NO.1 Scenario
Which configuration changes need to be made to allow WPA2 + PSK to operate property on the East-
WLC-2504A controller? (Choose four.)
A. Change the VLAN Identifier.
B. Change the PSK Format to HEX.
C. Change the Layer 3 Security to Web Policy.
D. Change the WLAN ID.
E. Click on the Status Enabled radio button.
F. Click on the PSK radio button and add the password in the text box.
G. Change the WPA + WPA2 Parameters to WPA2 Policy-AES.
H. Disable Dynamic AP Management.
I. Change the IP Address of the Virtual interface.
J. Change the SSID name of the WLAN.
Answer: D,E,F,J

NO.2 Refer to the exhibit.
A customer is having problems with clients associating to me wireless network.
Based on the configuration, which option describes the most likely cause of the issue?
A. Both AES and TKIP must be enabled
B. PME is set to "required"
C. MAC Filtering must be enabled
D. SA Query Timeout is set too low
E. Comeback timer is set too low
Answer: C

NO.3 A customer wants to allow employees to easily onboard their devices to the wireless network.
Which process can be configured on Cisco ISE to support this requirement?
A. native supplicant provisioning
B. self registration guest portal
C. client provisioning
D. local web auth
Answer: C

NO.4 WPA2 Enterprise with 802.1x is being used for clients to authenticate to a wireless network
through an ACS server. For security reasons, the network engineer wants to ensure only PEAP
authentication can be used. The engineer sent instructions to clients on how to configure their
supplicants, but users are still in the ACS logs authentication using EAPFAST. Which option describes
the most efficient way the engineer can ensure these users cannot access the network unless the
correct authentication mechanism is configured?
A. Enable AAA override on the SSID and configure an access policy in ACS that puts clients that
authenticated using EAP-FAST into a quarantine VLAN.
B. Enable AAA override on the SSID and configure an access policy in ACS that allows access only
when the EAP authentication method is PEAP.
C. Enable AAA override on the SSID, gather the usernames of these users, and disable their RADIUS
accounts until they make sure they correctly configured their devices.
D. Enable AAA override on the SSID and configure an access policy in ACS that denies access to the list
of MACs that have used EAP-FAST.
Answer: A

