300-430 — Frequently Asked Questions

Community-vetted answers to 48 common questions about this exam.

Questions from real practice questions

Each Q&A comes from a specific community question — follow the link for its full analysis.

How Do You Get the Latest wIPS/wIDS Detection Definitions?

The WLC only stores and forwards the wIPS profile it receives from the MSE, then relays it to APs via CAPWAP; new detection signatures ship with the MSE wIPS service, not with controller code.

No. Prime Infrastructure configures and monitors the MSE, but the wIPS service on the MSE is the source of the profiles that flow to controllers and then to wIPS access points.

Maximizing RFID Tag Tracking Channels on 802.11b/g APs

Standard Wi-Fi uses 3 non-overlapping channels (1, 6, 11) to reduce interference. However, for RFID tracking optimization, Cisco allows scanning up to 4 channels to improve location calculation accuracy.

The specific constraint of 'up to four channels' applies to the 2.4-GHz band for 802.11b/g APs as described in the question context. Different rules may apply to 5GHz depending on the available wide channels.

Which RADIUS Service-Type Gives Read-Only WLC Management Access?

Cisco maps Administrative (6) to read-write management privileges on the WLC, allowing configuration changes, so it cannot satisfy a read-only requirement.

No. Callback Login (D) is a legacy dial-up Service-Type that requests a callback number; it is not used for WLC management authorization levels.

Why Is Hyperlocation Location Accuracy Poor on an AireOS WLC?

The stem already states the controller runs AireOS v8.2, the release that supports Hyperlocation on 3700 Series APs, so the code requirement is satisfied and reinstalling software does not address the accuracy symptom.

Cisco's troubleshooting guide lists NTP sync across WLC, CMX/MSE and PI plus accurate tilt and azimuth on the maps as prerequisites; once those are verified, the remaining documented step is allowing 60-90 minutes for RRM to settle.

Autonomous AP 802.1X: Which Two RADIUS Details Must Be Configured?

PAC is used with EAP-FAST for tunnel establishment; standard 802.1X RADIUS client communication only needs the server IP and shared secret.

No. Those are for the AP's management login or an 802.1X supplicant, not for the AP-to-RADIUS server authentication exchange.

Which two CMX 10.6.2 interferer filtering parameters stop short-lived bursts?

The 10.6.2 guidance names Severity Cutoff (Interferer) and Duty Cycle Cutoff (Interferer) as the parameters to set; Intensity Cutoff is not part of that recommendation and is a distractor.

Duty Cycle Cutoff ignores interferers present for only a tiny fraction of the window, and Severity Cutoff requires a minimum interference severity, so brief bursts are discarded before they are recorded.

Which component must be the 802.1X authenticator with autonomous APs?

In 802.1X the RADIUS server is the authentication server that validates credentials; the authenticator is the network access device, here the autonomous AP, that controls the client port.

The supplicant is the client device, such as a laptop or phone, that requests network access and passes credentials through the AP to the RADIUS server.

Prime Infrastructure Client Data Stale by Five Minutes?

Database optimization addresses general PI slowness, not the specific five-minute delay in client state and AP detail. That delay is eliminated by receiving client Assoc/Disassoc and Auth/Deauth traps from the WLC.

They push near-real-time client session events from the controller to PI instead of PI waiting for its periodic polling cycle, so the client detail page reflects current state and connected AP.

How to Display Interferers on Cisco Prime Infrastructure Maps?

By default, the MSE tracks clients and rogue devices but not interferers; you must explicitly enable interferer tracking to see them on Prime Infrastructure maps.

Successful client location proves the MSE is already added, synchronized, and communicating via NMSP, so no additional MSE integration is required.

Which Two Fields Are Required in an ISE Native Supplicant Profile?

The ISE native supplicant profile only offers supported allowed-protocol combinations such as PEAP/TLS; LEAP/EAP-TTLS is not a selectable value, so it cannot be configured there.

The profile runs on the endpoint, which learns its controller from the SSID it joins; WLC identity is infrastructure-side and plays no part in the supplicant template.

How Do Eight WLCs Reduce Mobility Group Bandwidth?

No. Multicast must be enabled globally on the WLC first; the mobility group multicast setting then uses that multicast transport to reach the peer controllers.

Each controller unicasts mobility messages to all seven peers, so replication and control-plane load grow with group size instead of being carried in one multicast stream.

Which ACL Type Enables FlexConnect Split Tunneling?

A WLAN ACL is applied at the WLAN level for centrally switched traffic; only a FlexConnect ACL controls the local-versus-central switching decision by packet content at the FlexConnect AP.

Yes. FlexConnect ACLs classify and control traffic whether it is locally switched at the FlexConnect AP or centrally switched back to the controller over CAPWAP.

Why Is a Fabric-Enabled WLC Not Discovered by DNA Center?

SNMP is required for all device discovery, but the scenario says four controllers are discovered with the same firewall rules, so SNMP is already working; NETCONF is the fabric-specific requirement.

NETCONF uses TCP port 830. If that port is blocked or NETCONF is disabled on the fabric WLC, DNA Center cannot discover it as a fabric device.

Which Prime Infrastructure Report Troubleshoots VoWiFi Connectivity?

It shows generic wireless retry and error counters, not the per-stream jitter, packet loss, and latency metrics needed to diagnose voice-over-Wi-Fi quality.

It provides per-stream QoS details for real-time traffic, including jitter, latency, and packet loss, which are essential for VoWiFi client connectivity troubleshooting.

How to Log In to an AP Without Changing Global Login Policy?

AAA override applies to WLAN client authentication attributes such as VLAN, QoS, or ACL after 802.1X and does not control administrative CLI access to an access point.

In the WLC GUI, open the specific AP's configuration page, enable the credential override option, then set the AP username and password for that AP only.

Cisco WLC AP Authentication for Rogue Containment

Cisco WLC does not have a feature called AP Wireless Protection Rules; AP Authentication is the actual setting under Security > AP Policies that prevents friendly APs from being treated as rogues.

When AP Authentication is enabled, the controller validates APs via pre-shared key or certificate, so it recognizes friendly APs from other RF groups and does not contain them.

Why Won't Guests Authenticate on a Locally Authenticated FlexConnect Guest LAN?

Local authentication runs on the AP with its own user database and does not support the guest LAN feature, which depends on the controller's guest services for the login.

Backup RADIUS servers on the WLC matter when a FlexConnect AP operates in standalone mode for 802.1X EAP; they do not change how a guest LAN WLAN authenticates.

Why Does Cisco CMX Layer 2 HA Failover Fail?

Layer 2 HA must move the VIP between both CMX nodes by ARP, so the primary, secondary, and VIP all need to be on the same subnet; fixing only the VIP leaves the secondary unreachable.

Yes, Layer 3 HA is designed for routed separation, but this question explicitly states Layer 2 HA, so switching to Layer 3 would be a redesign rather than the required fix.

How Are Cisco CleanAir Alarms Collected for Archival?

The WLC processes CleanAir reports locally, not as a long-term central archive; Prime Infrastructure centrally receives and retains alarms from multiple controllers.

MSE can support location and wIPS functions, but it is not the CleanAir alarm archive. Prime Infrastructure remains the central collection and reporting platform.

Which FlexConnect State Keeps Branch Users Online After WLC Loss?

With Authentication Central the AP still proxies 802.1X through the WLC, so once the controller is unreachable new clients cannot authenticate even though local switching keeps the data path alive.

No. Local switching only keeps frames at the branch; if authentication is Central, clients still depend on the WLC to reach the AAA server and will fail to join.

Which QoS Value Must Be Trusted on WLC Trunk Ports?

Trunk ports are Layer 2 links carrying 802.1Q tags; trusting DSCP ignores the CoS priority bits in those tags and breaks the Layer 2 parity the question requires.

802.1p names the 3-bit priority field inside the 802.1Q tag, while the value carried in that field is CoS—which is what a switch or controller actually trusts.

How to Implement Reliable Multicast on AireOS WLC?

Multicast frames are transmitted at the lowest mandatory rate; removing 1, 2, 5.5, and 11 Mbps forces the WLC to use higher rates, reducing airtime and packet loss in large deployments.

Coverage cell is a parameter for Multicast Direct, not basic multicast. For standard multicast, the data rate is determined by the mandatory rate set, so option D is the direct fix.

Cisco DNA Spaces Connector Location Services Requirements

CAPWAP is for AP-controller control/data planes. DNA Spaces uses NMSP/SNMP to pull RF data without joining the WLAN infrastructure.

No. While APIs are useful for management, the real-time location data feed strictly depends on NMSP and SNMP protocols.

Configuring Video Stream Notifications with Multicast Direct

Northbound Notification sends alerts to external management systems (NMS), while Session Announcement State sends notifications directly to the wireless clients.

SNMP Traps are intended for network administrators to monitor controller health and do not reach the end-user's device interface.

← Back to 300-430 Implementing Cisco IP Switched Networks Study Guide