Exit demo 642-737 Implementing Advanced Cisco Unified Wireless Security (IAUWS) v2.0 PDF format · free preview

Cisco 642-737 - Questions & Answers

Free preview · every answer includes a full explanation

Product page: https://prepkeys.com/642-737.html

Question 1
Single choice

RADIUS is set up with multiple servers on the controller and an engineer wants to select each server for specific WLANs.

Where in the controller GUI is this configuration completed?

A.

Security > AAA > RADIUS

B.

Security > AAA > RADIUS > Fallback

C.

Security > Authentication > RADIUS

D.

WLANs > WLAN ID > Security > AAA Servers

E.

WLANs > WLAN ID > Security > Layer 3

F.

WLANs > WLAN ID > Advanced > AAA Servers

Question 2
Multiple choice

An engineer must change the wireless authentication from WPA2-Personal to WPA2- Enterprise.

Which three requirements are necessary? (Choose three.)

A.

802.1X

B.

EAP

C.

fast secure roaming

D.

802.11i

E.

RADIUS

F.

802.11u

G.

pre-shared key

Question 3
Multiple choice

An engineer must segment traffic into separate WLANs.

Which three factors should be used to determine traffic segmentation? (Choose three.)

A.

QoS policy

B.

subnet requirements

C.

application requirements

D.

security capabilities

E.

access control policies for voice

F.

enterprise resource planning

Question 4
Multiple choice

Which three RADIUS IETF attributes should be enabled on the Cisco Secure ACS v4.2 when implementing IBN for VLAN assignment to the Cisco WLC v7.0? (Choose three.)

A.

[064] Tunnel-Type

B.

[065] Tunnel-Medium-Type

C.

[066] Tunnel-Client-Endpoint

D.

[067] Tunnel-Server-Endpoint

E.

[069] Tunnel-Password

F.

[081] Tunnel-Private-Group-ID

G.

[082] Tunnel-Private-User-ID

Question 5
Multiple choice

An engineer is changing the encryption method of a wireless network from PEAP-MS-CHAP V2 to EAP-TLS.

Which two changes are necessary? (Choose two.)

A.

The authentication server requires a new certificate.

B.

All authentication clients require their own certificates.

C.

The users require the Cisco AnyConnect client.

D.

A new certificate is required for each authenticated user.

E.

A Cisco NAC server is required.

F.

Cisco Secure ACS is required.

Question 6
Single choice

An engineer is deploying a Cisco NAC appliance in a highly routed environment and requires it to act as a DHCP server.

What deployment model should be used?

A.

Layer 3 Virtual Gateway OOB Real-IP Gateway

B.

Layer 2 Virtual Gateway

C.

Layer 2 Real IP

D.

Layer 3 Real IP

Question 7
Multiple choice

Which three security features can be gained by installing a Cisco NAC Appliance into the network? (Choose three.)

A.

in-band or out-of-band deployment options

B.

intrusion detection

C.

bandwidth and traffic filtering controls

D.

posture assessment

E.

accurate identification, classification, and stopping of malicious traffic

F.

detection and containment of rogue clients

Question 8
Single choice

An engineer creating a configuration file to upload to a controller would like the guest WLAN to be set for L3 authentication only.

What command must be included in the configuration file?

A.

config wlan security web-auth enable 2

B.

config wlan security wpa wpa2 disable 2

C.

config wlan security web-auth server-precedence 2 local radius ldap

D.

config wlan custom-web global enable 2

Question 9
Multiple choice

Which two attacks represent a social engineering attack? (Choose two.)

A.

using AirMagnet Wi-Fi Analyzer to search for hidden SSIDs

B.

calling the IT helpdesk and asking for network information

C.

spoofing the MAC address of an employee device

D.

entering a business and posing as IT support staff

Question 10
Single choice

When configuring the WLC for single sign-on for the NAC, which device is used for the RADIUS accounting IP address?

A.

Cisco NAC Appliance Manager

B.

Cisco NAC Appliance Server

C.

Cisco NAC Guest Server

D.

Cisco ACS

E.

Cisco WCS

Showing 10 of 206 questions · Unlock the full set