- 4.9/5.0
- 277 Questions
- Updated on: 27-Aug-2026
- Implementing Cisco Enterprise Wireless Networks (ENWLSI)
- 22775 Prepared
Free Cisco 300-430 Practice Questions 2026 | Implementing Cisco Enterprise Wireless Networks (ENWLSI)
An engineer must achieve the highest level of location accuracy possible for a new mobile application. Which technology must be implemented for this use case?
A. Time Difference of Arrival
B. Bluetooth Low Energy
C. RSS lateration
D. ToA lateration
Explanation:
Cisco Hyperlocation is the premier solution for high-accuracy Wi-Fi client tracking, delivering an average accuracy of 1 to 3 meters . This performance is achieved by leveraging specialized AP hardware, such as the Cisco Aironet 4800 series, which uses an advanced antenna array to precisely measure the Angle of Arrival (AoA) of client signals . Location calculations also consider factors like RSSI for a very accurate assessment . For optimal performance, Hyperlocation requires unobstructed line-of-sight between the client and at least four Hyperlocation APs that form a "convex hull" around the client . Accurate AP placement documentation is also critical, as location errors are compounded if AP locations or orientation are off by as little as an inch .
Why the others are wrong:
A. Time Difference of Arrival (TDoA):
While a valid location technique, it is not the primary, top-tier accuracy solution deployed by Cisco, which focuses on Hyperlocation (AoA) for its most precise use cases .
B. Bluetooth Low Energy (BLE):
Physical BLE beacons have substantial shortcomings, including battery life and maintenance costs . Cisco's virtual BLE solution (Beacon Point) is simpler to manage but still does not generally match the median 1-3 meter accuracy of Hyperlocation for active Wi-Fi clients .
C. RSSI Lateration:
This method relies solely on Received Signal Strength Indication (RSSI) and is significantly less accurate than Hyperlocation. It is the baseline technique used before Hyperlocation is enabled .
References:
Cisco Hyperlocation Deployment Guide – AoA technology and accuracy requirements .
Cisco Hyperlocation Solution Data Sheet – 1 to 3 meter location accuracy .
Cisco Connected Mobile Experiences – Hyperlocation vs. RSSI performance .
The CTO of an organization wants to ensure that all Android devices are placed into a separate VLAN on their wireless network. However, the CTO does not want to deploy ISE. Which feature must be implemented on the Cisco WLC?
A. RADIUS server overwrite interface
B. AAA override
C. WLAN local policy
D. custom AVC profile
Explanation:
The requirement is to place Android devices into a separate VLAN without deploying Cisco ISE. The feature that meets this exact need on the Cisco WLC is WLAN Local Policy (also known as native profiling and policy classification) .
How it works: The WLC profiles endpoints natively using attributes like MAC OUI, DHCP options, and HTTP user-agent strings. When a client connects, the WLC classifies the device type (e.g., Android, Windows, iPhone) and applies the action defined in the local policy . For instance, you can create a policy that matches "Device Type" as "Android" and then assign a specific VLAN ID as the action . This configuration is done directly on the WLC and does not require any external RADIUS server or ISE .
Why the others are wrong:
B. RADIUS server overwrite interface:
This is not a valid feature name on the Cisco WLC. The correct feature for RADIUS-based VLAN assignment is "AAA override" .
C. AAA override:
This feature enables dynamic VLAN assignment based on attributes returned by a RADIUS server (such as Cisco ISE) . Since the CTO explicitly does not want to deploy ISE, AAA override is not suitable for this scenario . Additionally, if AAA override is enabled, it takes higher precedence than local policies, which would interfere with the desired configuration .
D. custom AVC profile:
Application Visibility and Control (AVC) profiles are used for monitoring, marking (QoS), dropping, or rate-limiting specific application traffic (e.g., Facebook, YouTube) . AVC does not support dynamic VLAN assignment based on device type .
References:
Cisco WLC Configuration Guide (Release 7.5) – Local Policies based on device type .
Exam discussion confirming WLAN local policy is the correct answer for this scenario .
Cisco Native Profiling documentation showing Android device classification and VLAN assignment .
What must be configured on the Global Configuration page of the WLC for an access point to use 802.1x to authenticate to the wired infrastructure?
A. supplicant credentials
B. RADIUS shared secret
C. local access point credentials
D. TACACS server IP address.
Explanation:
For an AP to authenticate to the wired network using 802.1X, it must act as a supplicant that presents credentials to the switch authenticator. The exact configuration for this is found on the Global Configuration page of the WLC.
On this page (accessible via Wireless > Access Points > Global Configuration), the section labeled 802.1x Supplicant Credentials is where you enable 802.1X authentication and configure the username and password that will be inherited by all APs joining the controller. This provides the credentials the AP needs to authenticate to the switch and RADIUS server.
Why the others are wrong:
B. RADIUS shared secret:
This is used to secure RADIUS communication between the switch (acting as the authenticator) and the RADIUS server, not for the AP to authenticate to the switch.
C. local access point credentials:
This is a less precise term. The required configuration is the 802.1X supplicant credentials (username/password) on the Global Configuration page.
D. TACACS server IP address:
TACACS+ is primarily used for device administration (like AAA for login to the WLC or switch), not for 802.1X port-based authentication of an AP.
References
Cisco Wireless Controller Configuration Guide – Configuring Authentication for Access Points (Global Configuration page).
Refer to the exhibit.
Which two items must be supported on the VoWLAN phones to take full advantage of this
WLAN configuration? (Choose two.)
A. TSPEC
B. SIFS
C. 802.11e
D. WMM
E. APSD
D. WMM
Explanation:
Wi-Fi Multimedia / WMM (Option D):
The exhibit shows Call Admission Control (CAC) enabled on the 802.11a/5GHz radio. CAC requires Wi-Fi Multimedia (WMM) to classify audio traffic into specific Access Categories (AC_VO for voice). Without WMM support on the VoWLAN phone, the client cannot tag frames with appropriate Quality of Service (QoS) priorities or negotiate bandwidth reservations with the access point.
Traffic Specification / TSPEC (Option A):
When Admission Control (ACM) is checked, clients are mandated to request explicit bandwidth allocation before establishing a call. VoWLAN phones use TSPEC requests (a subset of WMM/802.11e specifications) to negotiate CAC with the controller/AP. If a phone lacks TSPEC support, its voice call attempts will be blocked or relegated to best-effort traffic when ACM is enforced.
Why Other Options Are Incorrect:
B. SIFS:
Short Interframe Space (SIFS) is a fundamental, fixed IEEE 802.11 MAC-layer timing interval used across all wireless operations; it is not a configurable end-user phone feature required for Call Admission Control.
C. 802.11e:
While WMM is derived from the IEEE 802.11e standard, Cisco enterprise VoWLAN implementations specifically negotiate CAC and QoS parameters through the WMM and TSPEC frame extensions rather than requiring standalone 802.11e signaling.
E. APSD:
Automatic Power Save Delivery (U-APSD) manages power-saving sleep cycles for battery-operated wireless handsets, but it is not shown or involved in the Call Admission Control (CAC) parameters displayed in the exhibit.
References:
Cisco Wireless Controller Configuration Guide (Configuring Voice Parameters): Highlights that enabling Admission Control (ACM) requires WMM-capable clients that send TSPEC requests to ensure medium time allocation and prevent cell overloading.
Refer to the exhibit
An engineer needs to manage non-802.11 interference. What is observed in the output on
PI?
A. Several light interferers are collectively impacting connectivity at this site.
B. The three Individual clusters shown Indicate poor AP placement.
C. At least one strong interferer is impacting connectivity at this site.
Explanation:
The exhibit shows a CleanAir interference map from Prime Infrastructure (PI). The colored dots and clusters represent interferers detected by CleanAir-capable APs. The presence of five distinct numbered clusters (1 through 5) in the Living Room area indicates multiple interferers are being tracked.
However, the key observation is that cluster #5 is centrally located and appears as a dense, concentrated red/orange area. In CleanAir visualizations, the color and intensity of the interferer icon indicate severity:
Red/Orange = Severe or Strong interference.
Yellow = Moderate.
Green/Blue = Mild or Weak.
The exhibit shows at least one strong interferer (cluster #5) in the middle of the Living Room, which is likely causing significant connectivity issues for nearby clients and APs.
Why the others are wrong:
A. Several light interferers are collectively impacting connectivity:
The exhibit shows dense, colored clusters, not "light" interferers. Light interferers would appear as small, scattered dots without concentrated clustering.
B. The three individual clusters shown indicate poor AP placement:
The clusters represent interferers, not AP placement issues. Poor AP placement would appear as coverage holes or low signal-to-noise ratio, not as interference clusters.
References:
Cisco Prime Infrastructure CleanAir Documentation – Interference visualization and severity indicators.
Cisco 300-430 ENWLSI Official Certification Guide – Chapter on CleanAir and interference management.
Which two protocols are used to communicate between the Cisco MSE and the Cisco Prime Infrastructure network management software? (Choose two.)
A. HTTPS
B. Telnet
C. SOAP
D. SSH
E. NMSP
E. NMSP
Explanation:
SOAP (Simple Object Access Protocol):
Cisco Prime Infrastructure interfaces directly with the Cisco Mobility Services Engine (MSE) using SOAP/XML web services API calls. Prime Infrastructure uses SOAP to push service configurations (such as CAS location tracking, wIPS policies, or floor maps) to the MSE and query analytical reports.
HTTPS (Hypertext Transfer Protocol Secure):
All API interactions and administrative communication sessions between Cisco Prime Infrastructure and the MSE are encrypted via HTTPS (typically over TCP port 443). HTTPS provides transport-layer security and data integrity for SOAP payloads transferred between the management server and the location engine.
Why Other Options Are Incorrect:
B. Telnet:
Telnet sends unencrypted cleartext across the network and is disabled for administrative management between Cisco enterprise wireless platforms.
D. SSH:
While SSH is used for CLI administration (logging into the underlying Linux shell on the MSE/Prime appliances), it is not the programmatic management protocol used for Prime Infrastructure GUI integration and service synchronizations.
E. NMSP:
Network Mobility Services Protocol (NMSP) runs strictly between the Wireless LAN Controller (WLC) and the MSE to exchange client RSSI telemetry and wIPS events; it is not used directly for communication between Cisco Prime Infrastructure and the MSE.
References
Cisco Unified Wireless Network Protocol and Port Matrix: Details management channels, specifying SOAP/XML over HTTPS for Cisco Prime Infrastructure-to-MSE integration.
Cisco Prime Infrastructure User Guide: Details the requirements for adding and synchronizing an MSE node using SOAP web services over HTTPS.
A customer is deploying local web authentication. Which software application must be implemented on Cisco ISE to utilize as a directory service?
A. Solaris Directory Service
B. LDAP
C. SAML
D. Novell eDirectory
Explanation:
To support Local Web Authentication (LWA) using Cisco ISE as a centralized database, the directory service that must be implemented on ISE is LDAP (Lightweight Directory Access Protocol) . When a user enters credentials, the WLC sends a RADIUS Access-Request to ISE, which then queries the configured external identity source . For this use case, the external source is an LDAP-compliant directory .
Cisco ISE can integrate with LDAP v3 servers, including Microsoft Active Directory, Sun Directory Server, and Novell eDirectory, using pre-defined schemas . The configuration is done by navigating to Administration > Identity Management > External Identity Sources > LDAP in the ISE GUI .
Why the others are wrong:
A. Solaris Directory Service:
This is not a valid directory service product name. Cisco ISE supports Sun Directory Server, but "Solaris Directory Service" does not exist as a standalone directory service option.
C. SAML:
Security Assertion Markup Language (SAML) is a federation protocol used for single sign-on (SSO) and web-based authentication, not for local web authentication with LDAP. It is not a directory service.
D. Novell eDirectory:
While Novell eDirectory is a valid LDAPv3-compliant directory that can be used , LDAP is the protocol that must be implemented. The question asks for the software application, and LDAP is the correct generic answer.
References
Cisco ISE Admin Guide – External Identity Sources: LDAP configuration .
Study CCNP – WebAuth Types: LWA with external database on RADIUS or LDAP server .
A new MSE with wIPS service has been installed and no alarm information appears to be reaching the MSE from controllers. Which protocol must be allowed to reach the MSE from the controllers?
A. SOAP/XML
B. NMSP
C. CAPWAP
D. SNMP
Explanation:
The issue described is that no wIPS alarm information is reaching the new MSE from the WLCs. For wIPS (Wireless Intrusion Prevention System) to function, the communication chain between the WLC and the MSE relies on the Network Mobility Services Protocol (NMSP) .
NMSP is the secure, two-way protocol that manages all communication between the controller and the MSE. In a wIPS deployment, it provides the specific pathway for alarm data to be aggregated from controllers and forwarded to the wIPS service running on the MSE . The MSE then forwards these alarms to the management system (like Cisco Prime Infrastructure) using SNMP traps .
Therefore, if NMSP is blocked or not functioning correctly between the controllers and the MSE, no alarm information will be received by the MSE, even if the wIPS APs are correctly detecting attacks.
Why the others are wrong:
A. SOAP/XML:
This protocol is used for communication between the MSE and the management system (like Prime Infrastructure) for configuration and profile management, not for the WLC-to-MSE alarm data flow .
C. CAPWAP:
This protocol is used for communication between the Access Points and the Controller. Alarm data is encapsulated inside the CAPWAP control tunnel between the AP and the WLC . However, it is not the protocol used for communication from the WLC to the MSE.
D. SNMP:
While SNMP traps are used to forward wIPS alarm information from the MSE to the management system, the communication from the controller to the MSE for wIPS alarm data uses NMSP .
References:
Cisco Adaptive wIPS Deployment Guide – wIPS Alarm Flow and NMSP specification .
Cisco Enterprise Mobility Design Guide – Adaptive wIPS architecture .
Cisco 9800 Series WLC Configuration Guide – NMSP parameters .
What must be configured on ISE version 2.1 BYOD when using Single SSID?
A. no authentication
B. WPA2
C. open authentication
D. 802.1x
Explanation:
In a Cisco ISE version 2.1 BYOD deployment using a Single SSID design, the same wireless network is used for both the initial onboarding process and for subsequent, fully authorized network access . For this model to function, the SSID must be configured for 802.1X authentication on the WLC .
Why the others are wrong
A. open authentication & C. no authentication:
While similar, these options are incorrect for the Single SSID model. In Cisco ISE BYOD, an open, unauthenticated WLAN is characteristic of a Dual SSID design. In that flow, the open SSID is used exclusively for device onboarding and redirection to a guest portal, and clients must connect to a separate, secure SSID for full access . The Single SSID model requires a single, secure WLAN from the very beginning .
D. WPA2:
WPA2 is the Wi-Fi security protocol that secures the wireless link between the client and the AP, but it is not an authentication method. The question asks for the configuration on the ISE to enable the authentication flow. For Single SSID BYOD, it is the 802.1X authentication framework on the WLC that facilitates the required EAP exchanges with the ISE .
References:
Cisco BYOD Single SSID Design Overview
ISE BYOD Authorization Policies
Exam discussion on Single SSID vs. Dual SSID authentication
An engineer completed the basic installation for two Cisco CMX servers and is in the process of configuring high availability, but it fails. Which two statements about the root of the issue are true? (Choose two.)
A. The Cisco CMX instances are installed in the same subnet.
B. The types of the primary and secondary Cisco CMX installations differ.
C. The delay between the primary and secondary instance is 200 ms.
D. The sizes of the primary and secondary Cisco CMX installations differ.
E. Both Cisco CMX installations are virtual
D. The sizes of the primary and secondary Cisco CMX installations differ.
Explanation:
Strict Type Matching Requirement (Option B):
For Cisco CMX High Availability (HA) pairing to form successfully, both the primary and secondary CMX instances must be deployed on the exact same installation model type—meaning both must be virtual appliances (VMs) or both must be dedicated physical appliances. Mixing a physical appliance with a VM causes high availability pairing to fail validation.
Strict Size Matching Requirement (Option D):
Cisco CMX HA mandates that the primary and secondary nodes share identical node footprint sizing (e.g., both Low-End, both Standard, or both High-End instances). Mismatched sizing prevents database replication and state synchronization, leading to HA configuration failure.
Why Other Options Are Incorrect:
A. The Cisco CMX instances are installed in the same subnet:
Being in the same subnet is a valid requirement for Layer 2 High Availability deployments and will not cause HA pairing to fail.
C. The delay between the primary and secondary instance is 200 ms:
Cisco CMX supports Layer 3 HA across routed subnets as long as the round-trip latency (delay) between the primary and secondary nodes is under 250 ms. A delay of 200 ms falls within the acceptable operating threshold.
E. Both Cisco CMX installations are virtual:
Deploying CMX as virtual machines is fully supported, provided both nodes are VMs and share identical resource sizing.
References:
Cisco CMX Configuration Guide (Managing Cisco CMX System Settings - High Availability): Specifies prerequisites for HA, strictly requiring identical node sizes (Low, Standard, High-end), identical installation types (VM vs. Physical), matching software versions, and NTP synchronization across both instances prior to pairing.
| Page 5 out of 28 Pages |