Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Enterprise Wireless (ENWLSI)

Domain 5Objective 5

5.5 Implement wIPS Using Cisco Catalyst Center (formerly Cisco DNA Center) 300-430 Practice Questions (Page 2)

Part of the Advanced Location Services domain, which accounts for 10% of the 300-430 exam. Cisco does not publish an official question count, but from its 90-minute exam (~35–60 total, ~4–6 in this domain), expect 1–1 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
8concepts
10%of the exam

Questions 6–10

  1. 6application · medium

    A university is using Catalyst Center wIPS and is receiving a high volume of alarms for 'deauthentication attacks' in the student dormitories. Upon investigation, the network team finds that the alarms correlate with a legitimate student application that sends deauthentication frames to test roaming. They want to reduce false positives without losing detection of real attacks. What should they do?

    Select an answer first
  2. 7application · medium

    A hotel chain is deploying wIPS using Catalyst Center. They have a mix of APs that support both monitor mode and hybrid mode. The security team wants to maximize detection capabilities in the lobby area, which has high foot traffic and potential for rogue devices. They are willing to sacrifice some client capacity in that area. What should they do?

    Select an answer first
  3. 8foundation · easy

    When a wIPS alarm is raised in Catalyst Center, what is the first step an administrator should take to interpret the alert?

    Select an answer first
  4. 9application · medium

    A large enterprise is using Catalyst Center wIPS and also has Cisco Stealthwatch for network traffic analysis. They want to correlate wIPS alarms with network flows to identify the source of a wireless attack. What should they do?

    Select an answer first
  5. 10application · medium

    A network admin sees a wIPS alarm for 'Deauthentication Flood' coming from a specific AP's radio. The alarm repeats every few minutes. Upon investigation, the admin finds that a legitimate client is using a Wi-Fi analyzer app that sends deauthentication frames as part of its scanning. What should the admin do to handle this recurring false positive?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “300-430” is a trademark of its owner, used for identification only.