Cisco CCNP 300-425 Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Cisco CCNP 300-425 Exam Dumps and Practice Test Dumps.


Question 321. What does AAA override allow a RADIUS server to change

  1. AP antenna type
  2. Client policy attributes
  3. Controller hardware
  4. RF channel width only

Correct Answer: 2. Client policy attributes

Explanation:

AAA override allows attributes returned by a RADIUS server to override locally configured wireless policy settings for an authenticated client. These attributes can influence VLAN assignment, access control lists, quality of service, and other supported client policies. This makes identity based wireless networking possible because two clients connected to the same WLAN can receive different network treatment according to their authentication results. AAA override is configured under the Catalyst 9800 wireless policy profile. It is especially useful when Cisco ISE or another RADIUS platform centrally determines user authorization.

Question 322. What is required before RADIUS can dynamically override a client VLAN

  1. Monitor mode
  2. Local DHCP
  3. Sniffer mode
  4. AAA override

Correct Answer: 4. AAA override

Explanation:

AAA override must be enabled in the wireless policy profile before the RADIUS server can dynamically override the normal client VLAN assignment. Once enabled, supported RADIUS attributes can return a VLAN ID, VLAN name, or VLAN group for the authenticated client. This allows the same SSID to place different users into different network segments according to identity or authorization policy. Without AAA override, the normal VLAN configured in the wireless policy profile remains the primary client assignment. Dynamic VLAN design is commonly combined with centralized enterprise authentication systems.

Question 323. Which RADIUS attribute can carry a VLAN name or VLAN ID

  1. Tunnel Private Group ID
  2. Calling Station ID
  3. NAS IP Address
  4. Framed MTU

Correct Answer: 1. Tunnel Private Group ID

Explanation:

The Tunnel Private Group ID attribute can carry the VLAN information returned to the Catalyst 9800 during client authentication. Cisco identifies RADIUS attribute 81 as supporting a VLAN ID, VLAN name, or VLAN group name for dynamic client assignment. Other tunnel related attributes are also used as part of standard RADIUS VLAN authorization. AAA override must be enabled in the wireless policy profile so the returned VLAN information can supersede the locally configured assignment. This approach allows centralized identity systems to place users into appropriate network segments dynamically.

Question 324. What happens when AAA VLAN fallback is enabled and the assigned VLAN is unavailable

  1. The controller reboots
  2. The client enters monitor mode
  3. The policy profile VLAN is used
  4. The AP changes channels

Correct Answer: 3. The policy profile VLAN is used

Explanation:

AAA VLAN fallback provides backup connectivity when a VLAN returned by the authentication server is unavailable on the controller or site. When fallback is enabled, the Catalyst 9800 can place the client into the VLAN configured in the wireless policy profile instead of simply denying network access. This is useful in distributed environments where one central AAA policy may return VLANs that are not present at every location. The feature therefore improves client connectivity while still allowing centralized dynamic VLAN assignment whenever the requested VLAN is available.

Question 325. What occurs if both the AAA assigned VLAN and fallback policy VLAN are unavailable

  1. The client receives the management VLAN automatically
  2. The client is excluded
  3. The AP reloads
  4. The controller creates the VLAN

Correct Answer: 2. The client is excluded

Explanation:

In a central switching deployment, if the AAA assigned VLAN is unavailable and the VLAN configured in the wireless policy profile is also not defined, Cisco treats the configuration as invalid and excludes the client. VLAN fallback can only preserve connectivity when a valid fallback network exists. The controller does not automatically create missing VLANs. Designers using dynamic authorization should therefore make sure that required VLANs or suitable fallback VLANs are consistently defined at the locations where clients can connect.

Question 326. What does per client bidirectional rate limiting control

  1. Total client bandwidth
  2. AP antenna gain
  3. Controller licensing
  4. Mobility group size

Correct Answer: 1. Total client bandwidth

Explanation:

Per client bidirectional rate limiting places an aggregate bandwidth limit on each wireless client in both upload and download directions. The configured rate applies to the total traffic generated by the client rather than separately limiting every application flow. For example, if a client simultaneously runs a video stream and a file transfer, both applications share the same overall bandwidth allowance. This prevents users from exceeding intended bandwidth limits simply by opening several traffic flows. Cisco implements the feature through QoS client policies applied in the wireless policy profile.

Question 327. Which class map is required for the documented per client rate limit design

  1. Voice class only
  2. Video class only
  3. Default class
  4. Multicast class

Correct Answer: 3. Default class

Explanation:

Cisco documents per client bidirectional rate limiting using a policy map containing the default class map. When the default class contains a valid police rate and the policy is attached as the QoS client policy, the access point applies the rate limit to each connected client. Cisco also notes that adding another class map prevents the documented per client rate limiting behavior from operating on the AP. Designers should therefore distinguish simple aggregate client rate limiting from more complex application or class based QoS policy designs.

Question 328. Where does central switching send wireless client traffic

  1. Directly to the branch switch only
  2. Directly to the Internet
  3. To the RADIUS server
  4. Through CAPWAP to the controller

Correct Answer: 4. Through CAPWAP to the controller

Explanation:

Central switching sends wireless user traffic through the CAPWAP tunnel from the access point to the centralized wireless controller. The controller then maps the traffic to the appropriate client VLAN or network interface. This is the normal centralized forwarding model for local mode access points. It differs from FlexConnect local switching, where client traffic can be placed directly onto the branch LAN by the AP. Designers should consider WAN topology, controller placement, application paths, security policy, and bandwidth when choosing between centralized and local forwarding architectures.

Question 329. What does central DHCP do for wireless clients

  1. Sends DHCP traffic through the controller
  2. Disables DHCP
  3. Uses only AP local addresses
  4. Converts DHCP to DNS

Correct Answer: 1. Sends DHCP traffic through the controller

Explanation:

Central DHCP causes DHCP traffic received from wireless clients to be forwarded centrally through the controller. The controller then sends the DHCP packets into the appropriate client VLAN according to the configured policy. This can be used together with centralized switching and authentication in a standard campus deployment. In FlexConnect designs, central DHCP can also be selected when client data forwarding and network services require a centralized architecture. Designers should make sure the DHCP server and relay paths are reachable from the client VLANs used by the wireless policy profile.

Question 330. Where is the normal client VLAN configured for a Catalyst 9800 WLAN policy

  1. RF profile
  2. Policy profile
  3. AP certificate
  4. Mobility group

Correct Answer: 2. Policy profile

Explanation:

The Catalyst 9800 wireless policy profile contains the normal VLAN assignment used for clients associated with the WLAN. The policy profile also contains many other client forwarding and service settings. A policy tag maps a WLAN profile to its corresponding policy profile and applies that combination to access points. If AAA override is enabled, the authentication server can return a different VLAN for an individual client. Without a valid override, the policy profile VLAN normally determines where centrally switched client traffic is placed.

Question 331. What does a RADIUS realm use to choose an authentication server

  1. AP serial number
  2. Client RSSI
  3. User domain information
  4. Channel number

Correct Answer: 3. User domain information

Explanation:

A RADIUS realm uses the domain portion of the user’s Network Access Identifier to select an appropriate authentication or accounting server. This allows one WLAN to serve users from different organizations or identity domains while routing their AAA requests toward different RADIUS systems. Realm based designs are useful in environments with multiple authentication domains, partner organizations, or federated wireless access requirements. The wireless controller examines the user identity information and applies the configured realm mapping rather than sending every authentication request to the same server group.

Question 332. What can RADIUS realms control besides authentication requests

  1. Accounting requests
  2. AP transmit power
  3. DFS channels
  4. Antenna polarization

Correct Answer: 1. Accounting requests

Explanation:

Catalyst 9800 RADIUS realm support can direct both authentication and accounting requests according to the domain information contained in the user Network Access Identifier. This provides consistent AAA routing for environments where different identity realms must use different RADIUS infrastructure. Authentication validates the user, while accounting records session related activity according to the configured AAA design. Realm based server selection gives administrators greater control than sending every WLAN user to one common RADIUS server regardless of the identity domain contained in the username.

Question 333. Which feature can authenticate a wireless client by MAC address

  1. BSS Coloring
  2. TPC
  3. OFDMA
  4. MAC filtering

Correct Answer: 4. MAC filtering

Explanation:

MAC filtering can authenticate or authorize a wireless client according to its device MAC address. Catalyst 9800 supports local authentication as well as external AAA based approaches for MAC filtering. This can be useful for devices that cannot perform normal 802.1X authentication, such as certain printers, sensors, and specialized equipment. MAC addresses are not strong secrets and can be spoofed, so MAC filtering should not normally be considered equivalent to certificate based authentication. It is best used when device limitations or specific network access requirements justify it.

Question 334. What format does Cisco require for a locally configured MAC authentication username

  1. Colon separated MAC
  2. Twelve hexadecimal characters without separators
  3. Dotted decimal address
  4. Eight character hostname

Correct Answer: 2. Twelve hexadecimal characters without separators

Explanation:

For local MAC filtering authentication, Cisco requires the MAC address username in a continuous hexadecimal format without normal punctuation separators. Cisco documentation gives the format as twelve hexadecimal characters similar to abcdabcdabcd. The address is configured as a local username before the WLAN is configured to use MAC filtering for local authentication. Using the correct format is important because a colon separated or hyphen separated MAC address will not match the expected local authentication entry. External AAA deployments can use their own supported identity database formatting rules.

Question 335. What must be enabled in the policy profile for the documented MAC filtering SSID design

  1. AAA override
  2. Hyperlocation
  3. Mesh CAC
  4. Sniffer mode

Correct Answer: 1. AAA override

Explanation:

Cisco’s documented Catalyst 9800 MAC authentication SSID configuration enables AAA override in the wireless policy profile. This allows authorization information returned during MAC based authentication to influence the client policy applied by the controller. MAC filtering can be associated with a local or external authorization method depending on the deployment. Because many devices using MAC authentication are specialized endpoints with limited security capability, designers should combine this mechanism with appropriate segmentation and access restrictions instead of treating the MAC address itself as strong proof of identity.

Question 336. Which setting can a Catalyst 9800 policy profile contain

  1. Building wall material
  2. Spectrum analyzer model
  3. Client access control policy
  4. Antenna mounting bracket

Correct Answer: 3. Client access control policy

Explanation:

A Catalyst 9800 policy profile can contain client service settings such as VLAN assignment, access control lists, quality of service configuration, mobility anchor information, timers, and switching behavior. The WLAN profile defines wireless network characteristics while the policy profile determines much of the treatment clients receive after connecting. This separation makes the Catalyst 9800 configuration model reusable because one WLAN can be combined with different policies in different deployment areas when required. Physical RF characteristics such as wall attenuation and antenna mounting are design inputs rather than policy profile attributes.

Question 337. Which three settings are normally enabled for a local mode centrally switched WLAN

  1. Monitor Sniffer and Bridge
  2. Central switching Central authentication and Central DHCP
  3. Local switching Local DHCP and Local authentication
  4. Mesh Sensor and SE Connect

Correct Answer: 2. Central switching Central authentication and Central DHCP

Explanation:

Cisco guidance for a normal local mode WLAN indicates that the policy profile should use central switching, central authentication, and central DHCP when those services are handled through the wireless controller. Central switching tunnels user traffic through CAPWAP to the controller. Central authentication keeps the authentication workflow centralized, while central DHCP forwards client address assignment traffic through the controller into the appropriate VLAN. This design is common in campus environments where the controller and centralized services are reachable through high capacity infrastructure rather than a constrained branch WAN.

Question 338. How does per client rate limiting handle several simultaneous application flows

  1. Each flow gets the full limit
  2. Only the first flow is permitted
  3. Video bypasses the limit
  4. All flows share one aggregate limit

Correct Answer: 4. All flows share one aggregate limit

Explanation:

Per client bidirectional rate limiting applies one aggregate bandwidth limit across all traffic generated by a wireless client. If the client runs several applications at the same time, the combined traffic remains subject to the configured client rate. This corrects a limitation of older per flow approaches where every individual stream could receive the complete configured limit and a user could therefore exceed the intended total bandwidth. The aggregate method is useful for guest networks and other deployments where administrators want predictable and fair bandwidth consumption per connected device.

Question 339. What can AAA override dynamically provide to individual wireless clients

  1. AP firmware
  2. Antenna gain
  3. VLAN QoS and ACL attributes
  4. RF channel plans

Correct Answer: 3. VLAN QoS and ACL attributes

Explanation:

AAA override enables RADIUS authorization to dynamically apply supported attributes such as VLAN assignment, quality of service, and access control lists to individual wireless clients. This is a key identity networking capability because users on the same SSID can receive different access policies according to their identity, device type, role, or authorization result. The attributes returned by the AAA server take precedence over corresponding local settings where the feature supports the override. Cisco ISE is commonly used to provide this type of centralized policy decision in enterprise wireless environments.

Question 340. What is the valid VLAN ID range documented for Catalyst 9800 override VLANs

  1. 1 through 4094
  2. 1 through 255
  3. 1 through 1024
  4. 1 through 8192

Correct Answer: 1. 1 through 4094

Explanation:

Cisco documents the valid VLAN ID range as 1 through 4094 when defining VLANs that can be assigned through RADIUS override. These VLANs must exist in the controller and surrounding wired infrastructure where required for centrally switched traffic. Dynamic authorization does not automatically create missing network segments. Designers should therefore coordinate wireless VLAN assignment with switching, routing, DHCP, security, and AAA policy configuration. If the AAA server returns an unavailable VLAN, the client can be excluded unless the supported AAA VLAN fallback feature has been configured to provide an alternate policy profile VLAN.