two methods are best to accomplish your task? (Choose two.)

  1. Configure the VLAN Trunking Protocol pruning on the new switches because they may not need all of the VLANs.

  2. Prior to installation, ensure that all switches are running the same Cisco IOS software version as the VTP server.

  3. Ensure that all the new Cisco switches have their VTP domain name set to the default value of null

  4. Configure one of the new switches as a VTP server to distribute the VLANs appropriately.

  5. Ensure that all switches have the same VLAN Trunking Protocol password and

    encryption level.

  6. Configure all new switches as VTP clients and relocated switches as VTP server because the already have all the VLANs in their database.

  7. Ensure that all switches are running the same VTP version.

Answer: E,G Explanation: From:

http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12- 2/25ew/configuration/guide/conf/vtp.html#wp1034490

Question No: 17 – (Topic 1)

You are the network administrator at ACME Corporation and currently troubleshooting a Central Web Authentication issue where the guest users are not being redirected to the ISE guest login portal. You have verified that all configuration on the ISE is correct and that the ISE is sending the redirect URL for the client. Which configuration check can help to resolve the issue?

  1. Verify if DADIUS accounting interim update is enabled on the guest SSID.

  2. Verify if SNMP NAC is enabled on the guest SSID.

  3. Verify if the SSID is configured for VVPA2-AES Layer 2 security.

  4. Verify if AAA override is enabled for the guest SSID.

  5. Verify if the RFC 3567 support is enabled under ISE configuration on the Cisco WLC.

  6. Verify if authentication priority for web-auth is set to RADIUS.

Answer: D Explanation:

http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732- central-web-auth-00.html

Question No: 18 – (Topic 1)

You want to set up Prime Infrastructure to be notified when a device configuration has changed. Which option is available in Prime Infrastructure 2.2?

  1. Set up Prime Infrastructure to send an email containing the change audit report on a regularity scheduled basis.

  2. Set up Prime Infrastructure to send an email containing the configuration changes(s) immediately after the configuration change is detected.

  3. Set up Prime Infrastructure to send an email containing the change audit report immediately after the configuration change is detected.

  4. Set up Prime Infrastructure to send an email containing the device configuration change(s) on a regularly scheduled basis.

Answer: A Explanation:

http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/2- 2/user/guide/pi_ug.pdf

Question No: 19 – (Topic 1)

Which IEEE protocol can help a wireless client device to identify nearby APs that are available as roaming targets?

A. 802.11h B. 802.11ac C. 802.11k D. 802.11n E. 802.11w

Answer: C Explanation:

https://support.apple.com/en-gb/HT202628 https://documentation.meraki.com/MR/WiFi_Basics_and_Best_Practices/802.11k_and_802


http://www.cisco.com/c/en/us/td/docs/wireless/controller/8-1/Enterprise-Mobility-8-1- Design-Guide/Enterprise_Mobility_8-1_Deployment_Guide/wlanrf.html

Question No: 20 – (Topic 1)

On a Cisco 5760 WLC, which of the below is not part of the initial setup script?

  1. Wireless management interface

  2. Host name

  3. HTTP server login account

  4. SNMP Network Management

  5. NTP server

  6. Enable password

  7. Default routing protocol

Answer: G Explanation:


CT5760ControllerandCatalyst3850SwitchConfigurationExample-Cisco http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-vlan/116342-config- wlc-


5760 WLC Initial Configuration

This section outlines the steps to succesfully configure the 5760 WLC in order to host wireless services.

Configure Setup Script

— System Configuration Dialog — Enable secret warning


In order to access the device manager, an enable secret is required

If you enter the initial configuration dialog, you will be prompted for the enable secret

If you choose not to enter the intial configuration dialog, or if you exit setup without setting the enable secret,

please set an enable secret using the following CLI in configuration mode- enable secret 0

lt;cleartext passwordgt;


Would you like to enter the initial configuration dialog? [yes/no]: yes

At any point you may enter a question mark #39;?#39; for help. Use ctrl-c to abort configuration dialog at any prompt. Default settings are in square brackets #39;[]#39;.

Basic management setup configures only enough connectivity for management of the system, extended setup will ask you to configure each interface on the system

Would you like to enter basic management setup? [yes/no]: yes Configuring global parameters:

Enter host name [Controller]: w-5760-1

The enable secret is a password used to protect access to privileged EXEC and configuration modes. This password, after

entered, becomes encrypted in the configuration. Enter enable secret: cisco

The enable password is used when you do not specify an

enable secret password, with some older software versions, and some boot images. Enter enable password: cisco

The virtual terminal password is used to protect access to the router over a network interface.

Enter virtual terminal password: cisco

Configure a NTP server now? [yes]: Enter ntp server address :

Enter a polling interval between 16 and 131072 secs which is power of 2:16 Do you want to configure wireless network? [no]: no

Setup account for accessing HTTP server? [yes]: yes Username [admin]: admin

Password [cisco]: cisco Password is UNENCRYPTED.

Configure SNMP Network Management? [no]: no Current interface summary

Any interface listed with OK? value quot;NOquot; does not have a valid configuration InterfaceIP-AddressOK? MethodStatusProtocol Vlan1unassignedNOunsetupup GigabitEthernet0/0unassignedYESunsetupup Te1/0/1unassignedYESunsetupup

Te1/0/2unassignedYESunsetdowndown Te1/0/3unassignedYESunsetdowndown Te1/0/4unassignedYESunsetdowndown Te1/0/5unassignedYESunsetdowndown Te1/0/6unassignedYESunsetdowndown Enter interface name used to connect to the

management network from the above interface summary: vlan1 Configuring interface Vlan1:

Configure IP on this interface? [yes]: yes IP address for this interface:

Subnet mask for this interface [] : Class C network is, 24 subnet bits; mask is /24

Wireless management interface needs to be configured at startup It needs to be mapped to an SVI that#39;s not Vlan 1 (default)

Enter VLAN No for wireless management interface: 120 Enter IP address :

Enter IP address mask:

The following configuration command script was created: w-5760-1

enable secret 4 tnhtc92DXBhelxjYk8LWJrPV36S2i4ntXrpb4RFmfqY^Q enable password cisco line vty 0 15

password cisco

ntp server maxpoll 4 minpoll 4 username admin privilege 15 password cisco no snmp-server


no ip routing


interface Vlan1 no shutdown

ip address


interface GigabitEthernet0/0 shutdown no ip address


interface TenGigabitEthernet1/0/1


interface TenGigabitEthernet1/0/2


interface TenGigabitEthernet1/0/3


interface TenGigabitEthernet1/0/4


interface TenGigabitEthernet1/0/5


interface TenGigabitEthernet1/0/6 vlan 120

interface vlan 120

ip addr exit

wireless management interface Vlan120



[0] Go to the IOS command prompt without saving this config. [1] Return back to the setup without saving this config.

[2] Save this configuration to nvram and exit. Enter your selection [2]: 2 Building configuration…

Compressed configuration from 2729 bytes to 1613 bytes[OK]

Use the enabled mode #39;configure#39; command to modify this configuration. Press RETURN to get started!

