Cisco CCNP 300-425 Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Cisco CCNP 300-425 Exam Dumps and Practice Test Dumps.


Question 361. What helps Rolling AP Upgrade choose AP candidates

  1. DHCP lease time
  2. Client username
  3. RRM neighbor information
  4. Controller certificate age

Correct Answer: 3. RRM neighbor information

Explanation:

Rolling AP Upgrade uses Radio Resource Management neighbor information when selecting access points for each upgrade iteration. The controller attempts to choose APs in a way that preserves useful RF coverage while selected devices reload and install their new software. Coverage maintenance takes priority over simply reaching the requested upgrade percentage. This helps prevent too many neighboring APs from becoming unavailable at the same time. The process is therefore more intelligent than upgrading a random group of access points. Cisco uses the existing RF neighbor relationships to reduce client disruption during staggered software maintenance.

Question 362. What percentage is the traditional default for staggered AP upgrades

  1. 15 percent
  2. 5 percent
  3. 25 percent
  4. 50 percent

Correct Answer: 1. 15 percent

Explanation:

Cisco documentation for the traditional Rolling AP Upgrade workflow identifies 15 percent as the default percentage of access points selected for each upgrade iteration. Other supported choices include smaller or larger percentages depending on the software release and upgrade workflow. A lower percentage reduces the number of APs unavailable simultaneously but increases the total upgrade duration. A higher percentage can complete the process faster but places greater pressure on neighboring access points to maintain coverage. Designers should therefore choose the iteration size according to RF density, client load, and acceptable disruption.

Question 363. What does client steering use during a Rolling AP Upgrade

  1. DHCP Option 43
  2. RADIUS CoA
  3. CAPWAP echo
  4. 802.11v

Correct Answer: 4. 802.11v

Explanation:

Cisco Rolling AP Upgrade can use 802.11v client steering before an access point reloads. The controller sends transition information that encourages compatible clients to move toward neighboring APs while coverage is still available. Cisco documentation describes use of the disassociation imminent indication to help clients leave the candidate AP before it is taken offline. Clients that do not honor the steering request can eventually be disconnected before the AP reload occurs. This mechanism reduces user disruption and works together with RRM based candidate selection to preserve wireless service during a staggered upgrade.

Question 364. What happens to a client that ignores upgrade steering before AP reload

  1. It becomes a wired client
  2. It can be deauthenticated
  3. It receives a new SSID
  4. It becomes a mobility anchor

Correct Answer: 2. It can be deauthenticated

Explanation:

During Rolling AP Upgrade, Cisco first attempts to steer clients away from an AP selected for upgrade by using supported roaming assistance. If a client does not follow the steering request, the infrastructure can deauthenticate that client before the AP reloads. The client can then discover and associate with another available neighboring access point. This behavior ensures the upgrade is not indefinitely delayed by devices that ignore 802.11v transition requests. A strong RF design with overlapping coverage is important because client recovery depends on suitable neighboring APs being available.

Question 365. What should occur before activating a rolling AP software update

  1. AP image predownload
  2. DHCP scope deletion
  3. RF profile removal
  4. Guest anchor shutdown

Correct Answer: 1. AP image predownload

Explanation:

Rolling AP Upgrade depends on preloading the required software image onto access points before their individual upgrade iteration begins. Predownload allows the AP to continue serving clients while the new image is transferred in advance. When the AP is later selected for upgrade, it can switch to the already available image and reload without spending additional outage time downloading software. Cisco describes image preloading as a core requirement of the staggered upgrade workflow. Administrators should verify successful predownload status before beginning the final activation or migration process.

Question 366. What is the purpose of an AP image site filter

  1. Select client VLANs
  2. Choose RADIUS servers
  3. Limit updates to selected sites
  4. Change AP transmit power

Correct Answer: 3. Limit updates to selected sites

Explanation:

An AP image site filter allows administrators to select specific site tags whose access points should receive a software update or service package. This makes it possible to stage maintenance instead of upgrading every AP in the controller deployment at once. Cisco supports adding site tags to a filter, performing image predownload for those sites, and then activating the update for the filtered AP population. Additional sites can be added later when the administrator is ready to expand the rollout. Site based filtering therefore supports controlled phased maintenance and reduces operational risk.

Question 367. What does install commit do after an AP software package update

  1. Changes antenna gain
  2. Saves the update mapping persistently
  3. Deletes the AP image
  4. Changes WLAN authentication

Correct Answer: 2. Saves the update mapping persistently

Explanation:

After an AP software package has been activated, the install commit operation saves the update state and relevant package mapping into persistent configuration storage. Cisco notes that committing preserves the mapping even after a reload. Without the commit step, the software maintenance workflow is not fully finalized. This is especially important with site based service package deployment because the controller must remember which sites and AP populations are associated with the installed software package. Administrators should therefore treat commit as an essential final step rather than assuming activation alone completes the maintenance process.

Question 368. What is an AP Service Pack mainly used for

  1. Changing client VLANs
  2. Updating switch firmware
  3. Replacing controller hardware
  4. Delivering AP specific fixes

Correct Answer: 4. Delivering AP specific fixes

Explanation:

An Access Point Service Pack provides software fixes specifically for access points without requiring the same type of full controller release upgrade normally associated with a complete system image change. Cisco supports distributing an APSP selectively and activating it through rolling upgrade mechanisms so affected APs can receive the fix while maintaining wireless coverage. Site filtering can further limit deployment to the locations that need the update. This gives administrators a more targeted way to resolve AP software defects while reducing the operational impact of maintenance across the rest of the wireless network.

Question 369. What does a hot SMU patch avoid

  1. Client authentication
  2. Configuration synchronization
  3. Controller reload
  4. AP discovery

Correct Answer: 3. Controller reload

Explanation:

A hot Software Maintenance Upgrade patch can be applied without reloading the Catalyst 9800 controller. This reduces operational impact because connected access points and clients do not have to experience a controller restart simply to apply the supported fix. Cisco distinguishes hot patches from cold patches, which require a system reload. In an HA SSO pair, a supported SMU can be coordinated across both active and standby controllers. Hot patching is therefore useful when a software defect can be corrected dynamically and minimizing service interruption is a priority.

Question 370. What does a cold SMU patch require

  1. Controller reload
  2. Antenna replacement
  3. DHCP migration
  4. Client certificate deletion

Correct Answer: 1. Controller reload

Explanation:

A cold Software Maintenance Upgrade patch requires a controller reload before the patch becomes operational. Cisco HA SSO designs reduce the impact by updating and reloading the standby controller first. After the standby returns, a switchover occurs and the other controller can be updated. Because client and access point state is synchronized in an HA SSO pair, this staged process can preserve wireless service while both controllers are patched. The cold patch workflow therefore differs from a hot patch, which does not require the controller to reload at all.

Question 371. What does an AP Device Pack primarily add

  1. Client QoS rules
  2. Support for newer AP models
  3. Additional DHCP scopes
  4. New mobility groups

Correct Answer: 2. Support for newer AP models

Explanation:

An Access Point Device Pack is designed to add support for newer AP models without requiring administrators to move immediately to a completely new controller software release solely for hardware recognition. Cisco distinguishes APDP packages from AP Service Packs, which are generally focused on AP software fixes. Device packs can therefore simplify hardware introduction into an existing supported Catalyst 9800 environment. As with any software package, administrators should verify release compatibility and deployment requirements before installing the package on production controllers.

Question 372. What is the purpose of TrustSec Security Group Tags

  1. Identify AP radio channels
  2. Select DHCP servers
  3. Configure mesh parents
  4. Represent security group identity

Correct Answer: 4. Represent security group identity

Explanation:

Cisco TrustSec uses Security Group Tags to represent the security group or role associated with network traffic. Instead of building access decisions solely around IP addresses and subnets, organizations can classify users or devices according to identity and apply policy based on their assigned security group. Catalyst 9800 policy profiles can participate in TrustSec by supporting SGT configuration, inline tagging, and Security Group Access Control List enforcement. This approach can simplify segmentation when users move between different parts of the network while retaining the same business role or security classification.

Question 373. Where is the default SGT configured for a Catalyst 9800 WLAN

  1. Policy profile
  2. RF profile
  3. AP join profile
  4. Mobility group

Correct Answer: 1. Policy profile

Explanation:

The Catalyst 9800 policy profile contains TrustSec policy settings including the default Security Group Tag. Administrators can also configure inline tagging and Security Group Access Control List enforcement in the same policy area. The default SGT can be useful when traffic needs a defined security group value and one is not dynamically supplied by an external identity system. Keeping TrustSec behavior within the policy profile aligns security treatment with other WLAN client policies such as VLAN assignment and forwarding behavior.

Question 374. What does TrustSec inline tagging add to traffic

  1. DHCP Option 43
  2. CAPWAP discovery
  3. Security Group Tag information
  4. RF neighbor data

Correct Answer: 3. Security Group Tag information

Explanation:

TrustSec inline tagging carries Security Group Tag information with supported traffic so downstream devices can understand the security role associated with the packet. This allows switches and other TrustSec aware infrastructure to apply role based security decisions without depending entirely on source IP addressing. Catalyst 9800 policy profiles can enable CTS inline tagging for wireless client traffic. The surrounding wired infrastructure must also support the required TrustSec configuration so the tag can be preserved and interpreted correctly after traffic leaves the wireless controller.

Question 375. What does SGACL enforcement provide

  1. Role based traffic filtering
  2. Dynamic channel assignment
  3. AP software predownload
  4. DHCP address allocation

Correct Answer: 1. Role based traffic filtering

Explanation:

Security Group Access Control List enforcement provides policy filtering based on TrustSec security group relationships. Instead of defining access only by traditional source and destination IP addresses, the network can determine whether traffic between assigned security groups should be allowed or denied. Catalyst 9800 can enable role based enforcement within the wireless policy profile. This supports identity oriented segmentation where access policy follows the user’s or device’s security role. Proper TrustSec design also requires coordination with the wider network so security group tags and corresponding policies remain consistent beyond the wireless controller.

Question 376. Which command behavior enables SGACL enforcement in a wireless policy profile

  1. CAPWAP forwarding
  2. CTS role based enforcement
  3. DCA restart
  4. AP image predownload

Correct Answer: 2. CTS role based enforcement

Explanation:

Catalyst 9800 uses CTS role based enforcement within a wireless policy profile to enable Security Group Access Control List processing for wireless client traffic. This setting allows the controller to participate in TrustSec role based security decisions. It is separate from CTS inline tagging, which controls whether SGT information is carried with outgoing packets. Administrators can use both features together when the design requires the controller to enforce security group policy and preserve TrustSec identity information across the wired infrastructure.

Question 377. When is a default SGT especially required according to Cisco guidance

  1. When DFS is enabled
  2. When clients use DHCP
  3. When clients use open authentication without ISE
  4. When APs use FlexConnect

Correct Answer: 3. When clients use open authentication without ISE

Explanation:

Cisco notes that a default Security Group Tag is required for a user session when the client uses open authentication and the SGT is not being supplied by Cisco ISE. In an identity integrated environment, ISE can dynamically provide appropriate security group information after evaluating the user or device. With open authentication and no external SGT assignment, the controller needs a configured default value if TrustSec classification is required. This ensures traffic still receives a usable security group identity for downstream TrustSec policy decisions.

Question 378. What must be configured on the physical interface for TrustSec inline operation

  1. CTS manual
  2. Sniffer mode
  3. DHCP snooping only
  4. Bridge Group Name

Correct Answer: 1. CTS manual

Explanation:

Cisco TrustSec documentation notes that CTS manual configuration is required on the relevant physical interface when using inline tagging in the documented Catalyst 9800 design. The wireless policy profile then enables CTS inline tagging so Security Group Tag information is correctly handled for client traffic. TrustSec therefore requires coordination between the wireless policy configuration and the physical network interface configuration. Enabling a TrustSec checkbox in the WLAN policy alone is not sufficient if the connected infrastructure is not prepared to carry and interpret the security group information.

Question 379. Why should APs have a primary controller during certain AP service package workflows

  1. To increase RF power
  2. To change client VLANs
  3. To disable CAPWAP
  4. To prevent repeated switching between controllers

Correct Answer: 4. To prevent repeated switching between controllers

Explanation:

Cisco warns that when APs do not have a defined primary controller during certain Access Point Service Pack workflows, controllers with different AP software package states can both respond to AP discovery requests. This can cause access points to repeatedly move between controllers instead of remaining on the intended destination. Configuring a primary controller gives the AP a clear preference and stabilizes its controller relationship during the maintenance process. Deterministic controller assignment is therefore important when multiple controllers temporarily run different AP package combinations.

Question 380. What does site based rolling upgrade allow administrators to control

  1. AP antenna polarization
  2. Which sites are upgraded in each phase
  3. Client password complexity
  4. DFS radar sensitivity

Correct Answer: 2. Which sites are upgraded in each phase

Explanation:

Site based Rolling AP Upgrade allows administrators to select access points according to their site tags and move through the software deployment in controlled phases. A site filter can initially include a limited group of sites, and additional site tags can be added later as the administrator becomes comfortable with the new software. This staged approach limits operational exposure and makes it possible to validate the update in selected locations before broad deployment. Cisco also supports predownload and migration to a destination controller as part of the site based N plus 1 workflow.