Your success in Cisco 400-351 is our sole target and we develop all our 400-351 braindumps in a way that facilitates the attainment of this target. Not only is our 400-351 study material the best you can find, it is also the most detailed and the most updated. 400-351 Practice Exams for Cisco CCIE Wireless 400-351 are written to the highest standards of technical accuracy.
2026 New 400-351 Exam Dumps with PDF and VCE Free: https://www.2passeasy.com/dumps/400-351/
Q1. Which statement about wireless LAN security in a Cisco Unified Wireless Network VoWLAN deployment is false?
A. EAP-FAST, if available, is the recommended EAP type for use in VoWLAN deployments.
B. Although LEAP is considered secure for VoWLAN handsets when correctly deployed, it is recommended that a different EAP method (FAST, PEAP, TLS) is used, if available.
C. Dynamic WEP mitigates the security weaknesses in static WEP, making it a viable option that can be relied upon to secure a VoWLAN deployment.
D. When using EAP authentication, the EAP-Request timeout value should be adjusted based only on the advice of the VoWLAN handset vendor.
E. When using WPA Personal, strong keys should be used to avoid a dictionary attack.
Answer: D
Q2. Drag and drop steps of the 802.1x authentication process on the left to the corresponding number on the right.
Answer:
Q3. The network operations center is using PI to collect and monitor the AVC data from a cisco WLC however no AVC information is showing up in cisco PI based on this information from the Cisco WLC reason that Cisco PI is not showing the information is True.?
A. Cisco prime does not have the correct licensing installed.
B. The monitor-Name and exporter-name do note match
C. The Exporter-IP should be the IP address of the cisco WLC
D. The port number should be 9991.
Answer: D
Q4. Why would you enable the RFC 3578 option when adding a new RADIUS authentication server to a WLC?
A. you want to run both RADIUS and TACACS
B. to support Disconnect and Change of Authorization
C. to encrypt communications between the WLC and the RADIUS server
D. to support RADIUS key wrapping
Answer: B
Explanation:
If you are configuring a new RADIUS authentication server, choose Enabled from the Support for RFC 3576 drop-down list to enable RFC 3576, which is an extension to the RADIUS protocol that allows dynamic changes to a user session, or choose Disabled to disable this feature. The default value is Enabled. RFC 3576 includes support for disconnecting users and changing authorizations applicable to a user session and supports disconnect and change-of-authorization (CoA) messages. Disconnect messages cause a user session to be terminated immediately where CoA messages modify session authorization attributes such as data filters.
Q5. Which option in the cisco identity service engine allows for authorization based on Active Directory user and domain computer login?
A. Machine access restriction
B. Active directory group
C. Active directory attributes
D. Identity source sequences
Answer: A
Q6. based upon the given configuration which two statement are true? (choose two)
A. local RADIUS server is used
B. No password is required everyone can join wireless network
C. Users will be required to provide a username and password for authentication
D. User will be required to provide a password only order to get access
E. Remote RADIUS servers is used
Answer: A, C
Q7. Which two statement about AP local authentication by FlexConnect AP in standalone mode are true?(choose two)
A. Only LEAP,EAP F AST,PEAP and EAP-TLS authentication are supported
B. Only the vendor certificate authority (CA) certificate has to be downloaded to the Cisco wireless LAN controller for EAP-TLS authentication
C. Cisco wireless LAN controller must generate a certificate signing request by itself for submitting to a certificate authority for signing.
D. A flexconnect group must be created so that the cisco wireless LAN Controller can push the certificate to the flexconnect AP in the Flexconnect group.
Answer: A, D
Q8. Which two features require Network Time Protocol synchronization on the Cisco 5760 WLC?(Choose two)
A. AP CAPWAP multicast
B. SNMPv3
C. AP authentication
D. Band Select
Answer: B, C
Q9. Refer to the exhibit The wireless clients use VLAN 2150.the WLC Management is on VLAN 2149 and the lAPs use VLAN 2100 wireless clients report that they cannot access multicast routing enabled which two options must be enabled for the clients to receive multicast video? (Choose two)
A. MSDP
B. ip pim-sparse mode on VLAN 2149
C. ip igmp snooping
D. ip pim-sparse mode on VLAN 2150
Answer: B, D
Q10. DRAG DROP Drag and drop the RRM function on the left to the entity that performs the function on the right
Answer:
Exhibit