exam questions

Exam 300-430 All Questions

View all questions & answers for the 300-430 exam

Exam 300-430 topic 1 question 160 discussion

Actual exam question from Cisco's 300-430
Question #: 160
Topic #: 1
[All 300-430 Questions]

A healthcare organization notices many rogue APs and is concerned about a honeypot attack. Which configuration must a wireless network engineer perform in
Cisco Prime Infrastructure to prevent these attacks most efficiently upon detection?

  • A. Set the auto containment level to 0 and select the Using Our SSID containment option.
  • B. Set the manual containment level to 4 and select the Ad Hoc Rogue AP containment option.
  • C. Set the auto containment level to 0 and select the Ad Hoc Rogue AP containment option.
  • D. Set the auto containment level to 4 and select the Using Our SSID containment option.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Mimimimimi
Highly Voted 2 years, 4 months ago
Selected Answer: D
Answer is D. Honeypot attacks: A honeypot AP spoofs the SSID (and eventually MAC) of a real AP. Level 0 containment does not exist. Using our SSID option ensures that any rogue AP with the same SSID as "My Network" is contained.
upvoted 5 times
elmi4474
2 years, 3 months ago
At the first I agreed with you,bBut the questions stand for Cisco Prime Infrastructure. Using our SSID option is for WLC. So, I think i will stay for B.
upvoted 2 times
...
...
daeman
Highly Voted 2 years, 5 months ago
Selected Answer: B
B is the most logical answer here. https://www.cisco.com/c/en/us/td/docs/wireless/mse/3350/7-3/wIPS_Configuration_guide/Guide/wIPS/msecg_appB_wIPS.html The two answers with 0 containment aren't even valid options as the level is 1-4. Containing your own SSID makes no sense, so B is the only option left.
upvoted 5 times
...
rrahim
Most Recent 5 days, 22 hours ago
Selected Answer: D
Auto Containment Level to 4: Setting the auto containment level to 4 ensures that rogue APs are automatically contained as soon as they are detected. This level provides the most aggressive containment, which is necessary to prevent honeypot attacks and protect the network from unauthorized access points. Using Our SSID Containment Option: The Using Our SSID containment option ensures that rogue APs broadcasting the organization's SSID are contained. This is critical for preventing honeypot attacks, where attackers mimic the organization's SSID to lure clients into connecting to a malicious AP.
upvoted 1 times
...
Ocsicccnp
5 months ago
https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112045-handling-rogue-cuwn-00.html#toc-hId-715491869:~:text=Use%20of%20our%20SSID%20%2D%20If%20a%20rogue%20device%20uses%20an%20SSID%20which%20is%20the%20same%20as%20that%20configured%20on%20the%20controller%2C%20it%20is%20automatically%20contained.%20This%20feature%20aims%20to%20address%20a%20honey%2Dpot%20attack%20before%20it%20causes%20damage. Use of our SSID - If a rogue device uses an SSID which is the same as that configured on the controller, it is automatically contained. This feature aims to address a honey-pot attack before it causes damage.
upvoted 1 times
...
ahmedshahas
1 year, 2 months ago
Selected Answer: D
Use of our SSID - If a rogue device uses an SSID which is the same as that configured on the controller, it is automatically contained. This feature aims to address a honey-pot attack before it causes damage. https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112045-handling-rogue-cuwn-00.html#toc-hId-715491869
upvoted 1 times
...
peer1024
1 year, 4 months ago
Who can share the menue path to implement solution D on Prime 3.10? Unable to find it.
upvoted 1 times
...
GoldLeader
1 year, 7 months ago
Selected Answer: D
D. Agree with Mimimimimi, level 0 is not an option. Using own SSID is correct. The legit corp access points will send de-authentication messages to any client connected to the rouge AP on the corp SSID. It will not effect users connected to legit access points.
upvoted 2 times
...
peer1024
1 year, 8 months ago
Selected Answer: B
I did it on a testsystem: Dashboard > Incidents > Rogue Alarms > Open a destinctive Alarm > "AP containment" option > select "4 AP containment" The wording of "B" is really bad, but at least, I was able to use "B" as hint and to find the menue items in Prime 3.10 to complete this task. My prime is running in KVM and RHEL8 using the 12Gig RAM installation option. Disk is SAMSUNG SSD with 1000 MByte/s peak throughput
upvoted 1 times
...
Ripe
2 years, 1 month ago
Selected Answer: D
Answer is D Use of our SSID - If a rogue device uses an SSID which is the same as that configured on the controller, it is automatically contained. This feature aims to address a honey-pot attack before it causes damage.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago