exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 993 discussion

Actual exam question from Cisco's 350-401
Question #: 993
Topic #: 1
[All 350-401 Questions]

An engineer must construct an access list for a Cisco Catalyst 9800 Series WLC that will redirect wireless guest users to a splash page that is hosted on a Cisco ISE server. The Cisco ISE servers are hosted at 10.9.11.144 and 10.1.11.141. Which access list meets the requirements?

  • A.
  • B.
  • C.
  • D.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JeremieB
Highly Voted 7 months, 3 weeks ago
Selected Answer: D
https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#toc-hId-881505252
upvoted 6 times
yasmiine
6 months, 3 weeks ago
thank's for this link. But I'm little confused, it indicates that "domain" must be denyed, so the answer would be "C" ! Another thing, in the anwser D, the port www and 80 are the same, so it's a repetition ?
upvoted 4 times
...
...
dspdassanayake
Most Recent 2 days, 12 hours ago
Selected Answer: D
Source : https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html ip access-list extended REDIRECT deny ip any host <ISE-IP> deny ip host<ISE-IP> any deny udp any any eq domain deny udp any eq domain any permit tcp any any eq 80 You can improve the ACL by action to deny only the guest port 8443 to the ISE server.
upvoted 1 times
...
NetworkJanitor
1 month, 4 weeks ago
Selected Answer: D
D is the only one that closely matches Cisco's example in JeremieB's link The rest do not prohibit ISE hosts flows in both directions (src > dst AND dst -> src)
upvoted 1 times
...
AbdullahMohammad251
2 months ago
Selected Answer: C
A & B are not correct, you need to deny traffic to your ISE servers. The answer could be C or D but I think both are missing some statements. Since 'C' denies DNS traffic, but 'D' doesn't. I would go with 'C'
upvoted 2 times
AbdullahMohammad251
2 months ago
Option 'D' would be correct if it includes the following: "deny udp any any eq domain." I think the answers are incomplete, and not as they're mentioned on the exam!
upvoted 1 times
...
...
AbdullahMohammad251
2 months ago
Selected Answer: D
You need to deny traffic to your ISE PSN (policy service node) nodes as well as deny DNS and permit all the rest. The WLC will look into traffic that it can redirect (ports 80 and 443 by default). CLI configuration for our scenario: ip access-list extended REDIRECT 10 deny ip any host 10.9.11.141 20 deny ip any host 10.1.11.141 30 deny ip host 10.9.11.141 any 40 deny ip host 10.1.11.141 any 50 deny udp any any eq domain 60 deny udp any eq domain any 70 permit tcp any any eq 80 ---> for HTTP redirection https://www.cisco.com/c/en/us/support/docs/wireless/catalyst-9800-series-wireless-controllers/213920-central-web-authentication-cwa-on-cata.html#toc-hId-881505252:~:text=443%20by%20default).-,CLI%3A,-ip%20access%2Dlist
upvoted 1 times
AbdullahMohammad251
2 months ago
A & B are not correct, you need to deny traffic to your ISE servers. The answer could be C or D but I think both are missing some statements. Since 'C' denies DNS traffic, but 'D' doesn't. I would go with 'C'
upvoted 1 times
...
...
Hazem_Salah
2 months, 2 weeks ago
C should be the correct answer
upvoted 1 times
...
OoxYxoO
3 months, 1 week ago
Selected Answer: C
correct answer is C Denies all IP traffic to and from the ISE servers. Denies DNS traffic (UDP port 53). Permits HTTP traffic (TCP port 80).
upvoted 1 times
...
Rfvaz
3 months, 2 weeks ago
Selected Answer: C
Make more sense.
upvoted 1 times
...
Rupal_rawal
4 months, 3 weeks ago
Selected Answer: D
D is correct. For the redirection ACL, think of the deny action as a deny redirection (not deny traffic) and the permit action as permit redirection. The WLC only looks into traffic that it can redirect (ports 80 and 443 by default).
upvoted 1 times
...
Batman25
5 months, 3 weeks ago
Option C is right. There should be a deny traffic for UDP ports towards a domain ip access-list extended REDIRECT deny ip any host <ISE-IP> deny ip host<ISE-IP> any deny udp any any eq domain deny udp any eq domain any permit tcp any any eq 80 ip access-list extended REDIRECT deny ip any host <ISE-IP> deny ip host<ISE-IP> any deny udp any any eq domain deny udp any eq domain any permit tcp any any eq 80
upvoted 4 times
...
[Removed]
6 months, 1 week ago
Selected Answer: C
C is the correct answer
upvoted 1 times
[Removed]
6 months, 1 week ago
my bad, D is the correct Answer
upvoted 2 times
...
...
e0a2673
7 months, 1 week ago
Selected Answer: C
C is correct You need to deny traffic to your ISE PSNs nodes as well as deny DNS and permit all the rest. This redirect ACL is not a security ACL but a punt ACL that defines what traffic goes to the CPU (on permits) for further treatment (like redirection) and what traffic stays on the data plane (on deny) and avoids redirection.
upvoted 4 times
...
Swiz005
7 months, 2 weeks ago
Selected Answer: B
How can D by correct when it's denying access to the ISE server - I'll go with B
upvoted 4 times
...
shefo1
7 months, 3 weeks ago
Selected Answer: B
from all chatbots (chatGPT,Gemini,Capilot , etc...) A) & C): These options deny traffic to the ISE servers (10.9.11.141 and 10.1.11.141) which would prevent communication for authentication purposes. D): This option also denies traffic to the ISE servers but with a different syntax. Additionally, it allows traffic to port 80 (HTTP) which might bypass the redirection process.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago