View Full Cisco CCNP Wireless 350-101 Exam Dumps and Practice Test Dumps
Question 161: Which WPA3 security mode is designed for enterprise wireless networks using centralized authentication?
- Open Authentication
- WPA2-Personal
- WPA3-Enterprise
- WPA3-Personal
Correct Answer: 3. WPA3-Enterprise
Explanation:
WPA3-Enterprise is designed for enterprise environments that require centralized authentication and stronger security controls. It commonly works with 802.1X and an authentication server such as RADIUS, allowing individual users or devices to authenticate rather than sharing one common password. WPA3-Personal uses SAE for password-based authentication, while WPA2-Personal uses a pre-shared key. Open Authentication does not provide equivalent wireless security by itself. Therefore, WPA3-Enterprise is the appropriate security mode for enterprise WLANs using centralized authentication.
Question 162: Which EAP method provides certificate-based mutual authentication between a wireless client and the authentication server?
- EAP-MD5
- EAP-TLS
- PAP
- PEAP
Correct Answer: 2. EAP-TLS
Explanation:
EAP-TLS uses digital certificates to authenticate both the wireless client and the authentication server. This provides strong mutual authentication and avoids relying solely on a password for client authentication. PEAP typically establishes a TLS-protected tunnel and then uses an inner authentication method, while EAP-MD5 does not provide equivalent certificate-based mutual authentication. PAP is a basic credential exchange mechanism rather than a complete certificate-based EAP method. Therefore, EAP-TLS is the appropriate choice when both sides of an enterprise wireless authentication process must be validated using certificates.
Question 163: Which statement best describes PEAP in an enterprise wireless deployment?
- It is used only for WPA3-Personal
- It establishes a protected TLS tunnel for an inner authentication method
- It replaces CAPWAP
- It provides RF channel selection
Correct Answer: 2. It establishes a protected TLS tunnel for an inner authentication method
Explanation:
Protected Extensible Authentication Protocol (PEAP) establishes a TLS tunnel between the client and authentication server. An inner authentication method can then be used inside this protected tunnel, commonly involving username and password credentials. This protects the inner authentication exchange from direct exposure over the wireless network. PEAP is an enterprise authentication mechanism and is not responsible for RF channel selection or CAPWAP communication. WPA3-Personal instead uses SAE rather than PEAP. Therefore, establishing a protected TLS tunnel for an inner authentication method accurately describes PEAP.
Question 164: Which three IEEE 802.11 amendments are commonly associated with improving wireless client roaming?
- 802.11w, 802.11u, and 802.11h
- 802.11n, 802.11ac, and 802.11ax
- 802.11a, 802.11b, and 802.11g
- 802.11k, 802.11r, and 802.11v
Correct Answer: 4. 802.11k, 802.11r, and 802.11v
Explanation:
802.11k, 802.11r, and 802.11v provide complementary capabilities that can improve wireless roaming. 802.11k can provide neighbor and radio measurement information, helping clients identify potential roaming candidates. 802.11r provides Fast BSS Transition mechanisms that reduce transition-related delay. 802.11v can provide network-assisted BSS transition information and other management capabilities. These amendments address different portions of the roaming process and can work together in supported environments. Therefore, 802.11k, 802.11r, and 802.11v are the three amendments most directly associated with enhanced roaming behavior.
Question 165: Which feature is designed to protect supported wireless management frames from spoofing attacks?
- PMF
- TWT
- MU-MIMO
- OFDMA
Correct Answer: 1. PMF
Explanation:
Protected Management Frames (PMF), associated with IEEE 802.11w, provide protection for supported management frames. This helps defend against attacks that use forged management messages, including certain deauthentication and disassociation attacks. OFDMA improves channel efficiency by dividing channels into resource units, TWT coordinates client wake periods, and MU-MIMO enables simultaneous communication using multiple spatial streams. PMF is therefore the feature specifically associated with protecting management-frame traffic. In environments where supported, enabling appropriate PMF protection can strengthen wireless security against management-frame spoofing.
Question 166: In a FlexConnect deployment, which feature allows client traffic to be forwarded directly onto the local branch network?
- CAPWAP Discovery
- Local Switching
- Central Switching
- Mobility Anchoring
Correct Answer: 2. Local Switching
Explanation:
FlexConnect Local Switching allows an access point at a remote location to forward client traffic directly onto the local wired network. This avoids sending all client data across the WAN to a centralized controller and can reduce WAN bandwidth requirements. Central switching instead forwards client traffic through the controller, while Mobility Anchoring is commonly used for centralized guest traffic termination. CAPWAP Discovery is used by APs to locate controllers. Therefore, Local Switching is the FlexConnect capability that provides direct local forwarding of client traffic.
Question 167: Which Cisco redundancy feature allows a standby wireless LAN controller to take over when the active controller fails?
- CleanAir
- AVC
- SSO
- RRM
Correct Answer: 3. SSO
Explanation:
Stateful Switchover (SSO) provides controller redundancy by maintaining synchronized state between an active controller and a standby controller in supported deployments. If the active controller fails, the standby unit can assume the active role, helping reduce service interruption. RRM manages radio resources, AVC provides application visibility and control, and CleanAir provides RF interference intelligence. SSO is therefore the Cisco redundancy mechanism most directly associated with maintaining synchronized controller state and providing rapid failover between redundant controllers.
Question 168: Which CAPWAP discovery method allows an AP to locate a controller using a configured DNS name?
- SNMP discovery
- WMM discovery
- DNS discovery
- RADIUS discovery
Correct Answer: 3. DNS discovery
Explanation:
Cisco access points can use DNS discovery to locate a wireless LAN controller. The AP resolves an appropriate controller hostname through DNS and can then attempt to establish CAPWAP communication with the discovered controller. Other discovery mechanisms can also be available depending on the deployment, including information obtained through DHCP or previously learned controller addresses. RADIUS, WMM, and SNMP are not the mechanisms used for this DNS-based controller discovery process. Therefore, DNS discovery is the appropriate method when an AP locates a controller by resolving a configured hostname.
Question 169: What is the primary purpose of a mobility tunnel between Cisco wireless controllers?
- To replace the RADIUS server
- To provide DNS resolution
- To transport RF interference measurements only
- To exchange and transport mobility-related client information and traffic
Correct Answer: 4. To exchange and transport mobility-related client information and traffic
Explanation:
Cisco wireless controllers use mobility tunnels to support client mobility between controllers. These tunnels can carry information and, depending on the roaming scenario, client traffic required to maintain connectivity as a client moves between controllers. Mobility tunnels are therefore an important component of inter-controller roaming architectures. DNS provides name resolution, RADIUS provides AAA services, and RF monitoring uses separate mechanisms. The mobility tunnel should not be confused with the CAPWAP relationship between an AP and its controller. Its primary purpose is supporting controller-to-controller mobility operations.
Question 170: Which Cisco wireless architecture is commonly used to centralize guest traffic at a designated controller?
- Rogue Detector mode
- Mobility Anchor
- Monitor mode
- Sniffer mode
Correct Answer: 2. Mobility Anchor
Explanation:
A Mobility Anchor can provide a centralized termination point for guest WLAN traffic. Controllers at remote locations can establish mobility tunnels toward the designated anchor, allowing guest traffic to be forwarded to a centralized guest network. This design can help maintain consistent guest access policies and traffic isolation across multiple locations. Monitor mode and Rogue Detector mode serve wireless monitoring functions, while Sniffer mode is used for packet capture and analysis. Therefore, Mobility Anchor architecture is commonly used when centralized guest traffic termination is required.
Question 171: Which Cisco feature allows Bonjour service advertisements to be shared across Layer 3 boundaries?
- Client Exclusion
- RRM
- Bonjour Gateway
- RF Profile
Correct Answer: 3. Bonjour Gateway
Explanation:
Bonjour uses multicast DNS to discover services such as printers and other network-enabled devices. Standard multicast DNS discovery is generally limited by Layer 3 boundaries. Cisco Bonjour Gateway functionality can learn supported service advertisements and make them available across configured network boundaries according to policy. RF Profiles control radio parameters, RRM manages RF resources, and Client Exclusion restricts problematic wireless clients. Therefore, Bonjour Gateway is the feature most directly associated with extending Bonjour service discovery between different Layer 3 network segments.
Question 172: Which WMM access category provides the highest priority for delay-sensitive voice traffic?
- AC_VI
- AC_BE
- AC_VO
- AC_BK
Correct Answer: 3. AC_VO
Explanation:
Wi-Fi Multimedia (WMM) defines four access categories: AC_VO for voice, AC_VI for video, AC_BE for best effort, and AC_BK for background traffic. AC_VO receives the highest priority because voice applications are particularly sensitive to delay, jitter, and packet loss. AC_VI is intended for video traffic, while best-effort and background traffic receive lower priority. Proper WMM configuration helps the wireless network provide preferential access to delay-sensitive applications. Therefore, AC_VO is the WMM category associated with the highest priority for voice traffic.
Question 173: Which RF metric is most useful for identifying whether a wireless signal is strong relative to the noise floor?
- Channel number
- EIRP
- RSSI
- SNR
Correct Answer: 4. SNR
Explanation:
Signal-to-Noise Ratio (SNR) compares the desired received signal level with the surrounding RF noise level. A higher SNR generally indicates that the receiver can distinguish the desired signal more effectively from background noise. RSSI provides information about received signal strength but does not directly describe the noise environment. EIRP represents effective radiated transmit power, while the channel number simply identifies the RF channel being used. Therefore, SNR is the most useful metric for evaluating the strength of a received signal relative to the noise floor.
Question 174: What is the purpose of EIRP in wireless RF planning?
- To determine the effective radiated transmit power
- To identify the client’s authentication method
- To identify the RADIUS server
- To measure the number of connected clients
Correct Answer: 1. To determine the effective radiated transmit power
Explanation:
Effective Isotropic Radiated Power (EIRP) represents the effective power radiated by an antenna system and takes transmitter output and antenna gain into account, along with applicable losses. EIRP is important in wireless design because regulatory limits and coverage characteristics can depend on the effective radiated power. It is not a measurement of client authentication, client count, or RADIUS configuration. Antenna selection and transmit power therefore need to be considered together when planning RF coverage. EIRP is consequently an important concept for evaluating effective wireless transmit power.
Question 175: Which antenna characteristic determines how RF energy is distributed across a physical area?
- SSID length
- Antenna radiation pattern
- DHCP lease
- RADIUS timeout
Correct Answer: 2. Antenna radiation pattern
Explanation:
An antenna radiation pattern describes how RF energy is distributed in different directions around the antenna. This characteristic is important when designing wireless coverage because omnidirectional and directional antennas produce different coverage patterns. Antenna gain, mounting position, polarization, and the physical environment also affect the resulting RF coverage. RADIUS timeouts, DHCP leases, and SSID length do not determine the physical distribution of RF energy. Therefore, the antenna radiation pattern is the characteristic that most directly describes how RF energy is distributed across an area.
Question 176: Which Cisco wireless technology helps identify, classify, and provide visibility into sources of RF interference?
- 802.1X
- CleanAir
- DHCP Proxy
- RADIUS
Correct Answer: 2. CleanAir
Explanation:
Cisco CleanAir provides RF intelligence that can detect and classify sources of interference, including non-Wi-Fi devices that may affect wireless performance. By providing information about interference sources and their impact, CleanAir can assist administrators in troubleshooting RF problems and making informed wireless design decisions. RADIUS provides AAA services, DHCP Proxy handles DHCP communication, and 802.1X provides network access authentication. Therefore, CleanAir is the Cisco technology most directly associated with identifying and classifying RF interference.
Question 177: Which Wi-Fi 6 feature allows supported clients to coordinate scheduled periods of activity and sleep?
- OFDMA
- PMF
- BSS Coloring
- TWT
Correct Answer: 4. TWT
Explanation:
Target Wake Time (TWT) is an IEEE 802.11ax feature that allows supported clients and access points to coordinate scheduled communication periods. A client can remain inactive outside its scheduled wake period, potentially reducing radio activity and conserving battery power. OFDMA divides channels into resource units for more efficient client scheduling, BSS Coloring improves spatial reuse, and PMF protects supported management frames. Therefore, TWT is the feature most directly associated with scheduled client activity and power-saving behavior.
Question 178: Which Wi-Fi 6 feature helps distinguish transmissions from overlapping BSSs to improve spatial reuse?
- 802.11r
- TWT
- BSS Coloring
- EAP-TLS
Correct Answer: 3. BSS Coloring
Explanation:
BSS Coloring is an IEEE 802.11ax mechanism that assigns identifying information to wireless BSS transmissions. This can help devices distinguish transmissions originating from their own BSS from those belonging to overlapping BSSs. Under appropriate conditions, this information can support more efficient spatial reuse and reduce unnecessary deferral to transmissions from neighboring networks. TWT focuses on scheduled wake periods, EAP-TLS is an authentication method, and 802.11r improves roaming. Therefore, BSS Coloring is the feature directly associated with improving spatial reuse in overlapping Wi-Fi 6 environments.
Question 179: Which wireless condition can cause poor throughput even when a client reports strong RSSI?
- High channel utilization or RF interference
- Excellent channel separation
- Low noise and little contention
- High SNR and low utilization
Correct Answer: 1. High channel utilization or RF interference
Explanation:
Strong RSSI only indicates that the desired signal is being received at a relatively high level. It does not guarantee that the wireless medium is free of contention or interference. High channel utilization means that substantial airtime is already occupied, while RF interference can cause retransmissions and reduce effective throughput. A client can therefore experience poor performance even when its received signal appears strong. Troubleshooting should consider RSSI together with SNR, channel utilization, noise, retransmissions, and client data rates. High utilization or interference can explain poor throughput despite strong RSSI.
Question 180: Which Cisco wireless capability can provide centralized analytics about client health and wireless infrastructure performance?
- RADIUS Accounting
- Wireless Assurance
- DHCP Proxy
- CAPWAP Data Channel
Correct Answer: 2. Wireless Assurance
Explanation:
Wireless Assurance provides centralized visibility and analytics for wireless infrastructure and client performance. It can use collected telemetry and operational information to help administrators investigate connectivity, client health, RF conditions, and performance issues. DHCP Proxy assists with DHCP communication, the CAPWAP data channel carries client traffic in centralized deployments, and RADIUS Accounting records AAA-related activity. Wireless Assurance is therefore the capability most directly associated with centralized wireless analytics and operational visibility across the environment.