Cisco CCNP Wireless 350-101 Practice Test Questions and Exam Dumps Part 15 Q281-300

View Full Cisco CCNP Wireless 350-101 Exam Dumps and Practice Test Dumps

 

Question 281: Which CAPWAP port is used by default for the CAPWAP control channel between an AP and a Cisco wireless controller?

  1. UDP 5246
  2. UDP 1812
  3. UDP 5247
  4. UDP 1701

Correct Answer: 1. UDP 5246

Explanation:
CAPWAP uses UDP 5246 for its control channel and UDP 5247 for its data channel. The control channel carries management and control information exchanged between the access point and wireless controller. CAPWAP control messages are protected using DTLS to provide confidentiality and integrity. UDP 1812 is commonly associated with RADIUS authentication, while UDP 1701 is associated with L2TP. Understanding the CAPWAP port distinction is important when troubleshooting firewalls, ACLs, or network connectivity between Cisco APs and controllers. Therefore, UDP 5246 is the correct port for CAPWAP control traffic.

Question 282: Which Cisco wireless controller interface is primarily used for management access and communication with the controller itself?

  1. Dynamic interface
  2. Service port
  3. WLAN interface
  4. AP management interface

Correct Answer: 2. Service port

Explanation:
The service port on a Cisco wireless controller provides a dedicated interface for out-of-band management and certain recovery or maintenance functions. It is separate from the normal data-plane interfaces used to transport client traffic. Depending on the controller platform and deployment, the service port can be used for direct management access and troubleshooting when normal network connectivity is unavailable. Dynamic interfaces, in contrast, are commonly associated with VLANs and client traffic. Understanding the service port is useful when troubleshooting controller access or designing a management architecture that separates administrative traffic from production WLAN traffic.

Question 283: During AP discovery, which mechanism can allow a Cisco AP to locate a wireless controller when DHCP is used?

  1. 802.11k Neighbor Report
  2. DHCP Option 43
  3. RADIUS accounting
  4. WMM

Correct Answer: 2. DHCP Option 43

Explanation:
DHCP Option 43 can provide Cisco access points with the IP address of a wireless LAN controller during the DHCP process. After obtaining an IP address and relevant DHCP information, the AP can use the supplied controller information as part of its discovery process. This method is especially useful when the AP and controller are located in different IP subnets and broadcast-based discovery cannot cross routers. 802.11k is related to wireless neighbor information, RADIUS accounting records session information, and WMM provides wireless quality-of-service mechanisms. DHCP Option 43 is therefore the relevant mechanism for controller discovery in this scenario.

Question 284: Which step occurs after a Cisco lightweight AP discovers a controller and selects a suitable controller during the CAPWAP join process?

  1. The AP immediately begins client forwarding without authentication.
  2. The AP disables CAPWAP and operates permanently in standalone mode.
  3. The AP establishes the CAPWAP control connection and completes the join process.
  4. The AP creates a new RF Group automatically.

Correct Answer: 3. The AP establishes the CAPWAP control connection and completes the join process.

Explanation:
After a lightweight Cisco AP discovers potential controllers, it selects an appropriate controller and proceeds with the CAPWAP join process. The AP establishes the CAPWAP control connection, performs the required authentication and negotiation, and completes the join process before normal controller-based operation begins. The controller can then manage configuration, WLAN information, RF settings, and other AP functions. The AP does not simply begin forwarding client traffic without completing the control relationship. RF Groups are also controller-side RF management constructs rather than something created automatically by each AP during discovery.

Question 285: In a Cisco wireless deployment, which component normally acts as the authenticator between a wireless client and a RADIUS server during 802.1X authentication?

  1. DHCP server
  2. Wireless LAN controller or access point
  3. DNS server
  4. Wireless client only

Correct Answer: 2. Wireless LAN controller or access point

Explanation:
In an 802.1X wireless architecture, the wireless client acts as the supplicant, while the access point or wireless LAN controller performs the authenticator role. The authenticator controls access to the WLAN and relays EAP authentication information between the client and the RADIUS authentication server. The RADIUS server performs the authentication and authorization functions based on the configured credentials and policies. DHCP and DNS servers perform different network services and are not normally responsible for the 802.1X authentication exchange. Understanding these roles is essential when troubleshooting enterprise WLAN authentication problems.

Question 286: Which RADIUS function provides information about a user’s session, such as when the session started or ended?

  1. RADIUS authentication
  2. RADIUS authorization
  3. RADIUS accounting
  4. RADIUS encryption

Correct Answer: 3. RADIUS accounting

Explanation:
RADIUS accounting is used to record information about network access sessions. Accounting messages can provide details such as session start and stop events, session duration, and other usage information depending on the implementation. Authentication determines whether a user or device can authenticate, while authorization determines what access or policy should be applied after successful authentication. RADIUS itself does not use a function called “RADIUS encryption” as a separate AAA role. In wireless environments, accounting can be useful for auditing, usage tracking, and integration with systems that need records of client sessions.

Question 287: An administrator needs to assign wireless users to different VLANs based on attributes returned by the authentication server. Which capability is most appropriate?

  1. Dynamic VLAN assignment
  2. CleanAir
  3. CAPWAP discovery
  4. DFS

Correct Answer: 1. Dynamic VLAN assignment

Explanation:
Dynamic VLAN assignment allows a wireless infrastructure to place authenticated users into different VLANs based on information returned by an authentication or authorization server. In an enterprise WLAN, RADIUS can return attributes such as VLAN-related information, allowing the controller or AP to apply the appropriate VLAN to the user’s session. This approach can support role-based or user-based network segmentation without requiring a separate WLAN for every user group. CleanAir addresses RF interference detection, CAPWAP discovery locates controllers, and DFS manages radar-sensitive channels. Dynamic VLAN assignment directly addresses the requirement for authentication-based VLAN placement.

Question 288: Which feature allows a wireless client to access a guest WLAN through a web-based authentication page?

  1. 802.11k
  2. Web authentication
  3. RRM
  4. OFDMA

Correct Answer: 2. Web authentication

Explanation:
Web authentication provides a browser-based mechanism commonly used for guest WLAN access. A client can associate with the wireless network and receive network connectivity sufficient to reach a web portal, where the user may be required to accept terms, enter credentials, or complete another authentication process. This approach is frequently used in guest environments because it does not require the user to configure an enterprise 802.1X supplicant. 802.11k assists with radio measurements and neighbor information, RRM manages RF parameters, and OFDMA improves spectrum efficiency. Web authentication is therefore the appropriate feature for portal-based guest access.

Question 289: Which Cisco wireless feature can provide controller-based visibility and analytics about client connectivity and network health?

  1. Wireless Assurance
  2. DHCP Option 43
  3. WPA3-SAE
  4. CAPWAP DTLS

Correct Answer: 1. Wireless Assurance

Explanation:
Wireless Assurance provides analytics and visibility into wireless infrastructure and client experience. In Cisco environments, assurance capabilities can help administrators investigate connectivity problems, performance issues, authentication failures, and other operational conditions by collecting and correlating information from the wireless network. DHCP Option 43 is associated with AP controller discovery, WPA3-SAE provides a personal WLAN authentication mechanism, and CAPWAP DTLS protects control communication. Wireless Assurance is therefore the feature most directly associated with operational visibility and analytics rather than basic WLAN connectivity or authentication.

Question 290: What is the primary purpose of a mobility group in a Cisco wireless architecture?

  1. To replace RADIUS authentication
  2. To provide centralized DHCP services
  3. To enable controllers to exchange mobility information and support client roaming
  4. To assign RF channels independently of RRM

Correct Answer: 3. To enable controllers to exchange mobility information and support client roaming

Explanation:
A Cisco wireless mobility group allows multiple wireless controllers to exchange mobility information and support client roaming across controller boundaries. The controllers establish mobility relationships so that client state and other information can be maintained when a client moves between APs managed by different controllers. This helps provide continuity for roaming clients and supports services such as seamless mobility within an appropriately designed deployment. A mobility group does not replace RADIUS, provide centralized DHCP by itself, or independently assign RF channels. Its primary role is facilitating controller-to-controller mobility communication and roaming.

Question 291: Which Cisco wireless feature can provide a centralized gateway function for Bonjour or mDNS service discovery across different VLANs?

  1. Bonjour Gateway
  2. CleanAir
  3. Client Exclusion
  4. RF Group

Correct Answer: 1. Bonjour Gateway

Explanation:
Bonjour Gateway allows service-discovery traffic based on Bonjour or multicast DNS to be selectively propagated between different network segments. This is useful when devices providing services such as printing, media sharing, or other mDNS-based services are located in different VLANs from the clients that need to discover them. Instead of broadly forwarding multicast traffic everywhere, the gateway can provide controlled service discovery between defined networks. CleanAir is used for RF interference monitoring, Client Exclusion addresses problematic clients, and RF Groups support RF management. Bonjour Gateway is therefore the relevant capability for cross-VLAN Bonjour service discovery.

Question 292: Which IEEE 802.11 amendment is primarily associated with fast BSS transition for wireless clients?

  1. 802.11v
  2. 802.11k
  3. 802.11r
  4. 802.11w

Correct Answer: 3. 802.11r

Explanation:
IEEE 802.11r, also known as Fast BSS Transition, is designed to reduce the time required for a client to complete security-related operations when roaming between access points. Faster transitions are particularly important for latency-sensitive applications such as voice over Wi-Fi, where lengthy authentication delays can interrupt active sessions. 802.11k provides information about neighboring APs and radio measurements, while 802.11v can assist with network-directed client transitions. 802.11w is associated with Protected Management Frames. Therefore, 802.11r is the amendment specifically designed to improve the speed of secure roaming transitions.

Question 293: Which Cisco feature can help an administrator determine whether radar activity is affecting available 5 GHz channels?

  1. DHCP Proxy
  2. DFS event monitoring
  3. WMM
  4. RADIUS accounting

Correct Answer: 2. DFS event monitoring

Explanation:
Dynamic Frequency Selection, or DFS, is used with certain 5 GHz channels that are subject to regulatory requirements related to radar detection. When radar is detected, an AP may be required to stop using the affected channel and select another permitted channel. DFS event information can therefore help administrators determine whether radar detection is influencing channel availability or causing channel changes. DHCP Proxy handles DHCP traffic, WMM provides wireless QoS, and RADIUS accounting records session information. DFS event monitoring is consequently the most relevant troubleshooting mechanism when investigating radar-related channel behavior.

Question 294: Which RRM function automatically selects an appropriate RF channel for an access point based on the surrounding RF environment?

  1. Dynamic Channel Assignment
  2. Dynamic VLAN Assignment
  3. Web Authentication
  4. Client Exclusion

Correct Answer: 1. Dynamic Channel Assignment

Explanation:
Dynamic Channel Assignment, or DCA, is an RRM function that evaluates RF conditions and helps select appropriate operating channels for access points. The goal is to reduce interference and improve overall channel utilization within the managed wireless environment. RRM can consider factors such as neighboring APs, interference, channel utilization, and other RF measurements when making channel-management decisions. Dynamic VLAN Assignment is related to client segmentation, Web Authentication provides portal-based access, and Client Exclusion is used to restrict problematic clients. DCA is therefore the RRM function directly associated with automated RF channel selection.

Question 295: Which RRM function controls an access point’s transmit power to help maintain appropriate RF coverage?

  1. Dynamic Channel Assignment
  2. Dynamic Transmit Power Control
  3. DHCP Proxy
  4. Mobility Anchor

Correct Answer: 2. Dynamic Transmit Power Control

Explanation:
Dynamic Transmit Power Control, commonly referred to as TPC, is an RRM function that adjusts AP transmit power based on RF conditions and configured requirements. Proper transmit-power management can help maintain suitable coverage while reducing excessive cell overlap and unnecessary interference. Dynamic Channel Assignment focuses on channel selection rather than transmit power. DHCP Proxy handles DHCP request processing, while a Mobility Anchor supports specific mobility and guest-access designs. TPC is particularly important in environments where consistent RF coverage and controlled cell size are required, especially when many APs operate in close proximity.

Question 296: What is a major benefit of 802.11k in a Cisco wireless deployment?

  1. It encrypts all management frames
  2. It provides neighbor and radio measurement information to clients
  3. It assigns users to VLANs
  4. It replaces WPA2 authentication

Correct Answer: 2. It provides neighbor and radio measurement information to clients

Explanation:
IEEE 802.11k enables a wireless client to obtain information about nearby access points and radio conditions through mechanisms such as Neighbor Reports. This information can help a capable client make more informed roaming decisions instead of scanning the entire RF environment blindly. 802.11k does not replace WLAN security protocols, perform VLAN assignment, or provide management-frame protection. 802.11r focuses on faster secure transitions, while 802.11v provides mechanisms that can assist with network-directed BSS transitions. Therefore, providing useful neighbor and radio information to clients is a key benefit of 802.11k.

Question 297: Which wireless security feature protects management frames against certain spoofing and forged management-frame attacks?

  1. PMF
  2. DHCP Snooping
  3. RRM
  4. OFDMA

Correct Answer: 1. PMF

Explanation:
Protected Management Frames, or PMF, are defined by IEEE 802.11w and provide protection for certain wireless management frames. PMF helps reduce the ability of attackers to spoof protected management traffic and can improve resilience against attacks involving forged deauthentication or disassociation frames. PMF is a security mechanism and is distinct from DHCP Snooping, which protects against certain unauthorized DHCP behavior, RRM, which manages RF parameters, and OFDMA, which improves wireless spectrum efficiency. Understanding PMF is important when designing modern secure WLANs because management-frame protection addresses threats that traditional encryption alone does not fully prevent.

Question 298: A client has strong RSSI but experiences poor throughput. Which measurement should an administrator investigate first to determine whether the RF environment is limiting performance?

  1. DHCP lease duration
  2. DNS cache size
  3. Channel utilization
  4. RADIUS accounting interval

Correct Answer: 3. Channel utilization

Explanation:
Strong RSSI does not necessarily indicate a healthy or uncongested wireless environment. A client can have excellent received signal strength while experiencing poor throughput because the channel is heavily utilized by other transmissions, neighboring WLANs, interference sources, or excessive contention. Channel utilization provides an important indication of how busy the RF medium is and should therefore be investigated when throughput is poor despite strong signal strength. DHCP lease duration, DNS cache size, and RADIUS accounting intervals do not directly measure RF medium utilization. High channel utilization can help explain why a client with strong RSSI still experiences poor performance.

Question 299: Which measurement is most useful for determining the difference between the received signal level and the RF noise floor?

  1. EIRP
  2. SNR
  3. Channel width
  4. Association time

Correct Answer: 2. SNR

Explanation:
Signal-to-Noise Ratio, or SNR, represents the relationship between the desired wireless signal and the background noise level. A higher SNR generally indicates that the desired signal is more distinguishable from noise and can support more reliable wireless communication. RSSI or received signal level describes signal strength but does not by itself indicate the amount of background noise. EIRP describes effective transmitted power, channel width describes the amount of RF spectrum used, and association time describes connection behavior. When an administrator needs to understand how far the desired signal is above the noise floor, SNR is the appropriate measurement.

Question 300: In a high-density wireless deployment, which design approach can help improve capacity by reducing excessive cell overlap and managing channel reuse?

  1. Increase every AP to maximum transmit power
  2. Use the same channel on every nearby AP
  3. Disable all RRM functions
  4. Use appropriate cell sizing and coordinated channel reuse**

Correct Answer: 4. Use appropriate cell sizing and coordinated channel reuse

Explanation:
High-density WLANs require careful RF planning because simply increasing AP transmit power does not necessarily increase usable capacity. Excessive cell overlap can increase contention and co-channel interference, while poor channel planning can reduce available airtime. Appropriate cell sizing, coordinated channel reuse, suitable channel widths, and careful transmit-power management can help distribute clients and available airtime more effectively. RRM can assist with automated RF management when properly configured, but high-density environments may also require deliberate design and validation through site surveys. Therefore, coordinated channel reuse and appropriate cell sizing are important elements of a capacity-focused wireless design.