- 4.9/5.0
- 277 Questions
- Updated on: 27-Aug-2026
- Implementing Cisco Enterprise Wireless Networks (ENWLSI)
- 22775 Prepared
Free Cisco 300-430 Practice Questions 2026 | Implementing Cisco Enterprise Wireless Networks (ENWLSI)
A customer has 10 Cisco 3700 Series APs in autonomous mode installed at a warehouse facility. A new VoWLAN service is being deployed to support Cisco WLAN phones. All wired QoS is configured. The customer requires that all VoWLAN signaling and RTP traffic be prioritized between the wired and wireless networks. Which configuration is required?
A. Apply a Cisco AVC profile for RTP and signaling on all the APs.
B. Switch on Fastlane on all the APs.
C. Set EDCA on all the APs to optimize voice and video.
D. Enable AWID priority mapping on all the APs
Explanation:
The requirement is to prioritize VoWLAN signaling and RTP traffic between the wired and wireless networks on autonomous APs. The key is ensuring consistent priority handling across different network types.
AVVID priority mapping addresses this specific need. The 802.11e protocol assigns a User Priority of 6 to voice packets, while Cisco wired networks assign a Class of Service (CoS) value of 5 . Enabling AVVID priority mapping automatically maps Ethernet packets tagged as CoS 5 to 802.11e UP 6 when they are exchanged between the wired and wireless sides of the access point . This ensures the AP applies the correct priority to voice packets for compatibility with Cisco AVVID (Architecture for Voice, Video and Integrated Data) networks . According to the autonomous AP configuration guide, this feature is enabled by default and is crucial for proper end-to-end QoS for voice .
Why the others are wrong:
A. Apply a Cisco AVC profile for RTP and signaling:
AVC (Application Visibility and Control) is a feature primarily available on controller-based (lightweight) APs and WLCs, not on autonomous APs . It is not the required configuration for this specific autonomous deployment.
B. Switch on Fastlane:
Fastlane is also a feature used on WLCs (specifically AireOS 8.3+) and iOS/Mac devices . It is not a configuration option for autonomous APs.
C. Set EDCA to optimize voice and video:
While adjusting EDCA (Enhanced Distributed Channel Access) parameters can help with voice quality, it is not the specific configuration required to maintain consistent QoS marking between wired and wireless networks. Cisco strongly recommends using default EDCA settings to avoid unexpected traffic blockages . This option does not address the CoS-to-UP mapping required.
References:
Cisco IOS Configuration Guide for Autonomous Cisco Aironet Access Points, Release 15.3(3)JE
Cisco 300-430 ENWLSI exam topics on QoS implementation
An engineer is setting up a WLAN to work with a Cisco ISE as the AAA server. The company policy requires that all users be denied access to any resources until they pass the validation. Which component must be configured to achieve this stipulation?.
A. WPA2 passkey
B. AAA override
C. CPU ACL
D. preauthentication ACL
Explanation:
The key requirement here is to deny all access to network resources until a client has passed validation from the Cisco ISE server. A preauthentication ACL (Access Control List) is the component designed for this purpose.
This ACL is applied to the WLAN before a client authenticates. Its main job is to restrict access during the initial connection phase. Typically, it is configured to only permit the essential traffic needed for the authentication process itself—for example, allowing the client to communicate with the ISE server, and possibly permitting DNS and DHCP traffic .
Why the others are wrong:
A. WPA2 passkey:
This is a pre-shared key (PSK) used for security and encryption (WPA2-Personal). It does not provide a mechanism to restrict network access before authentication in an enterprise environment with ISE.
B. AAA override:
This feature is used to apply policies like VLAN assignment, ACLs, and QoS after successful authentication, based on the user's identity and role . It is not the component that denies pre-authentication access .
C. CPU ACL:
This ACL controls traffic destined for the CPU of the wireless LAN controller itself, protecting the control plane . It does not control a client's access to network resources.
References:
Cisco Configuration Guides referencing preauthentication ACLs for web authentication .
Cisco documentation on ISE NAC configuration, explicitly recommending the creation of a preauthentication ACL for ISE communication .
An engineer set up RADIUS for WLC management to harden the configuration. Read-only access must be provided to a user. Which Service-Type attribute must be configured on the RADIUS server to meet this requirement?
A. Callback Login
B. Administrative
C. Call Check
D. NAS Prompt
Explanation:
The RADIUS Service-Type attribute is used to specify the type of service a user is requesting or has been authorized to receive . The Administrative value is specifically designated for granting a user management access to the network device itself, as opposed to network access.
When the Administrative Service-Type is configured on the RADIUS server and returned to the WLC, it authorizes the user for administrative functions. While the basic level of access is determined separately (often via privilege levels), this attribute indicates the user's role is for device management. Within this administrative context, the user can be granted read-only permissions, for example, by setting a privilege level of 1 through additional RADIUS attributes .
Why the others are wrong:
A. Callback Login:
This is a legacy value used in dial-up networking to request a callback from the NAS to a specific number for security or billing purposes. It is not relevant to granting administrative access.
C. Call Check:
This is not a standard Service-Type value. It is unrelated to user authorization for network or device access.
D. NAS Prompt:
This Service-Type was intended for devices that require interactive prompt-based login. However, it is not the correct attribute to use for granting administrative read-only permissions on a WLC.
References:
IETF RFC 2865 defines RADIUS and the Service-Type attribute .
IETF RFC 3575 lists Administrative (6) as a recognized Service-Type value for management access .
A wireless barcode scanner on a plant floor finds the closest AP that is set to power level 7 statically. However, the scanner has trouble associating and sending data. Which action fixes this issue?
A. Turn on Band Steering in the controller to move the scanner to 5 GHz.
B. Add QoS for the application in the network.
C. Turn on TPC in the controller.
D. Add more APs to the area.
Explanation:
The barcode scanner is having trouble associating and sending data because the AP's transmit power is set statically to a high level. This creates an asymmetric connection: the AP's strong signal reaches the scanner, but the scanner, a low-powered device, cannot transmit back to the AP with the same strength. This is a known problem, as controllers do not mitigate coverage holes caused by clients that are statically set to a power level .
Enabling Transmit Power Control (TPC) resolves this. TPC is a Radio Resource Management (RRM) feature that dynamically adjusts an AP's transmit power . Instead of blasting a static signal, TPC allows the AP to coordinate with the controller and lower its power to an optimal level . This better matches the scanner's weaker signal, solving the asymmetry issue and providing a more reliable connection.
Why the others are wrong:
A. Band Steering:
This encourages dual-band clients to use 5 GHz to reduce 2.4 GHz congestion. It does not fix mismatched transmit power between the AP and the client.
B. Add QoS:
Quality of Service prioritizes certain data traffic. It cannot improve the physical signal strength or resolve association problems caused by low client power.
D. Add more APs:
Adding APs would create a denser environment, but with a statically high power level, it would likely increase interference rather than help. TPC is the recommended method to manage power levels effectively .
References:
Cisco Wireless Controller Configuration Guide – TPC and RRM .
Cisco 802.11h and TPC Overview .
An engineer is using Cisco Prime Infrastructure reporting to monitor the state of security on the WLAN. Which output is produced when the Adaptive wIPS Top 10 AP report is run?
A. last 10 wIPS events from monitor mode APs
B. last 10 wIPS events from sniffer mode APs
C. last of 10 sniffer mode APs with the most wIPS events
D. last of 10 monitor mode APs with the most wIPS events
Explanation:
The Adaptive wIPS Top 10 AP report in Cisco Prime Infrastructure is specifically designed to list the most recent wireless intrusion prevention events detected by access points operating in monitor mode. Cisco's official configuration guide for Adaptive wIPS defines this report as one that "lists the last 10 events reported for monitor access points". This matches the description in option A.
To provide this data, the report first identifies which APs have generated the highest number of adaptive wIPS alarms, displaying the top ten, and then presents a summary of their most recent events. The information for this report is sourced from the Mobility Services Engine (MSE), which collects and processes wIPS data from the controllers.
Why the Others Are Wrong:
B & C (sniffer mode APs):
The report is specific to monitor mode APs. Sniffer mode APs are used for a different function—capturing raw 802.11 frames for deep packet analysis with tools like AiroPeek—and are not the source for this particular report.
D (last of 10 monitor mode APs with the most wIPS events):
While the report does consider the top APs, its primary output is the last 10 events from these monitors. It is not a list of "the last of 10 monitor mode APs".
References:
Cisco Adaptive Wireless Intrusion Prevention System Configuration Guide – defines the report's function.
ExamTopics discussion confirming the output of the report.
An employee with administrative rights has a Cisco OEAP at home. The employee must add an SSID to connect personal devices. Which two actions enable the employee to access the AP configuration? (Choose two.)
A. Enter the IP address of the OEAP in a web browser.
B. Obtain the IP address of the OEAP from a sticker on the device.
C. Obtain the IP address of the OEAP from the home router of the employee.
D. Connect to the preconfigured SSID and obtain the IP address of the AP from the welcome page.
E. Connect to the IP address of the OEAP via SSH.
C. Obtain the IP address of the OEAP from the home router of the employee.
Explanation:
Cisco OfficeExtend Access Points (OEAPs) provide secure remote corporate connectivity from home environments. When the WLC enables the Disable Local Management setting off or grants local administrative privileges to the OEAP user, the employee can access the local HTTP/HTTPS management GUI on the AP to configure local personal SSIDs:
Obtain IP Address from Home Router (Option C):
The WAN/uplink interface of the OEAP receives a dynamic private IP address assigned via DHCP from the employee's home ISP router/gateway. Checking the client lease table or DHCP status page on the home router provides the exact IP address assigned to the OEAP.
Access via Web Browser (Option A):
Once the employee knows the assigned IP address, entering that IP address (http://
Why Other Options Are Incorrect:
B. Obtain the IP address of the OEAP from a sticker on the device:
Physical labels on Cisco APs display MAC addresses, serial numbers, and model identifiers—not dynamically assigned local DHCP IP addresses.
D. Connect to the preconfigured SSID and obtain the IP address of the AP from the welcome page:
Preconfigured corporate SSIDs tunnel traffic directly to the corporate WLC over DTLS without serving a local welcome page that reveals the AP's local home-network IP address.
E. Connect to the IP address of the OEAP via SSH:
Local management on OfficeExtend APs for end users is provided through a web GUI interface rather than command-line SSH access.
Reference:
Cisco OfficeExtend Access Point Deployment Guide: Outlines local GUI management capabilities for OEAP devices, detailing how remote users can log into the local web interface via its DHCP-assigned home router IP address to configure personal local SSIDs.
Which role does an engineer configure for administrative access to the wireless infrastructure, using Cisco ISE, to allow configuration of the WLC syslog configuration?
A. MANAGEMENT
B. SECURITY
C. CONTROLLER
D. WIRELESS
Explanation:
Syslog settings are configuration parameters for system-level logging and monitoring functions. In the Cisco WLC, these settings are located under the Management tab in the GUI .
When using Cisco ISE for TACACS+ device administration, the authorization roles that can be assigned to a user correspond directly to these GUI menu sections. The available roles include WLAN, Controller, Wireless, Security, Management, and Commands, each mapping to its respective tab . Therefore, to permit a user to configure syslog settings, the administrator must assign the MANAGEMENT role in the ISE authorization profile. This grants the user access to the Management menu, which contains the syslog configuration options .
Why the others are wrong:
B. SECURITY:
This role provides access to security configurations like ACLs and firewall rules, but does not cover system logging tasks .
C. CONTROLLER:
This role grants access to general controller settings such as network interfaces, but it is not the specific role required for system management functions like syslog configuration .
D. WIRELESS:
This role is intended for wireless-specific configurations, such as SSIDs and radio settings, and is unrelated to system logging .
References:
Cisco ISE Administrator Guide – TACACS+ common task profiles for WLC .
Cisco WLC TACACS+ configuration documentation .
Refer to the exhibit.

The security team has implemented ISE as an AAA solution for the wireless network. The
wireless engineer notices that though clients are able to authenticate successfully, the ISE
policies that are designed to place them on different interfaces are not working. Which
configuration must be applied in the RADIUS Authentication Settings section from the ISE
Network Device page?
A. Disable KeyWrap.
B. Use ASCII for the key input format.
C. Change the CoA Port.
D. Correct the shared secret.
Explanation:
The issue is that clients authenticate successfully, but ISE policies like dynamic VLAN assignment are not applied. This is a classic symptom of a Change of Authorization (CoA) communication failure. After successful 802.1X authentication, ISE uses a CoA request to push policy attributes (like a VLAN ID or downloadable ACL) to the Wireless LAN Controller. If the WLC does not receive or process this CoA, the client session remains in its initial state.
The most common cause of this is a port mismatch. The exhibit shows the CoA Port is set to 1800. However, Cisco's default CoA port for its devices is 1700 . A configuration using port 1800 would cause ISE to send CoA requests to a port the WLC is not listening on, effectively breaking dynamic policy enforcement.
Why the others are wrong:
A. Disable KeyWrap:
This is an optional RADIUS security setting. If misconfigured, it would likely break authentication entirely, which is not the case here.
B. Use ASCII for key input format:
This only changes how the shared secret is entered on the ISE page. It does not affect CoA functionality.
D. Correct the shared secret:
A shared secret mismatch would prevent all RADIUS communication, meaning clients would not authenticate successfully at all.
References:
Cisco ISE documentation: Default CoA port is 1700 for Cisco devices and 3799 for non-Cisco vendors .
Troubleshooting guides for mixed-vendor environments list CoA port mismatches as a primary cause of dynamic authorization failures .
A customer must provide a secure wireless network from a Cisco Catalyst 9800 Series Wireless Controller to a Cisco AP to remote users The corporate WLAN must be provided over the Internet to specific locations and support a locally-installed IP phone Which two actions accomplish this configuration? (Choose two )
A. Configure NAT on the physical interface
B. Enable Local Switching under the WLAN
C. Create a Flex Group and add the AP
D. Enable Office Extend AP on the Flex Profile.
E. Configure Remote LAN under the Remote LAN
D. Enable Office Extend AP on the Flex Profile.
Explanation:
To provide a secure corporate WLAN over the Internet to remote users using a Cisco Catalyst 9800 Wireless Controller, you need to configure the AP to operate in OfficeExtend (OEAP) mode. This mode uses FlexConnect technology with specific enhancements for remote deployment.
Create a Flex Group and add the AP (Option C):
The remote AP must be part of a FlexConnect group to share configuration and enable local switching capabilities. The Flex Group contains the APs that will operate as OEAPs and allows them to share settings like VLANs and ACLs.
Enable Office Extend AP on the Flex Profile (Option D):
OfficeExtend mode is enabled within the Flex Profile on the Catalyst 9800. This profile contains the OEAP-specific settings, such as enabling the OEAP feature, configuring DTLS encryption, and setting up split tunneling. This step is mandatory to activate the OEAP functionality.
Why the others are wrong:
A. Configure NAT on the physical interface:
NAT is not configured on the WLC for OEAP. The AP typically resides behind a home router that performs NAT. The OEAP establishes a CAPWAP tunnel through NAT without requiring NAT configuration on the WLC.
B. Enable Local Switching under the WLAN:
While local switching is used in OEAP deployments to offload traffic locally, the OEAP mode is not enabled directly on the WLAN. It is enabled within the Flex Profile. Local switching is a separate configuration applied to the WLAN.
E. Configure Remote LAN under the Remote LAN:
Remote LAN (RLAN) is a feature for extending wired connectivity through an OEAP, not the primary method for enabling the OEAP mode itself. The RLAN is configured under the Flex Profile or Policy Profile, not under a separate "Remote LAN" menu.
References:
Cisco Catalyst 9800 Series Wireless Controller Configuration Guide – OEAP and FlexConnect Profile configuration.
Cisco 300-430 ENWLSI Official Certification Guide – Chapter on OfficeExtend APs.
What are two considerations when deploying a Cisco Hyperlocation? (Choose two.)
A. NTP configuration is available, but not recommended.
B. The Cisco Hyperlocation feature must be enabled only on the wireless LAN controller.
C. After enabling Cisco Hyperlocation on Cisco CMX, the APs and the wireless LAN controller must be restarted.
D. The Cisco Hyperlocation feature must be enabled on the wireless LAN controller and Cisco CMX.
E. If the Cisco CMX server is a VM, a high-end VM is needed for Cisco Hyperlocation deployments.
E. If the Cisco CMX server is a VM, a high-end VM is needed for Cisco Hyperlocation deployments.
Explanation:
Dual System Enabling Requirement (Option D):
Cisco Hyperlocation requires functional enablement across both network control and analytics engines. The feature must be enabled on the Wireless LAN Controller (WLC) so access points collect Angle of Arrival (AoA) and BLE metrics, and it must be enabled on Cisco CMX under system location settings to process and render location coordinates.
High-End Virtual Machine Resource Sizing (Option E):
Processing high-density AoA calculations and real-time FastLocate data streams places significant compute demands on Cisco CMX. Cisco specifies that virtualized CMX instances deploying Hyperlocation require a High-End VM template (typically 16–20 vCPUs, 32–64 GB RAM, and 500 GB+ disk storage).
Why Other Options Are Incorrect:
A. NTP configuration is available, but not recommended:
NTP synchronization is mandatory across the WLC, CMX, and APs to ensure accurate timestamping for location calculations.
B. The Cisco Hyperlocation feature must be enabled only on the wireless LAN controller:
Enabling Hyperlocation on the WLC alone is insufficient; CMX must also have Hyperlocation enabled to process raw signal data.
C. After enabling Cisco Hyperlocation on Cisco CMX, the APs and the wireless LAN controller must be restarted:
Enabling Hyperlocation requires restarting the CMX services (cmxctl restart) and the Access Points, but the WLC itself does not require a reboot.
References:
Cisco AP4800 Hyperlocation Deployment Guide: Specifies that Hyperlocation requires configuration on both WLC and CMX, mandating a High-End CMX VM deployment profile to handle system processing.
Cisco Wireless LAN Controller Configuration Guide (Hyperlocation): Details required steps for enabling Hyperlocation profiles across controllers and CMX engines.
| Page 11 out of 28 Pages |