exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 312 discussion

Actual exam question from Cisco's 200-301
Question #: 312
Topic #: 1
[All 200-301 Questions]


Refer to the exhibit. The network engineer is configuring a new WLAN and is told to use a setup password for authentication instead of the RADIUS servers.
Which additional set of tasks must the engineer perform to complete the configuration?

  • A. Disable PMF Enable PSK Enable 802.1x
  • B. Select WPA Policy Enable CCKM Enable PSK
  • C. Select WPA Policy Select WPA2 Policy Enable FT PSK
  • D. Select WPA2 Policy Disable PMF Enable PSK
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ciscoman021
Highly Voted 2 years ago
Selected Answer: D
The correct option for this scenario would be D. Select WPA2 Policy Disable PMF Enable PSK. When configuring a WLAN to use a setup password for authentication instead of RADIUS servers, the following tasks must be performed: Select WPA2 Policy: The engineer should select WPA2 (Wi-Fi Protected Access II) as the security policy for the WLAN. WPA2 is a widely used security protocol that provides strong encryption and authentication for wireless networks. Disable PMF: PMF (Protected Management Frames) is a security feature that helps protect against certain types of attacks on wireless networks. However, it may cause compatibility issues with some client devices. Therefore, it should be disabled when using a setup password for authentication. Enable PSK: PSK (Pre-Shared Key) is a form of authentication that uses a shared password or passphrase to authenticate clients on the wireless network. When using a setup password for authentication, the engineer should enable PSK and set the shared password or passphrase.
upvoted 24 times
...
oatmealturkey
Highly Voted 2 years, 2 months ago
Selected Answer: D
It is not B, you cannot select both CCKM and PSK. Cisco is trying to throw us off with disabling PMFs, but D is the best answer.
upvoted 6 times
studying_1
1 year, 11 months ago
but PMF is a security feature of WPA3, so i guess no need to keep it enabled, since we're using WPA2, n'est ce pas? je crois que oui, please, correct me if i'm wrong
upvoted 3 times
dropspablo
1 year, 9 months ago
studying_1 you are correct. See what the Official Cisco Guide says: "WPA3 includes other features that WPA and WPA2 do not have, such as SAE (Simultaneous Authentication of Equals), Forward Secrecy, and PMF (Protected Management Frames). (OCG Wendell Adom v1)". (The correct answer is D. "need to disable PMF") ***and from what I understand, when using the PMF, you would also need to enable the "PMF PSK", and not just the "PSK". I agree that this PMF (802.11w) config is meant to be misleading.***
upvoted 2 times
...
...
...
riteshm42
Most Recent 2 months, 1 week ago
Selected Answer: D
D. Select WPA2 Policy Disable PMF Enable PSK Here's why: Selecting the WPA2 Policy ensures that the WLAN uses WPA2 for secure authentication. Disabling PMF (Protected Management Frames) is necessary if you're not using RADIUS or other advanced security mechanisms. Enabling PSK (Pre-Shared Key) allows the use of a setup password for authentication instead of RADIUS servers.
upvoted 1 times
...
EmmaW
5 months ago
Better option would be - Enable WPA2 - Enable Pre-Shared Key - Enable FT PSK But as it's not an option, then we are choosing between the closest options B and D. Enable Cisco Centralized Key Management or Disable PMF? CCKM, Cisco Centralized Key Management - is another alternative to PSK, and there is nothing about PSK - https://community.cisco.com/t5/wireless-mobility-knowledge-base/what-is-cckm-and-how-does-it-affect-fast-and-secure-roaming/ta-p/3130421 So it means we disable PMF.
upvoted 1 times
...
xtraMiles
9 months ago
Selected Answer: D
Well, in Packet Tracer, CCKM is greyed out in both WPA Policy and WPA2 Policy option under WPA+WPA2 Parameter selection. All the other Layer 2 Security options says "This feature is not supported in Packet Tracer". Soooo... Also, in WPA2 Policy, PMF is greyed out as well and the setting is fixed at Disabled. I'm picking D since WPA2 is newer than WPA.
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: D
D is correct
upvoted 2 times
...
chegurus
1 year, 7 months ago
D is the correct answer. the "Configuring WLAN Security" section in the CCNA 200-301 official cert guide has the same example.
upvoted 1 times
...
OrwellMB
1 year, 9 months ago
Selected Answer: B
With WPA2 enabled, you NEED to select one of the encryption options. Therefore, B remains. Also: "when you configure your wireless LAN for CCKM fast secure roaming, EAP-enabled clients securely roam from one access point to another without the need to reauthenticate with the RADIUS server" So with CCKM (only with B option) you can bypass the RADIUS server entirely.
upvoted 2 times
Nian
5 months ago
With CCKM the initial authentication is through RADIUS w. 802.1X. B cannot be correct
upvoted 1 times
...
...
Dunedrifter
1 year, 10 months ago
Selected Answer: D
WPA2 should be used. It's more secure than WPA
upvoted 4 times
...
splashy
2 years, 3 months ago
Selected Answer: D
A.dot1x = no B.CCKM + PSK = no go (atleast not on the devices i've seen in netacad course + PT) C.Possible but ONLY FT capable clients will be able to connect, non-FT will not which is very far from ideal. D. While disabling PMF is sub-optimal, at least you will not be denying non FT-capable clients/devices to connect.
upvoted 5 times
...
[Removed]
2 years, 3 months ago
using a wpa/wpa2 mixed mode is a high security risk https://www.speedguide.net/faq/wpa2-vs-wpa2wpa-mixed-mode-security-436#:~:text=WPA2%2FWPA%20mixed%20mode%20allows,for%20use%20by%20the%20client. basically clients can use either wpa and wpa2 to connect, which is a big no no for security. i think it's either B or D. Again all options are correct but i think B is more correct because it provide the most security, CCKM works with PSK correct me if i am wrong.
upvoted 1 times
...
Request7108
2 years, 3 months ago
Selected Answer: C
This is a badly written question and answer set. I ran this on my 5520, code version 8.10.130 A) Obviously wrong because it is dot1x B) Wrong because CCKM is not an option when using PSK. For the code version I'm running, CCKM disappears as soon as I select personal versus enterprise. C) WPA and WPA2 is allowable but not ideal. It also needs to have the FT enabled checked and the FT PSK box checked. On my code version, this is automatically done when I set FT to enable. D) While not ideal to disable PMF, it is possible. Strictly speaking, this question comes down to whether or not Cisco is expecting both FT boxes to be checked or not. I hope they aren't being this neurotic so I'm choosing C, despite D being the most asinine yet accurate.
upvoted 2 times
...
Panda_man
2 years, 4 months ago
Selected Answer: B
A - Is not correct since they say RADIUS is not used and 802.1.x is to be used for authentication through RADIUS, TACACS; C- not correct you can not have WPA Policy and WPA2 policy at the same time; D-not correct,since it's not reccomandation to disable Pmf and especially if WPA2 is unable; Therefore B should be correct answer.
upvoted 5 times
Request7108
2 years, 3 months ago
Your evaluation of C is incorrect because it is possible to have WPA and WPA2 at the same time. It is not recommended, but it is possible.
upvoted 2 times
Drader
2 years, 1 month ago
Isn't it possible to have WPA2 and WPA at the same time for backwards compatibility?
upvoted 1 times
...
...
...
fjori
2 years, 4 months ago
A is not the choice as 802.1x is an authentication protocol to allow access to networks with the use of a RADIUS server. C is not correct as FT PSK is used only for static configuration only . D is not correct as we shoul not disable PMF for security. So the correct answer is B
upvoted 1 times
...
mijhn13
2 years, 6 months ago
are you sure etidic? im confused
upvoted 1 times
...
[Removed]
2 years, 6 months ago
Selected Answer: C
The answer is C
upvoted 1 times
chathu123
2 years, 6 months ago
can you explain it ?
upvoted 1 times
RougePotatoe
2 years, 5 months ago
He is wrong. "802.11r FT + PMF is not recommended." https://www.cisco.com/c/dam/en/us/td/docs/wireless/controller/technotes/80211r-ft/b-80211r-dg.html
upvoted 2 times
...
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago