200-301 · Question #996
A WLC sends alarms about a rogue AP, and the network administrator verifies that the alarms are caused by a legitimate autonomous AP. How must the alarms be stopped for the MAC address of the AP?
The correct answer is D. Set the AP Class Type to Friendly.. To stop rogue AP alarms for a legitimate autonomous AP on a WLC, classify the AP as "Friendly" to prevent further alerts.
Question
Options
- ARemove the AP from WLC management
- BPlace the AP into manual containment.
- CManually remove the AP from Pending state.
- DSet the AP Class Type to Friendly.
How the community answered
(29 responses)- A17% (5)
- B3% (1)
- C10% (3)
- D69% (20)
Why each option
To stop rogue AP alarms for a legitimate autonomous AP on a WLC, classify the AP as "Friendly" to prevent further alerts.
Removing an AP from WLC management is not applicable here, as the WLC is not managing the autonomous AP, it's just detecting it as a rogue.
Placing an AP into manual containment is for actively neutralizing a malicious rogue AP by flooding deauthentication frames, which is the opposite of what's desired for a legitimate AP.
Autonomous APs are not typically in a "Pending" state on a WLC; this state is for new lightweight APs attempting to join the WLC.
On a Wireless LAN Controller (WLC), when an AP is identified as a rogue but is known to be legitimate and authorized (like an autonomous AP not managed by the WLC), its AP Class Type should be set to "Friendly"; this action prevents the WLC from raising alarms for that specific MAC address.
Concept tested: Cisco WLC rogue AP classification
Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/m_configuring_rogue_detection_and_containment.html
Topics
Community Discussion
No community discussion yet for this question.