Proper study guides for Avant-garde Cisco CCIE Wireless Written Exam certified begins with Cisco 400-351 preparation products which designed to deliver the Downloadable 400-351 questions by making you pass the 400-351 test at your first time. Try the free 400-351 demo right now.

Q1. When creating a guest account on Cisco identity Services Engine .Which option in the sponsor portal allows for the guest credentials to be used for RADIUS authentication without requiring the guest user to log into the guest portal? 

A. Set the Guest role to Guest 

B. Set the Guest role to Activated guest 

C. Set the Time Profile to Radius 1Day 

D. Check the box to send email not send email notification id the guest user name is based on the email address. 


Q2. Which two statements are true based upon the output in the exhibit? (Choose two.) 

A. Operation will be effective only if the video profile on the WLC is mapped to the 802.1p protocol with a tagged value of 5. 

B. It is recommended to configure IP multicast on the WLC in multicast-multicast mode. 

C. CAC must be enabled to avoid channel oversubscription and guarantee the configured media bandwidth. 

D. In case of a violation after an RRC re-evaluation, the stream is demoted to the best- effort class. 

Answer: B, ? 

Q3. Which statement about wireless LAN security in a Cisco Unified Wireless Network VoWLAN deployment is false? 

A. EAP-FAST, if available, is the recommended EAP type for use in VoWLAN deployments. 

B. Although LEAP is considered secure for VoWLAN handsets when correctly deployed, it is recommended that a different EAP method (FAST, PEAP, TLS) is used, if available. 

C. Dynamic WEP mitigates the security weaknesses in static WEP, making it a viable option that can be relied upon to secure a VoWLAN deployment. 

D. When using EAP authentication, the EAP-Request timeout value should be adjusted based only on the advice of the VoWLAN handset vendor. 

E. When using WPA Personal, strong keys should be used to avoid a dictionary attack. 


Q4. Given the IPV6 address and subnet 2001:adcb:3257:9048::/64,which option list the start and ending IP address of this subnet? 

A. 2001:adcb:3257:9048: ,2001:adcb:3257:9048:0000:0000:0000:ffff 

B. 2001:adcb:3257:9048:0:0:0:0 .2001:adcb:3257:9048:0000:ffff:ffff:ffff 

C. 2001:adcb:3257:9048:0:0:0:0 ,2001:adcb:3257:9048: ffff'ffff:ffff:ffff 

D. 2001:adcb:3257 9048 0 0 0 0 ,2001adbc: 3257 9048 0000:0000:0000:ffff E. 2001:adcb:3257:9048 :0:0:0:0, 2001:adcb:3257: 9048: 0000:0000:ffff: ffff 

E. 2001:adcb:3257:9048:0::, 2001:adcb:3257:9048:0000:0000:0000:ffff 


Q5. Which three options are valid AP modes for lightweight APS in the WLC 7.0.116 release? (Choose three.) 

A. SE-Connect 


E. Rogue Detector 

F. Sniffer 

Answer: A, E, F 



Q6. Which three type of ACLs are supported by the Cisco 5760 WLC? 


B. Switch Port ACls 

C. Router ACLs 

D. QoS ACLs 

E. Router Port ACLs 

F. Port ACLs 

Answer: A, C, F 

Q7. You are a network administrator at ACME corporation where you have a pair of Cisco 5760 Wireless LAN Controllers deployed for HA AP SSO mode. A failover event occurs and the secondary Cisco 5760 controller moves into the active role. Which three statements about the failover event are true? (Choose three) 

A. Rogue APs and clients are not synced to the standby and are releamed upon switchover. 

B. With SSO,wIPS information is already synced with the stanby unit and this information need not be releamed upon switchover. 

C. Upon guest anchor controller switchover, mobility tunnels stay active, APs remain connected, clients rejoin at MA or MC, and clients are anchored on the new active controller. 

D. Switchover during AP preimage download causes the APs to start image download all over again from the new active controller. 

E. The new active controller does not need to releam the shun list from IPS and other MCs, which eliminates the need to redistribute it to the Mas. 

F. Netflow records are already exported upon switchover and collection starts resuming in the new active controller. 

Answer: C, D, E 

Q8. Drag and drop steps of the 802.1x authentication process on the left to the corresponding number on the right. 


Q9. Which port does cisco JSE use by default to send RADIUS CoA messages to the Cisco WLC? 

A. UDP 3799 

B. UDP 1813 

C. UDP 1700 

D. TCP 1812 


Q10. If a guest anchor controller is used outside the firewall,which firewall ports must you open for guest access including SNMP and mobility features to work in a Cisco unified wireless network? 

A. UDP 16667. IP Protocol97. UDP 500 501 

B. UDP 16666 .IP Protocol97. UDP 162 163 

C. UDP 12222 .IP Protocol97. UDP 161 162 

D. UDP 16666 . IP Protocol 97. UDP 161 162 

E. UDP 12223 . IP Protocol 97. UDP 161 162