exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 861 discussion

Actual exam question from Cisco's 350-401
Question #: 861
Topic #: 1
[All 350-401 Questions]

An engineer modifies the existing ISE guest portal URL to use a static FQDN. Users immediately report that they receive certificate errors when they are redirected to the new page. Which two additional configuration steps are needed to implement the change? (Choose two.)

  • A. Add a new DNS record to resolve the FQDN to the PSN IP address
  • B. Create and sign a new CSR that contains the static FQDN entry
  • C. Manually configure the hosts file on each user device.
  • D. Disable HTTPS on the WLC under the Management menu
  • E. Add the FQDN entry under the WLC virtual interface
Show Suggested Answer Hide Answer
Suggested Answer: AB 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
cjoyce1980
6 months ago
Selected Answer: AB
The two correct additional configuration steps needed to implement the change are: A. Add a new DNS record to resolve the FQDN to the PSN IP address This is required so that when users try to access the FQDN, it correctly resolves to the IP address of the Policy Service Node (PSN), ensuring proper redirection. B. Create and sign a new CSR that contains the static FQDN entry A new certificate must be generated with the static FQDN in the subject or subject alternative name (SAN) field. This is necessary to avoid certificate errors, as the certificate must match the new FQDN for secure HTTPS connections. Explanations for incorrect options: C: Manually configuring the hosts file on each user device is not a scalable or practical solution for large networks. D: Disabling HTTPS on the Wireless LAN Controller (WLC) under the Management menu would not resolve certificate issues, and it would reduce security. E: While adding the FQDN to the WLC virtual interface could help with redirection, it does not address the certificate error issue directly.
upvoted 2 times
...
ferdomravec87
6 months, 1 week ago
Selected Answer: AE
I believe A is wrong, read the question. Users are reporting certificate errors, meaning they already can reach the new FQDN so it already is in DNS. So I am going with AE for this one.
upvoted 1 times
...
chiacche
7 months ago
Selected Answer: AB
1. FQDN is the unique identifier for a website or service. 2. CSR needs to include the FQDN so that the CA can issue an SSL certificate for that FQDN. 3. DNS resolves the FQDN to the corresponding IP address, ensuring users can access the website or service.
upvoted 1 times
...
Shri_Fcb10
11 months ago
Selected Answer: AB
Adding the FQDN to the Wireless LAN Controller (WLC) virtual interface is often necessary for proper redirection and SSL certificate matching. However, it does not directly address the two main issues causing certificate errors: DNS resolution and cert matching
upvoted 3 times
...
[Removed]
11 months ago
Selected Answer: AB
A and B are correct tested in a real environment
upvoted 2 times
...
supershysherlock
1 year, 1 month ago
Selected Answer: AB
A & B are correct
upvoted 4 times
...
supershysherlock
1 year, 1 month ago
Option E, adding the FQDN entry under the WLC virtual interface, does not directly address certificate errors. This step is unnecessary for resolving certificate issues related to the ISE guest portal URL. Instead, focus on ensuring proper DNS resolution and configuring the correct SSL certificate with the FQDN.
upvoted 1 times
...
Osama_anwar
1 year, 1 month ago
Selected Answer: AB
are the correct answer
upvoted 2 times
...
slacker_at_work
1 year, 1 month ago
https://community.cisco.com/t5/network-access-control/where-to-configure-public-fqdn-for-guest-users-in-cisco-ise-or/td-p/4869630 this proves once again that I am right, A & E
upvoted 2 times
...
slacker_at_work
1 year, 1 month ago
Selected Answer: AE
A. By adding a new DNS record to resolve the FQDN to the PSN (Policy Services Node) IP address, users will be able to resolve the FQDN to the correct IP address when accessing the guest portal, thus avoiding certificate errors. E. Adding the FQDN entry under the WLC (Wireless LAN Controller) virtual interface ensures that the WLC can correctly handle the traffic directed to the static FQDN for the guest portal. The other options (B, C, D) are not relevant or necessary for addressing certificate errors when redirecting users to the new page using a static FQDN.
upvoted 3 times
...
teems5uk
1 year, 3 months ago
Selected Answer: AB
Given answer is correct.
upvoted 4 times
...
shefo1
1 year, 3 months ago
Selected Answer: AB
the below AI chatbots say that option A and B is right - chatGPT , google BARD (google) , capilot (windows) , Aria (opera mini) , LEO (brave browser)
upvoted 3 times
...
nerostart
1 year, 3 months ago
Selected Answer: AE
I think correct answers should be A&E
upvoted 1 times
...
Tadese
1 year, 4 months ago
Selected Answer: AE
AE think corect
upvoted 1 times
...
Toob93
1 year, 4 months ago
Selected Answer: AE
I think correct answers should be A&E
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago