View Full Cisco CCNP Wireless 350-101 Exam Dumps and Practice Test Dumps
Question 41: Which 802.11 management frame is used by a client to request association with an access point after discovering the WLAN?
- Association Request
- Probe Response
- Beacon
- ACK
Correct Answer: 1. Association Request
Explanation:
After discovering a suitable WLAN and completing the required authentication exchange, a wireless client sends an Association Request to the access point. The request allows the AP to establish the client’s association and includes information about the client’s capabilities and requested parameters. The AP responds with an Association Response indicating whether the request is accepted or rejected. Probe Response frames are used during active network discovery, beacon frames advertise WLAN information periodically, and ACK frames acknowledge successful frame reception. Therefore, the Association Request is the management frame used when a client requests to join a particular WLAN.
Question 42: Which 802.11 frame does an access point transmit in response to a client’s Probe Request?
- Authentication Response
- Probe Response
- Association Response
- CTS
Correct Answer: 2. Probe Response
Explanation:
When a wireless client actively scans for available WLANs by transmitting a Probe Request, an access point can respond with a Probe Response. The response contains information about the WLAN, including capabilities, supported rates, security information, and other parameters that help the client evaluate whether the network is suitable. An Association Response is sent after the client submits an Association Request, while CTS is part of the RTS/CTS medium-access mechanism. Therefore, Probe Response is the frame specifically associated with answering a client’s active WLAN discovery request.
Question 43: Which 802.11 authentication method is considered open because it does not itself provide cryptographic authentication of the client?
- WPA3-Enterprise
- 802.1X
- Open System authentication
- EAP-TLS
Correct Answer: 3. Open System authentication
Explanation:
Open System authentication is the basic 802.11 authentication method in which the authentication exchange itself does not provide strong cryptographic authentication of the wireless client. In modern enterprise WLANs, stronger security is normally provided through mechanisms such as WPA2-Enterprise or WPA3-Enterprise combined with 802.1X and an appropriate EAP method. EAP-TLS provides certificate-based authentication, while 802.1X provides the framework for controlled network access. WPA3-Enterprise provides a modern enterprise security architecture. Open System authentication therefore describes the basic authentication method that does not itself provide strong client authentication.
Question 44: Which EAP method uses digital certificates on both the client and authentication server for mutual authentication?
- EAP-MD5
- PEAP
- EAP-TLS
- EAP-LEAP
Correct Answer: 3. EAP-TLS
Explanation:
EAP-TLS uses Transport Layer Security and digital certificates to provide strong mutual authentication between the wireless client and authentication server. In a typical deployment, the client presents a certificate to the authentication server and the server also proves its identity through a trusted certificate. This provides strong protection against credential interception and rogue authentication infrastructure when properly implemented. EAP-MD5 does not provide equivalent mutual certificate-based authentication, while PEAP normally establishes a protected tunnel before authenticating the client. EAP-LEAP is an older Cisco-proprietary method with known security limitations. EAP-TLS is therefore the certificate-based mutual-authentication method.
Question 45: Which wireless security technology provides protection against offline dictionary attacks by using Simultaneous Authentication of Equals?
- WPA3-Personal
- WPA2-Personal
- WEP
- Open authentication
Correct Answer: 1. WPA3-Personal
Explanation:
WPA3-Personal uses Simultaneous Authentication of Equals, or SAE, to provide stronger protection for password-based wireless authentication. SAE is designed to make offline password-guessing attacks significantly more difficult than the pre-shared-key authentication approach used by WPA2-Personal. WPA2-Personal uses a PSK-based mechanism, while WEP uses obsolete and insecure encryption techniques. Open authentication does not provide equivalent wireless security. WPA3-Personal therefore represents the security technology associated with SAE and stronger resistance to offline password-guessing attacks.
Question 46: What is the primary purpose of a wireless LAN controller’s WLAN profile?
- To define WLAN characteristics such as SSID and security settings
- To assign physical switch ports to users
- To replace the RF antenna
- To provide DNS services
Correct Answer: 1. To define WLAN characteristics such as SSID and security settings
Explanation:
A WLAN profile on a Cisco wireless LAN controller defines important characteristics of a wireless network, including its WLAN identifier, SSID, security configuration, authentication behavior, and other operational parameters. The controller can apply the WLAN configuration to the access points that provide the service. Physical switch-port assignments are handled by the wired network infrastructure, antennas are physical RF components, and DNS is a separate network service. WLAN profiles therefore provide a centralized configuration framework for defining how a particular wireless network should operate.
Question 47: Which wireless controller configuration determines how client traffic is mapped to a wired VLAN?
- RF Profile
- WLAN-to-interface mapping
- AP Join Profile
- Country code
Correct Answer: 2. WLAN-to-interface mapping
Explanation:
A wireless LAN must be associated with an appropriate controller interface or VLAN mapping so that client traffic can reach the correct wired network. The WLAN-to-interface association determines which controller interface and corresponding VLAN are used for traffic from that WLAN. RF Profiles define radio parameters, AP Join Profiles contain AP-controller communication settings, and the country code establishes regulatory and RF capabilities. Correct VLAN mapping is particularly important when separating guest, corporate, voice, or IoT traffic into different Layer 2 networks. Therefore, WLAN-to-interface mapping is the configuration directly associated with assigning WLAN traffic to a wired VLAN.
Question 48: Which Cisco wireless feature can dynamically change an access point’s transmit power to maintain appropriate RF coverage?
- RRM
- DHCP
- AAA
- NAT
Correct Answer: 1. RRM
Explanation:
Cisco Radio Resource Management, or RRM, can dynamically adjust radio parameters such as transmit power and channel selection based on measurements collected from the wireless environment. Dynamic transmit-power management helps maintain suitable RF coverage and can reduce excessive overlap or interference between neighboring access points. DHCP assigns IP configuration, AAA provides authentication and authorization services, and NAT translates IP addresses. RRM therefore provides the automated RF optimization capabilities needed to dynamically adapt AP radio parameters as the environment changes.
Question 49: Which RF problem occurs when a client receives a strong signal but the surrounding RF noise is also high?
- High SNR
- Low SNR
- High EIRP only
- Low channel width
Correct Answer: 2. Low SNR
Explanation:
Signal-to-Noise Ratio, or SNR, represents the difference between the desired wireless signal and the surrounding noise. A client can have a relatively strong received signal while still experiencing poor wireless performance if the noise level is also high. In that situation, the resulting SNR is low, which can lead to lower modulation rates, retransmissions, and unreliable communication. High SNR indicates a cleaner RF environment. EIRP describes transmitted radiated power, while channel width describes spectrum allocation. Therefore, strong signal combined with significant noise is characterized by low SNR.
Question 50: Which Cisco wireless feature is designed to detect unauthorized access points connected to the wired network?
- Rogue AP detection
- NAT
- DHCP snooping
- NTP
Correct Answer: 1. Rogue AP detection
Explanation:
Rogue access-point detection is used to identify unauthorized wireless devices that may be connected to the organization’s wired infrastructure or otherwise operating within the RF environment. Cisco wireless infrastructure can gather information about neighboring APs and use wired and wireless observations to classify devices according to configured policies. Detecting rogue APs is important because unauthorized wireless devices can create security risks, bypass network controls, or provide an unintended path into the network. NAT, DHCP snooping, and NTP perform unrelated network functions. Rogue AP detection is therefore the appropriate wireless security capability for this requirement.
Question 51: Which type of wireless attack involves sending forged deauthentication frames to disconnect legitimate clients from an access point?
- Evil twin
- Deauthentication attack
- VLAN hopping
- MAC flooding
Correct Answer: 2. Deauthentication attack
Explanation:
A deauthentication attack involves transmitting forged 802.11 deauthentication frames in an attempt to force legitimate wireless clients to disconnect from their access points. Attackers may use this technique to disrupt WLAN availability or create conditions that support other attacks. An evil-twin attack instead involves impersonating a legitimate WLAN, while VLAN hopping targets Layer 2 VLAN segmentation and MAC flooding targets switch MAC-table behavior. Wireless intrusion detection and prevention mechanisms can help identify suspicious management-frame activity. The attack described is therefore specifically a deauthentication attack.
Question 52: Which wireless security threat involves an attacker creating a fake access point that imitates a legitimate WLAN?
- Evil twin
- RF jamming
- ARP spoofing
- DHCP exhaustion
Correct Answer: 1. Evil twin
Explanation:
An evil-twin attack occurs when an attacker creates a rogue access point that imitates a legitimate WLAN, often using the same or a deceptively similar SSID. Unsuspecting clients may connect to the fraudulent AP, allowing the attacker to attempt credential theft, traffic interception, or other malicious activity. RF jamming attempts to disrupt wireless communications through interference, ARP spoofing targets local network address resolution, and DHCP exhaustion attempts to consume available DHCP addresses. Wireless security monitoring and appropriate authentication practices can help reduce the risk associated with rogue or impersonating access points. The described threat is an evil-twin attack.
Question 53: Which 802.11 feature improves efficiency by combining multiple MAC protocol data units into a single transmission opportunity?
- Frame aggregation
- DFS
- Open authentication
- RTS/CTS
Correct Answer: 1. Frame aggregation
Explanation:
Frame aggregation improves wireless efficiency by combining multiple frames into a larger transmission structure, reducing the overhead associated with transmitting each frame individually. Modern 802.11 standards use aggregation techniques such as A-MPDU and A-MSDU to improve throughput and reduce per-frame protocol overhead. DFS addresses radar detection, open authentication concerns WLAN authentication, and RTS/CTS is used to manage access to the shared medium in certain scenarios. Frame aggregation is therefore the feature directly associated with combining multiple data units to improve transmission efficiency.
Question 54: Which 802.11 feature allows an access point to use a wider RF channel by combining adjacent 20-MHz channels?
- Channel bonding
- Roaming
- Beamforming
- Power Save
Correct Answer: 1. Channel bonding
Explanation:
Channel bonding combines adjacent 20-MHz channels to create a wider wireless channel, such as a 40-MHz channel in technologies that support it. Wider channels can provide greater theoretical throughput because more spectrum is available for a single transmission. However, using wider channels also consumes more spectrum and can reduce the number of independently reusable channels, so the design must consider client density and interference. Roaming relates to client mobility, beamforming improves spatial transmission characteristics, and Power Save reduces client energy consumption. Channel bonding is therefore the feature directly associated with increasing channel width.
Question 55: What is the primary purpose of beamforming in modern Wi-Fi systems?
- To focus transmitted RF energy toward a client
- To assign IP addresses
- To authenticate users through RADIUS
- To prevent VLAN loops
Correct Answer: 1. To focus transmitted RF energy toward a client
Explanation:
Beamforming uses information about the wireless channel to improve how RF energy is directed toward a receiving client. By concentrating transmission energy spatially, beamforming can improve signal quality and potentially increase data rates or reliability under suitable RF conditions. The exact implementation depends on the wireless standard and equipment capabilities. Beamforming does not provide IP addressing, RADIUS authentication, or VLAN loop prevention. DHCP provides IP addressing, 802.1X and RADIUS support authentication, and STP handles Layer 2 loop prevention. Therefore, focusing RF transmission toward the client is the primary purpose of beamforming.
Question 56: Which Cisco wireless profile is primarily used to define radio-specific parameters such as channel width and transmit power settings?
- RF Profile
- WLAN Profile
- AP Group
- AAA Profile
Correct Answer: 1. RF Profile
Explanation:
An RF Profile is used to define radio-related configuration parameters for access points, such as channel width, transmit power ranges, data rates, and other RF behavior supported by the controller platform. RF Profiles allow administrators to apply consistent radio policies to groups of access points serving different environments, such as high-density areas or remote branches. WLAN Profiles define wireless network and security characteristics, AP Groups organize WLAN-to-AP relationships, and AAA Profiles relate to authentication and authorization settings. Therefore, an RF Profile is the configuration object most directly associated with radio-specific parameters.
Question 57: Which wireless deployment is most appropriate when a branch office needs local client traffic switching but centralized controller management?
- Monitor mode
- FlexConnect
- Sniffer mode
- Autonomous bridge only
Correct Answer: 2. FlexConnect
Explanation:
FlexConnect is designed for distributed deployments such as branch offices where access points can remain centrally managed while switching client traffic locally. Local switching can reduce WAN bandwidth consumption and avoid sending all user traffic to a centralized controller location. The access point can maintain communication with the controller for management and control functions while providing local data forwarding according to the configured design. Monitor and sniffer modes are intended for wireless monitoring rather than normal client service. Therefore, FlexConnect is the deployment model that best matches centralized management combined with local branch traffic switching.
Question 58: Which protocol is commonly used to synchronize clocks across Cisco wireless infrastructure and network devices?
- NTP
- FTP
- ARP
- STP
Correct Answer: 1. NTP
Explanation:
Network Time Protocol, or NTP, is used to synchronize clocks between network devices and time sources. Accurate time is important for logging, troubleshooting, certificate validation, authentication systems, and correlation of events across distributed wireless infrastructure. FTP is a file-transfer protocol, ARP resolves IPv4 addresses to MAC addresses on local networks, and STP prevents Layer 2 switching loops. NTP therefore provides the time-synchronization function required to keep device clocks aligned. Consistent timestamps are particularly useful when investigating wireless authentication failures, roaming events, and security incidents.
Question 59: Which Cisco wireless feature can group multiple WLANs and selectively advertise them through specific access points?
- AP Group
- RF Group
- RRM
- Mobility Group
Correct Answer: 1. AP Group
Explanation:
An AP Group allows administrators to control which WLANs are advertised by specific groups of access points. This can be useful in environments where different AP locations need to provide different sets of wireless services. For example, a particular group of APs can advertise selected corporate, guest, or specialized WLANs while other APs advertise a different combination. RF Groups are associated with RF management, RRM manages radio resources, and Mobility Groups support controller mobility relationships. AP Groups are therefore the configuration mechanism directly associated with selectively mapping WLANs to groups of access points.
Question 60: Which wireless metric is most directly associated with the amount of time the RF medium is busy?
- Channel utilization
- RSSI
- EIRP
- BSSID
Correct Answer: 1. Channel utilization
Explanation:
Channel utilization represents how much of the available airtime on an RF channel is being occupied or detected as busy. High channel utilization can indicate heavy client traffic, interference, or excessive contention and may contribute to reduced WLAN performance. RSSI measures received signal strength, EIRP describes effective radiated transmit power, and BSSID identifies a specific Basic Service Set. Channel utilization is therefore the metric most directly associated with how busy an RF channel is. Monitoring this metric is useful when diagnosing capacity problems, excessive contention, and RF conditions that may affect wireless performance.