Download of 400-351 test preparation materials and courses for Cisco certification for IT engineers, Real Success Guaranteed with Updated 400-351 pdf dumps vce Materials. 100% PASS CCIE Wireless Written Exam exam Today!
2026 New 400-351 Exam Dumps with PDF and VCE Free: https://www.2passeasy.com/dumps/400-351/
Q1. Refer to the exhibit .
According to the debugs and loin the Cisco WLC and Cisco LAP which WLC discovery Algorithm is used by the LAP to join the Cisco WLC?
A. DHCP server LAP sends a layer 3 CAPWAP discover request to the Cisco WLC that is listed m the DHCP option 43.
B. configured LAP sends a uncast layer 3 CAPWAP discover request to the Cisco WLC IP address that the LAP has in its NVRAM
C. Broadcast lap broadcasts a layer 3 CAPWAP discover massage on the local ip subnet
D. DNS lap resolve the DNS Name CISCO-CAPWAP-CONTEOLLER cisco to the Cisco WLC ip address then it sends a uncast layer 3 CAPWAP discovery request to the Cisco WLC
Answer: A
Q2. Which two statement about LAG in the Cisco wireless LAN controller running Aire OS 8.0 are true?(choose two)
A. LAG bundles all of the crsco WLC distribution system ports into a single 802.3ad port channel.
B. There can be only one AP-manager interface if LAG is enabled
C. LAG configuration change take effect immediately after they are configured
D. Channel negotiation LACP and PAgP are supported
Answer: A, B
Q3. You are implementing a WLC at a remote site and want to make sure that you are able to sync up with the Cisco WCS at the central site. Which two statements about this process are true? (Choose two.)
A. If the WLC is behind a firewall, you must make sure that UDP ports 161 and 162 are open.
B. The Cisco WCS server does not need direct IP connectivity to the WLC.
C. Cisco WCS will not be able to communicate with the WLC if the WLC is behind a NAT device.
D. If the WLC is behind a NAT device, the WLC's dynamic AP-manager interface must be configured with the external NAT IP address.
Answer: A, C
Q4. DRAG DROP
Drag and drop the AVC configuration feature on the left to their respective function on the right.?
Answer:
Exhibit
Q5. Which option in the cisco identity service engine allows for authorization based on Active Directory user and domain computer login?
A. Machine access restriction
B. Active directory group
C. Active directory attributes
D. Identity source sequences
Answer: A
Q6. While troubleshooting a failed central web authentication configuration on cisco WLC you discover that the Cisco WLC policy manager state is showing RUN For new client and not CENTRAL_WEB_AUTH what is most likely the issue.?
A. The WLAN Layer 2 security should be sent to WPA+WPA2
B. The WLAN NAC state should be set to RADIUS NAC
C. The web login page under the cisco WLC security should be set to external (redirect to external server)
D. The WLAN layer 3 security should be set to web page policy with condition web redirect.
Answer: B
Q7. Which three statements about 802.11ac are true? (choose three)
A. MU-MIMO is supported in wave 1
B. MU-MIMO allows one AP to transmit unique data to multiple stations simultaneously
C. when using MU-MIMI up to 8 devices can transmit data at the same time
D. 802.11 a/b/g/n device are able to connect to 802.11ac radios
E. it IS possible to reach 160 MHz by combining two discontinuous 80 MHz channel block
F. 802.11 ac is supported in the 2.4- and 5-Ghz radio band
Answer: B, D, E
Q8. DRAG DROP Drag and drop the RRM function on the left to the entity that performs the function on the right
Answer:
Exhibit
Q9. Your customer is having wireless VoIP problems. When the Cisco 7925 phones roam from APtlo AP2, the voice drops out and comes back. The phones are set up for PEAP/WPA2-AES with CCKM to an external RADIUS server .The APs and WLAN are setup in FlexConnect mode. Which statement explains the issue?
A. PEAP with WPA2-AES is not supported with Cisco Centralized Key Management, use EAP-FAST.
B. The APs have not been added to the FlexConnectgroup .
C. PEAP with WPA2-AES is not supported with Cisco Centralized Key Management, use LEAP.
D. The APs have been added to the FlexConnectgroup .
Answer: B
Q10. Why would you enable the RFC 3578 option when adding a new RADIUS authentication server to a WLC?
A. you want to run both RADIUS and TACACS
B. to support Disconnect and Change of Authorization
C. to encrypt communications between the WLC and the RADIUS server
D. to support RADIUS key wrapping
Answer: B
Explanation:
If you are configuring a new RADIUS authentication server, choose Enabled from the Support for RFC 3576 drop-down list to enable RFC 3576, which is an extension to the RADIUS protocol that allows dynamic changes to a user session, or choose Disabled to disable this feature. The default value is Enabled. RFC 3576 includes support for disconnecting users and changing authorizations applicable to a user session and supports disconnect and change-of-authorization (CoA) messages. Disconnect messages cause a user session to be terminated immediately where CoA messages modify session authorization attributes such as data filters.