Cisco 400-351 Faq 2021

Want to know Ucertify 400-351 Exam practice test features? Want to lear more about Cisco CCIE Wireless Written Exam certification experience? Study Approved Cisco 400-351 answers to Up to the minute 400-351 questions at Ucertify. Gat a success with an absolute guarantee to pass Cisco 400-351 (CCIE Wireless Written Exam) test on your first attempt.

Check 400-351 free dumps before getting the full version:

NEW QUESTION 1
DRAG DROP
Drag and drop the Cisco WLC discovery attempt method on the left to the correct order on the right.
400-351 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
400-351 dumps exhibit

NEW QUESTION 2
Refer to the exhibit.
400-351 dumps exhibit
A wireless user has roamed from an AP connected to MA 1to AP connected to MA 3the traffic flow for the user between roam is shown . Which option shows the traffic flow for the user after roam, considering default sticky anchoring is enabled on the WLAN?

  • A. MA-3>Distribution switch>core>mc>distribution switch >MA-1
  • B. MA-3>Distribution switch>MA-1distribution switch >core
  • C. MA-3> Distribution switch>MA-2>Distribution switch >core
  • D. MA-3> Distribution switch >ma -2> MA-l>Distribution switch>core

Answer: A

NEW QUESTION 3
Which statement about Wired Guest Access is true?

  • A. The guest traffic can terminate on the foreign WLC, but egress interface must be defined on theguest SSID
  • B. Wired Guest Access is not supported in the Cisco 5760 WLC
  • C. The wired guest traffic terminates only on the anchor Cisco WLC
  • D. The Cisco 5760 WLC supports Wired Guest Access only in conjunction with the converged access switches.

Answer: C

Explanation:
http://www.cisco.com/c/en/us/support/docs/wireless/5700-series-wireless-lan-controllers/118810- technote-wlc-00.html

NEW QUESTION 4
400-351 dumps exhibit
Refer to the exhibit. Which statement about this CPU ACL is correct?

  • A. This CPU ACL is used as a redirection aCLto redirect all traffic except Telnet to 172.21.153.37.
  • B. A user on the 10.64.0.0/24 network can use Telnet to access the WLC IP address on 172.21.153.37.
  • C. A user on the 10.64.0.0/24 network cannot use Telnet to access the WLC IP address on 172.21.153.37.
  • D. A user on the 10.64.0.0/24 network cannot use HTTPS to 172.21.153.37.
  • E. No subnets other than 10.64.0.0/24 can manage the WL

Answer: C

Explanation:
From:
http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wlan-security/71978-acl-wlc.html
400-351 dumps exhibit

NEW QUESTION 5
You use the Cisco ISE profiler service to classify endpoints. You use multiple probes to correlate the profiled data. Which two types of profiling; probes can establish IP-to-MAC address binding when the endpoints are on different subnets? (Choose two)

  • A. RADIUS
  • B. NetFlow
  • C. DHCP
  • D. SNMP trap
  • E. NMAP

Answer: AC

NEW QUESTION 6
Refer the exhibit.
400-351 dumps exhibit
Wireless voice users on VLAN 2150 report poor voice quality during heavy network usage.The WLC is configured correctly.Given the configuration in the exhibit,which possible cause of the problem is true?

  • A. MLSQoS is not enabled on the switch.
  • B. VLAN 2150 is not allowed on the trunkport of the switch
  • C. The WLC switch port dose not trust CoS values for Voice traffic that traverses the WLC
  • D. The wireless voice VLAN does not have the proper QoS setting

Answer: C

NEW QUESTION 7
DRAG DROP
Drag and drop the configuration steps for access point groups on the wireless LAN controller from the left into the correct order on the right.
400-351 dumps exhibit

  • A. Mastered
  • B. Not Mastered

Answer: A

Explanation:
400-351 dumps exhibit

NEW QUESTION 8
Refer to the exhibit.
400-351 dumps exhibit
You enabled NAT to make sure that your WLC is publicly reachable . if other NAT parameters are left to default1 which statement is true. ?

  • A. The AP WLC discovery fails for APs int local mode using 209.165.200.44
  • B. The AP WLC discover succeeds for OEAPsjoning the WLC using 192.168.3.44
  • C. The AP WLC discover succeeds for OEAPsJoning the WLC using 192.168.3.44 or 209 165.200.44
  • D. The AP WLC discover Fail for APs in local mode using 192.168.3.44

Answer: C

Explanation:
Section: 2.0 Network Infrastructure

NEW QUESTION 9
On a Cisco autonomous AP, the maximum number of attempts to send a packet (packet retries) is set to 32 by default. Which statement about the result when the AP has tried to send a packet for that number of attempts and no response is received from the client is true?

  • A. The access point drops the packet.
  • B. The client MAC address is excluded for 60 seconds.
  • C. The access point resets the radio interface.
  • D. The access point disassociates the clien

Answer: A

Explanation:
From:
Packet Retries & Max-Retries I mrn-cciew https://mrncciew.com/2013/06/16/packet-retries-max-retries/
In Autonomous(IOS) AP, you can configure number of attempts the wireless device makes to send a packet before giving up & dropping the packet. There are two ways of configuring this feature. One method for best effort (priority value 0) traffic & another method for non-best effort (priority value 1- 7)
1. Best-effort Traffic (packet retries command)
2. N on-Best-effort Traffic (packet max-retries command ) CLI default:
packet retries 32 drop-packet channel width 40-above channel dfs station-role root rts retries 32
cfg:
http://www.cisco.com/c/en/us/td/docs/wireless/access_point/15-3-3/configuration/guide/cg15-3-
3/cg15-3-3-chap6-radio.html
Configuring the Maximum Data Packet Retries
The maximum data retries setting determines the number of attempts the makes to send a packet before giving up and dropping the packet. The default setting is 32. Beginning in privileged EXEC mode

NEW QUESTION 10
You have been asked to change your 7925 wireless IP phone scan mode from Auto lo Continuous. Which two statements about Continuous scan mode are true? (Choose two.)

  • A. Idle battery life is increased slightly when using this scan mode because the client does not have to send any association probe requests
  • B. The phone scans only when the basic service set is lost.
  • C. The phone scans only when on a call or when the signal strength (RSSI) is low.
  • D. This mode is recommended for environments where frequent roams occur or where smaller cells (pico cells) exist.
  • E. The phone scans continuously even when it is not in a cal

Answer: DE

NEW QUESTION 11
Compared to an active survey, which three types of information are lost when performing a passive survey? (Choose three.)

  • A. retransmissions
  • B. uplink information
  • C. PHY rate
  • D. RSSI
  • E. TxBF
  • F. SNR
  • G. rogues

Answer: ABC

NEW QUESTION 12
You are installing Converged Access controllers that run Cisco IOS-XE and you are ready to implement QoS. From the below, choose all the possible QoS target levels that would apply to downstream
traffic (toward the client)?

  • A. Client, SSID, Radio, Port
  • B. Client, SSID, Radio
  • C. Client, Radio
  • D. Client, SSID

Answer: A

Explanation:
400-351 dumps exhibit
http://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_010010.html

NEW QUESTION 13
Which one of the following commands could limit WLC output from subsequent debug commands to show only information associated with a specific wireless client device that has the MAC address 00:0c:41:07:33:a6?

  • A. Debug mobility addr 00:0c:41:07:33:a6 enable
  • B. Debug mac addr 00:0c:41:07:33:a6
  • C. Debug mac addr 00-0c-41-07-33-a6 enable
  • D. Debug mobility addr 00:0c:41:07:33:a6

Answer: B

NEW QUESTION 14
Which two descriptions of the encoding formats supported by RESTCONF and NETCONF are true? (Choose two.)

  • A. NETCONF supports JSON and XML encoding.
  • B. NETCONF supports JSON encoding.
  • C. RESTCONF supports XML encoding.
  • D. RESTCONF supports JSON and XML encoding.
  • E. NETCONF supports XML encoding.
  • F. RESTCONF supports JSON encodin

Answer: DE

NEW QUESTION 15
Refer to the exhibit.
400-351 dumps exhibit
Which security method is the wireless workgroup bridge with this configuration going to use to establish its wireless connection?

  • A. WPA2-AES with LEAP over 5 Ghz
  • B. WPA2-AES with EAP-FAST over 5 Ghz
  • C. WPA2-AES with EAP-FAST over 2 4 Ghz
  • D. WPA2-AES with PEAP over 5 Ghz

Answer: A

NEW QUESTION 16
A corporation has hired you as a consultant to help them with a unique requirement of granting access to people based on their location They currently have Cisco MSE 8 0 version ISE 2 0 and Cisco Prime Infrastructure Which statement about the MSE and ISE integration is true?

  • A. Authorization of users based on exact location is not possible However, specific authorization policies can be created based on the location of the authenticator
  • B. ISE uses NMSP connection to the MSE to fetch the location information and create the location tree to be used in authorization rules.
  • C. The wrong placement of APs within Cisco Pnme Maps may result in unauthorized user access to resources.
  • D. With ISE and MSE integration reauthorization of users cannot be done if the band-select feature is enabled
  • E. Cisco MSE can be added to ISE as an authenticator and MSE sent RADIUS requests to the ISE server

Answer: B

NEW QUESTION 17
Which feature intersection of a Cisco 5760 Wireless LAN Controller with HA AP SSO is not true?

  • A. Switchover during AP preimage download causes the Aps to start image download all over again from the new active controller.
  • B. Upon guest anchor controller switchover, mobility tunnels stay active, Aps remain connected, clients rejoin at MA or MC, and clients are anchored on the new active controller.
  • C. WIPS information is synced to the standby uni
  • D. The standby unit does not have to relean wIPS information upon switchover.
  • E. Roamed clients that have their data path going through the mobility tunnel endpoint "becomed Local" in case of Layer 2 with sticky anchoring and Layer 3 roa
  • F. Layer 2 roamed clients are not affected except when roaming occurs between Cisco Unified Wireless Network and CA controller.

Answer: C

Explanation:
From:
CT5760 High Availability AP SSO Deployment Guide, Cisco IOS XE Release 3.3 - Cisco http://www.cisco.com/c/en/us/td/docs/wireless/controller/technotes/5700/software/release/ios_x e_33/5760_HA_DG_iosXE33.html
This document introduces the Access Point Stateful Switch Over redundancy model for High Availability (HA) with CT5760 controllers using the StackWise-480 technology. HA in Cisco 5700 Series Wireless Controller is enabled using Cisco StackWise-480 technology.
Feature Intersection with AP SSO
• Switchover during AP Pre-Image download causes the APs to start image download all over again from the new Active controller.
• Rogue APs and clients are not synced to Standby and are re-learnt upon switchover.
• Infra structure MFP key is not synced to the Standby controller and is re-learnt upon switchover.
• New Active controller re-learns the shim list from IPS and other MCs. and redistributes it to the MAs.
• wIPS information is not synced to the Standby unit and is re-learnt upon switchover.
• Clean Air detected Interferer devices are re-learnt after switchover.
• Net Flow records are cleared upon switchover and collection starts fresh on the new Active controller.
• Mobility paths and tunnels to the MO and other peer MCs are not disrupted upon switchover. However the Client state is cleaned up on the MO under which the HA pair exists and is re-learnt from the new Active controller when the client re-associates.
• Roamed clients that have their data path going through the Mobility Tunnel Endpoint (MTE) "become Local'" in case of L2 with Sticky Anchoring and L3 Roam. L2 Roamed Clients are not affected except when roaming occurs between CUWN and CA controllers.
• RRM related configurations and the AP neighbor list in the Leader HA pair is synced to the Standby controller.
• Upon Guest Anchor controller switchover, mobility tunnels stay active. APs remain connected, clients rejoin at MA or MC. and are anchored on the new Active controller.

NEW QUESTION 18
Which two advanced WLAN options are required when deploying central web authentication with Cisco ISE? (Choose two.)

  • A. P2P Blocking Action set to Drop.
  • B. NAC State RADIUS NAC
  • C. NAC State SNMPNAC.
  • D. DHCP Add
  • E. Assignment disabled.
  • F. Allow AAA override enable

Answer: BE

Explanation:
From
400-351 dumps exhibit
http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115732-central-webauth- 00.html

NEW QUESTION 19
Refer to the exhibit.
400-351 dumps exhibit
400-351 dumps exhibit
Which feature (and associated show output) is seen here?

  • A. Controller>show client tsm 802.11a 00:01:02:03:04:05 all
  • B. Controller>show client wmm 802.11a 00:01:02:03:04:05 all
  • C. Controller>show ap stats 802.11a00:01:02:03:04:05
  • D. Controller>show client detail 00:01:02:03:04:05

Answer: A

Explanation:
400-351 dumps exhibit
http://www.cisco.com/c/en/us/td/docs/wireless/controller/7- 4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010 000.html

NEW QUESTION 20
Which two options are correct according to debug output presented in the following exhibit ? (Choose two.)
Exhibit:
400-351 dumps exhibit

  • A. The wireless client "hangs" in probes (does not proceed with 802.11 authentication and association). It is likely that the "encryption" or "key-management" advertised in the probe response does not match.
  • B. Since the AP receives a probe request from the wireless client, the Access Point Functions state for the machine changes from "Idle" to "Probe."
  • C. The wireless client uses a static IP address, so "0.0.0.0 START (0)" can be found in the logs.
  • D. The wireless client has been successfully authenticated.Reauthentication is set to occur on an extremely aggressive schedule (every five seconds).

Answer: AB

NEW QUESTION 21
When a Flex Connect AP is in the "local authentication, local switching" state, it handles client authentication and switches client data packets locally. This state is valid in standalone mode and connected mode. Which three statements about a FlexConnect AP are true? (Choose three).

  • A. In connected mode, the AP provides minimal information about the locally authenticated client to the controlle
  • B. This information is not available on the controller policy typ
  • C. Access VLA
  • D. VLAN name, supported rate
  • E. Encryption ciphter.
  • F. In connected mode, the access point provides minimal information about the locally authenticated client to the controlle
  • G. However, this information is available to the controller policy type., access VLAN, VLAN name, supported rates, encryption cipher.
  • H. Local authentication is useful where you cannot maintain a remote office setup of a minimum bandwidth of 128 kbps with the round-trip latency no greater than 100 ms and the maximum transmission unit no smaller than 576 bytes.
  • I. Local authentication is useful where you cannot maintain a remote office setup of a minimum bandwidth of 128 kbps with the round-trip latency no greater than 150 ms and the maximum transmission unit no higher than 500 bytes.
  • J. Local authentication in connected mode does not require any WLAN configuration.
  • K. Local authentication can be enabled only on the WLAN of a FlexConnect AP that is in local switching mode.

Answer: ACF

Explanation:
http://www.cisco.com/c/en/us/td/docs/wireless/controller/7- 2/configuration/guide/cg/cg_filexconnect.html

NEW QUESTION 22
Which two statements about the various types or DevOps tools are true? (Choose two)

  • A. Puppet requires the installation of a master (server) and agents (clients) architecture for configuring systems.
  • B. Salt cannot communicate with clients through general SSH, it use minions client agents only.
  • C. Puppet and Chef are written in Python, Python skills are a must to operate these two.
  • D. Ansible does not require agent node installation and uses SSH for performing all tasks.
  • E. Chef and Puppet are much more attuned to the needs of system administrator

Answer: CE

NEW QUESTION 23
Which two characteristics of an loT network are true? (Choose two.)

  • A. The transmission rate in an loT network is consistent.
  • B. loT networks must be designed for low-powered devices.
  • C. loT networks use IS-IS for routing.
  • D. loT networks are 100% reliable
  • E. loT networks are bandwidth constrained

Answer: BE

NEW QUESTION 24
Which statement about 802.11h is true?

  • A. DFS feature works irrespective of whether the channel setting on WLC is set to auto or manual.
  • B. 802.llh is not a mandatory standard under FCC regulations.
  • C. The FCC does not require 802.llh to be supported in the 5 GHz band.
  • D. When the radio detects a radar, it can use the channel for only 20 minutes at a tim

Answer: A

Explanation:
From:
EEE
802 .llh-2003-Wikipedia, the free encyclopedia https://en.wikipedia.org/wiki/IEEE_802.11h-2003
The standard provides Dynamic Frequency Selection (DFS) and Transmit Power Control (TPC) to the 802.11a PHY. It has been integrated into the full IEEE 802.11-2007 standard.
FCC Regulations Update –Cisco http://www.cisco.com/c/en/us/products/collateral/wireless/aironet-1300-
series/prod_white_paper0900aecd801c4a88.html https://supportforums.cisco.com/document/52376/tpc-and-dfs-overview

NEW QUESTION 25
Refer to the exhibit.
400-351 dumps exhibit
This output is an example of which 802.11 frame?

  • A. beacon
  • B. association
  • C. probe request
  • D. probe response

Answer: A

NEW QUESTION 26
......

Thanks for reading the newest 400-351 exam dumps! We recommend you to try the PREMIUM Passcertsure 400-351 dumps in VCE and PDF here: https://www.passcertsure.com/400-351-test/ (393 Q&As Dumps)