Cisco CCNP Wireless 350-101 Practice Test Questions and Exam Dumps Part 14 Q261-280

View Full Cisco CCNP Wireless 350-101 Exam Dumps and Practice Test Dumps

 

Question 261: Which Cisco wireless AP mode allows an AP to provide client access while performing local switching through a FlexConnect WLAN?

  1. Monitor mode
  2. FlexConnect mode
  3. Sniffer mode
  4. Rogue Detector mode

Correct Answer: 2. FlexConnect mode

Explanation:

FlexConnect mode is designed for distributed wireless deployments in which access points remain managed by a centralized controller while supporting local services at remote sites. When a WLAN is configured for Local Switching, client traffic can be forwarded directly onto the local wired network instead of being centrally switched through the controller. This architecture is particularly useful for branch offices connected over WAN links. Monitor and Sniffer modes are specialized monitoring modes, while Rogue Detector mode focuses on rogue-device detection. Therefore, FlexConnect mode is the appropriate AP mode for locally switched client access at remote sites.

Question 262: Which component on a Cisco wireless LAN controller is used primarily for out-of-band management access on supported platforms?

  1. Dynamic interface
  2. WLAN interface
  3. Service port
  4. RF interface

Correct Answer: 3. Service port

Explanation:

The service port on supported Cisco wireless LAN controllers provides a dedicated interface for out-of-band management and certain recovery or maintenance functions. It is separate from the normal data-path interfaces used for WLAN client traffic. A dynamic interface is commonly associated with a VLAN and WLAN client connectivity, while a WLAN represents the wireless network configuration rather than a physical controller interface. RF interfaces are associated with wireless radio operations rather than controller management. Therefore, the service port is the interface most directly associated with dedicated out-of-band management access.

Question 263: Which protocol is commonly used by Cisco wireless controllers to communicate with a RADIUS authentication server?

  1. RADIUS
  2. CAPWAP
  3. LWAPP
  4. SNMP

Correct Answer: 1. RADIUS

Explanation:

RADIUS is the standard AAA protocol commonly used between Cisco wireless infrastructure and an authentication server in enterprise WLAN deployments. It can provide authentication, authorization, and accounting functions. CAPWAP is used for communication between lightweight access points and wireless LAN controllers, while SNMP is primarily used for network management and monitoring. LWAPP is an older Cisco AP-to-controller protocol that preceded CAPWAP. Therefore, RADIUS is the appropriate protocol when a Cisco wireless controller communicates with a centralized authentication server for enterprise wireless access.

Question 264: Which IEEE 802.11 amendment is associated with protecting management frames from unauthorized modification or spoofing?

  1. 802.11k
  2. 802.11r
  3. 802.11v
  4. 802.11w

Correct Answer: 4. 802.11w

Explanation:

IEEE 802.11w introduced Protected Management Frames (PMF), which provide protection for supported management frames. This helps reduce the effectiveness of attacks that rely on forged management messages, such as certain deauthentication and disassociation attacks. IEEE 802.11k provides radio measurement capabilities, 802.11r improves fast roaming, and 802.11v provides network-assisted management capabilities including BSS Transition Management. Therefore, 802.11w is the amendment directly associated with protecting supported wireless management frames.

Question 265: Which RF metric is commonly used to determine whether a client has sufficient signal quality for reliable wireless communication?

  1. VLAN ID
  2. SNR
  3. DHCP scope
  4. BSSID

Correct Answer: 2. SNR

Explanation:

Signal-to-Noise Ratio (SNR) compares the strength of the desired wireless signal with the surrounding noise level. It is an important indicator of signal quality because a strong RSSI alone does not guarantee reliable communication if the noise floor is also high. A healthy SNR generally provides the receiver with better conditions for decoding wireless transmissions. VLAN IDs identify logical networks, DHCP scopes provide IP addressing information, and BSSID identifies a wireless BSS. Therefore, SNR is an important RF metric when evaluating whether a client has adequate signal quality.

Question 266: Which Cisco wireless feature allows different WLANs to be assigned to specific groups of APs?

  1. AP Group
  2. RF Group
  3. Mobility Group
  4. RRM

Correct Answer: 1. AP Group

Explanation:

AP Groups allow administrators to associate selected WLANs with specific groups of access points. This is useful when different areas of an organization need different WLANs, such as separate wireless services for employees, guests, or specialized departments. RF Groups are used for RF management relationships, Mobility Groups support controller mobility, and RRM manages radio resources. By assigning WLANs through AP Groups, administrators can control which wireless networks are advertised by particular APs. Therefore, AP Group is the appropriate feature for assigning different WLAN configurations to selected AP groups.

Question 267: Which authentication method provides mutual certificate-based authentication between a wireless client and a RADIUS server?

  1. PEAP
  2. EAP-MD5
  3. EAP-TLS
  4. PAP

Correct Answer: 3. EAP-TLS

Explanation:

EAP-TLS uses digital certificates to provide strong mutual authentication between the wireless client and authentication server. Both sides can present certificates, allowing each party to verify the identity of the other. PEAP typically protects an inner authentication method within a TLS tunnel, while EAP-MD5 and PAP do not provide the same certificate-based mutual authentication capabilities. EAP-TLS is therefore commonly selected when an organization requires strong certificate-based authentication for enterprise wireless access. Proper certificate deployment and trust configuration are essential for successful EAP-TLS operation.

Question 268: What is the primary function of a WLAN profile on a Cisco wireless LAN controller?

  1. To define the physical antenna pattern
  2. To configure the wireless network’s operational and security settings
  3. To measure RF noise
  4. To identify rogue wired switches

Correct Answer: 2. To configure the wireless network’s operational and security settings

Explanation:

A WLAN profile defines the configuration associated with a wireless LAN. Depending on the controller platform and configuration, this can include the WLAN identifier, SSID, security settings, authentication methods, QoS policies, and other operational parameters. Antenna radiation patterns are physical RF characteristics, RF noise is measured through wireless monitoring mechanisms, and rogue wired switches are not configured through WLAN profiles. Therefore, the WLAN profile is the configuration object used to define how a particular wireless network operates and how clients are authenticated and serviced.

Question 269: Which feature allows an administrator to assign a wireless client’s traffic to a VLAN based on information returned by a RADIUS server?

  1. Dynamic VLAN assignment
  2. CAPWAP Discovery
  3. CleanAir
  4. TWT

Correct Answer: 1. Dynamic VLAN assignment

Explanation:

Dynamic VLAN assignment allows an authentication server such as RADIUS to return authorization attributes that identify the VLAN to which an authenticated client should be assigned. This can provide user- or policy-based network segmentation without requiring every user to connect to a different SSID. CAPWAP Discovery assists with AP controller discovery, CleanAir provides RF intelligence, and TWT coordinates scheduled client activity. Dynamic VLAN assignment is therefore the feature that allows the wireless infrastructure to place clients into different VLANs according to authentication-server policy.

Question 270: Which Cisco wireless feature is most useful for identifying non-Wi-Fi sources of RF interference?

  1. WMM
  2. RADIUS Accounting
  3. CleanAir
  4. DHCP Proxy

Correct Answer: 3. CleanAir

Explanation:

Cisco CleanAir provides spectrum intelligence that can identify and classify sources of RF interference, including devices that do not use Wi-Fi protocols. Examples can include certain Bluetooth devices, microwave ovens, wireless video equipment, and other RF emitters depending on the environment. WMM manages wireless traffic prioritization, RADIUS Accounting records AAA session information, and DHCP Proxy assists with DHCP communication. CleanAir is therefore the Cisco technology most directly associated with detecting and classifying non-Wi-Fi RF interference.

Question 271: Which Wi-Fi 6 feature allows an AP to schedule transmissions to multiple clients using smaller portions of the available channel?

  1. PMF
  2. OFDMA
  3. TWT
  4. 802.11r

Correct Answer: 2. OFDMA

Explanation:

Orthogonal Frequency-Division Multiple Access (OFDMA) divides a wireless channel into smaller resource units that can be allocated to different clients. This allows an access point to schedule multiple clients efficiently and can improve airtime utilization, especially in environments with many clients sending smaller amounts of data. TWT focuses on scheduled wake periods, PMF protects supported management frames, and 802.11r improves roaming. Therefore, OFDMA is the Wi-Fi 6 feature most directly associated with dividing a channel into smaller resource units for client scheduling.

Question 272: Which wireless design factor is particularly important for voice-over-Wi-Fi deployments?

  1. Consistent RF coverage and sufficient SNR throughout the roaming area
  2. Maximum possible channel width everywhere
  3. Disabling QoS
  4. Using maximum transmit power on every AP

Correct Answer: 1. Consistent RF coverage and sufficient SNR throughout the roaming area

Explanation:

Voice-over-Wi-Fi applications are sensitive to delay, jitter, packet loss, and roaming interruptions. Consistent RF coverage and sufficient SNR help maintain reliable connectivity as a voice client moves between access points. Voice deployments also require appropriate channel planning, QoS, capacity, and properly designed cell boundaries. Maximum transmit power can create oversized cells and increase contention, while excessive channel width may reduce channel reuse. Disabling QoS would also undermine traffic prioritization. Therefore, consistent RF coverage and adequate SNR throughout the intended roaming area are important elements of voice WLAN design.

Question 273: Which WMM access category provides the highest priority for delay-sensitive voice traffic?

  1. AC_BE
  2. AC_BK
  3. AC_VI
  4. AC_VO

Correct Answer: 4. AC_VO

Explanation:

WMM defines four access categories: AC_VO for voice, AC_VI for video, AC_BE for best effort, and AC_BK for background traffic. AC_VO is designed to provide the highest priority because voice applications are sensitive to delay and jitter. It uses more favorable contention parameters than the lower-priority categories. AC_VI is intended for video, while AC_BE and AC_BK are intended for best-effort and background traffic. Therefore, AC_VO is the WMM access category used to provide the highest priority to delay-sensitive voice traffic.

Question 274: Which condition can cause a wireless client to experience poor throughput even when its RSSI is strong?

  1. Low channel utilization and low noise
  2. High channel utilization or interference
  3. Excellent SNR
  4. Minimal contention

Correct Answer: 2. High channel utilization or interference

Explanation:

RSSI measures received signal strength but does not describe how much competing traffic or interference is present on the channel. A client can therefore have strong RSSI while experiencing poor throughput if the wireless medium is heavily occupied or affected by interference. High channel utilization can reduce available airtime, while interference can increase retransmissions and reduce effective data rates. SNR, noise level, retransmission rates, and channel utilization should all be considered during troubleshooting. Therefore, high channel utilization or RF interference can explain poor throughput despite a strong received signal.

Question 275: Which Cisco wireless feature can provide a centralized termination point for guest WLAN traffic?

  1. Mobility Anchor
  2. Monitor mode
  3. Sniffer mode
  4. AP Group

Correct Answer: 1. Mobility Anchor

Explanation:

A Mobility Anchor can serve as a centralized termination point for guest WLAN traffic. Foreign controllers can establish mobility tunnels toward the anchor, allowing guest traffic to be forwarded to a centralized network location. This architecture can help maintain consistent guest policies and isolate guest traffic from internal network resources. Monitor mode is used for wireless monitoring, Sniffer mode captures wireless traffic, and AP Groups control WLAN associations with access points. Therefore, Mobility Anchor architecture is the feature most directly associated with centralized guest traffic termination.

Question 276: Which protocol is used to securely protect CAPWAP control communication between a lightweight AP and controller?

  1. TLS
  2. DTLS
  3. FTP
  4. SSH

Correct Answer: 2. DTLS

Explanation:

CAPWAP uses Datagram Transport Layer Security (DTLS) to protect the control channel between a lightweight access point and its controller. DTLS provides security for datagram-based communication and helps protect CAPWAP control traffic against interception and modification. TLS is commonly associated with stream-oriented protocols such as TCP-based applications, while FTP and SSH serve different application purposes. Therefore, DTLS is the protocol associated with securing CAPWAP control communication between Cisco lightweight APs and their controllers.

Question 277: Which wireless measurement is most directly associated with the amount of airtime currently being consumed on an RF channel?

  1. EIRP
  2. RSSI
  3. Channel utilization
  4. BSSID

Correct Answer: 3. Channel utilization

Explanation:

Channel utilization represents the proportion of time that an RF channel is detected as occupied. High utilization can result from client traffic, neighboring WLANs, interference, or other transmissions and can reduce the airtime available for additional wireless communication. RSSI measures received signal strength, EIRP represents effective radiated power, and BSSID identifies a wireless BSS. Therefore, channel utilization is the measurement most directly associated with how much airtime on an RF channel is currently being consumed.

Question 278: Which Cisco wireless capability helps administrators analyze the RF spectrum beyond normal Wi-Fi protocol traffic?

  1. Spectrum Analysis
  2. RADIUS Accounting
  3. DHCP Proxy
  4. WPA3-SAE

Correct Answer: 1. Spectrum Analysis

Explanation:

Spectrum Analysis examines RF energy across the wireless spectrum and can help identify interference sources that may not appear as normal Wi-Fi frames. This provides additional visibility when troubleshooting RF problems caused by non-Wi-Fi transmitters or other environmental sources. RADIUS Accounting records authentication-related session information, DHCP Proxy assists with DHCP operations, and WPA3-SAE provides password-based wireless authentication. Therefore, Spectrum Analysis is the capability most directly associated with examining the broader RF spectrum to identify potential interference.

Question 279: Which wireless security technology provides stronger protection for password-based personal WLAN authentication by using SAE?

  1. WPA2-Personal
  2. WPA3-Personal
  3. WPA2-Enterprise
  4. PEAP

Correct Answer: 2. WPA3-Personal

Explanation:

WPA3-Personal uses Simultaneous Authentication of Equals (SAE) for password-based authentication. SAE provides stronger resistance to offline password-guessing attacks than the traditional WPA2-Personal pre-shared-key approach. WPA2-Enterprise uses 802.1X and a centralized authentication server, while PEAP is an enterprise EAP authentication method. Therefore, WPA3-Personal is the security technology associated with SAE and improved protection for password-based personal WLAN authentication.

Question 280: Which design practice helps reduce excessive co-channel contention in a high-density wireless deployment?

  1. Increase transmit power on every AP
  2. Use maximum channel width on all radios
  3. Carefully plan channel reuse, AP placement, and cell size
  4. Place all APs on the same channel

Correct Answer: 3. Carefully plan channel reuse, AP placement, and cell size

Explanation:

High-density WLANs require careful RF planning because many clients and access points compete for limited airtime. Appropriate channel reuse, AP placement, transmit-power levels, and cell sizing help distribute clients and reduce unnecessary co-channel contention. Increasing transmit power indiscriminately can enlarge coverage cells and increase contention, while using maximum channel width everywhere can reduce the number of channels available for reuse. Placing all APs on the same channel creates excessive contention. Therefore, careful planning of channel reuse, AP placement, and cell size is an important strategy for improving capacity in high-density wireless environments.