exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 337 discussion

Actual exam question from Cisco's 200-301
Question #: 337
Topic #: 1
[All 200-301 Questions]

A WLC sends alarms about a rogue AP, and the network administrator verifies that the alarms are caused by a legitimate autonomous AP. How must the alarms be stopped for the MAC address of the AP?

  • A. Remove the AP from WLC management
  • B. Place the AP into manual containment.
  • C. Manually remove the AP from Pending state.
  • D. Set the AP Class Type to Friendly.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
splashy
Highly Voted 2 years, 7 months ago
Keyword is "legitimate autonomous AP" Answer is D I think option B will kick the clients, which you probably don't want https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112045-handling-rogue-cuwn-00.html#anc23 https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112045-handling-rogue-cuwn-00.html#anc34 https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112045-handling-rogue-cuwn-00.html#anc32 Also search for "Valid client on Rogue AP" in provided links
upvoted 19 times
[Removed]
2 years, 7 months ago
I agree basIn order to classify a rogue AP as friendly, malicious, or unclassified, navigate toMonitor > Rogue > Unclassified APs, and click the particular rogue AP name. Choose the option from the drop-down list, as shown in the image.ed on the article" Taken from the article in the link "
upvoted 3 times
[Removed]
2 years, 7 months ago
Didnt paste that in so smoothly but you get my point
upvoted 1 times
...
...
[Removed]
1 year, 4 months ago
Yes, you're right. In the docs you'll find a discussion on exactly what "containment" is in this context: "Containment is a method that uses over-the-air packets to temporarily interrupt service on a rogue device until it can physically be removed. Containment works with the spoof of de-authentication packets with the spoofed source address of the rogue AP so that any clients associated are kicked off." Since it's a legitimate friendly AP, that's obviously not what you want to do.
upvoted 1 times
...
...
fefyk
Highly Voted 1 year, 2 months ago
Fk you net acad
upvoted 9 times
...
onyia.edward
Most Recent 10 months, 1 week ago
Rule-Based Rogue States Classification Type • Internal—If the unknown access point is inside the network and poses no threat to WLAN security, you would manually configure it as Friendly, Internal. An example is the access points in your lab network. • External—If the unknown access point is outside the network and poses no threat to WLAN security, you would manually configure it as Friendly, External. An example is an access point that belongs to a neighboring coffee shop. • Alert—The unknown access point is moved to Alert if it is not in the neighbor list or in the user-configured friendly MAC list. Friendly link https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/16-2/configuration_guide/b_162_consolidated_3850_cg/b_162_consolidated_3850_cg_chapter_01100101.pdf
upvoted 1 times
...
1b81c0c
11 months, 2 weeks ago
Selected Answer: D
Must be more D than B
upvoted 1 times
...
lmmujsi
1 year ago
Selected Answer: D
On a Cisco Wireless LAN Controller (WLC), when a rogue AP alarm is received and it is determined that the AP is indeed legitimate, you can stop the alarms for that particular AP by designating it as a 'Friendly' AP. This is done to acknowledge that the AP is known and not a security threat. The correct way to stop the alarms for the MAC address of a legitimate autonomous AP is: D. Set the AP Class Type to Friendly. By classifying the AP as 'Friendly,' the WLC recognizes the AP as a known and trusted device, and it will not trigger rogue AP alarms for that MAC address in the future. This is the standard way of handling such a scenario on a Cisco WLC.
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: D
it´s D
upvoted 1 times
...
aklas
1 year, 4 months ago
Selected Answer: D
Answer is D: "If a rogue AP is classified as friendly, it means that the rogue AP exists in the vicinity, is a known AP, and need not be tracked. Therefore, all the rogue clients are either deleted or not tracked if they are associated with the friendly rogue AP." https://content.cisco.com/chapter.sjs?uri=/searchable/chapter/content/en/us/td/docs/wireless/controller/7-5/configuration-guide/b_cg75/b_cg75_chapter_0111010.html.xml B will remove the client from the network by using the nearby legitimate APs to jam it. This doesn't turn off the alarms either: https://www.cisco.com/c/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112045-handling-rogue-cuwn-00.html#toc-hId--1159393380
upvoted 1 times
...
wakaish
1 year, 7 months ago
Manual containment is the appropriate action in this case. It allows you to manually identify the AP as legitimate and prevent the WLC from sending rogue AP alarms for that specific AP. This way, the WLC will stop treating it as a rogue and generating alarms while still being managed by the WLC.
upvoted 1 times
...
raul_kapone
1 year, 8 months ago
Selected Answer: D
When the controller receives a rogue report from one of its managed access points, it responds as follows: 1. The controller verifies that the unknown access point is in the friendly MAC address list. If it is, the controller classifies the access point as Friendly. 2. If the unknown access point is not in the friendly MAC address list, the controller starts applying rogue classification rules. Source: https://content.cisco.com/chapter.sjs?uri=/searchable/chapter/content/en/us/td/docs/wireless/controller/7-5/configuration-guide/b_cg75/b_cg75_chapter_0111010.html.xml
upvoted 1 times
raul_kapone
1 year, 8 months ago
If the rogue access point is not on the network, the controller marks the rogue state as Alert, and you can manually contain the rogue.
upvoted 1 times
...
...
Isuzu
1 year, 11 months ago
Selected Answer: D
A WLC will send alarms about a rogue AP when it detects an AP that is not under its management. This can happen when a legitimate autonomous AP is installed on the network. To stop the alarms, the network administrator must set the AP Class Type to Friendly. This will tell the WLC that the AP is a legitimate AP and that it should not send alarms about it. The other options are incorrect for the following reasons: Removing the AP from WLC management will stop the alarms, but it will also prevent the WLC from managing the AP. This is not necessary, since the AP is a legitimate AP. Placing the AP into manual containment will stop the alarms, but it will also prevent the AP from being used by clients. This is not necessary, since the AP is a legitimate AP. Manually removing the AP from Pending state will not stop the alarms. The WLC will continue to send alarms about the AP until the AP Class Type is set to Friendly.
upvoted 3 times
...
liviuml
2 years ago
Selected Answer: D
Answer is D. Search for "Table 1. Classification Mapping" in following link: https://content.cisco.com/chapter.sjs?uri=/searchable/chapter/content/en/us/td/docs/wireless/controller/7-5/configuration-guide/b_cg75/b_cg75_chapter_0111010.html.xml Regards,
upvoted 1 times
...
Ciscoman021
2 years ago
Selected Answer: B
If the alarms sent by the WLC are caused by a legitimate autonomous AP, the most appropriate action to stop the alarms for the MAC address of the AP is: B. Place the AP into manual containment. Manual containment is a method used to block a rogue AP and prevent it from interfering with the wireless network. It is a more targeted and less disruptive method compared to removing the AP from WLC management altogether, which would result in loss of connectivity for the AP.
upvoted 1 times
...
linuxlife
2 years, 1 month ago
Rogue Classification Rules Rogue classification rules, allow you to define a set of conditions that mark a rogue as either malicious or friendly. These rules are configured at the PI or the WLC, but they are always performed on the controller as new rogues are discovered.
upvoted 1 times
linuxlife
2 years, 1 month ago
Rogue Containment Containment is a method that uses over-the-air packets to temporarily interrupt service on a rogue device until it can physically be removed. Containment works with the spoof of de-authentication packets with the spoofed source address of the rogue AP so that any clients associated are kicked off.
upvoted 1 times
linuxlife
2 years, 1 month ago
https://www.cisco.com/c/dam/en/us/support/docs/wireless/4400-series-wireless-lan-controllers/112045-handling-rogue-cuwn-00-14.jpeg
upvoted 1 times
...
...
...
fjori
2 years, 5 months ago
Selected Answer: D
https://www.cisco.com/c/en/us/td/docs/wireless/controller/7-4/configuration/guides/consolidated/b_cg74_CONSOLIDATED/b_cg74_CONSOLIDATED_chapter_010111001.html Internal—If the unknown access point is inside the network and poses no threat to WLAN security, you would manually configure it as Friendly, Internal. An example is the access points in your lab network. External—If the unknown access point is outside the network and poses no threat to WLAN security, you would manually configure it as Friendly, External. An example is an access point that belongs to a neighboring coffee shop. Alert—The unknown access point is moved to Alert if it is not in the neighbor list or in the user-configured friendly MAC list.
upvoted 2 times
...
alejandro12
2 years, 5 months ago
Answer is D
upvoted 2 times
...
[Removed]
2 years, 6 months ago
Selected Answer: D
The Answer is D
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago