Cisco CCNP Wireless 350-101 Practice Test Questions and Exam Dumps Part 17 Q321-340

View Full Cisco CCNP Wireless 350-101 Exam Dumps and Practice Test Dumps

 

Question 321: Which method can help a Cisco lightweight AP discover a controller when the AP and controller are on different IP subnets?

  1. DHCP Option 43
  2. WMM
  3. 802.11w
  4. RADIUS Accounting

Correct Answer: 1. DHCP Option 43

Explanation:
DHCP Option 43 can provide a Cisco lightweight access point with controller discovery information when the AP receives its network configuration from a DHCP server. This is particularly useful when the AP and controller are located on different IP subnets and Layer 2 broadcast-based discovery cannot reach the controller. The DHCP response can contain the controller’s IP address, allowing the AP to initiate the appropriate discovery process. WMM provides wireless QoS, 802.11w provides Protected Management Frames, and RADIUS Accounting records session information. DHCP Option 43 is therefore an important mechanism for controller discovery in routed enterprise networks.

Question 322: Which Cisco wireless controller feature allows an administrator to define a logical WLAN and associate it with a specific VLAN?

  1. RF Group
  2. WLAN profile mapped to a dynamic interface
  3. CleanAir
  4. Mobility Group

Correct Answer: 2. WLAN profile mapped to a dynamic interface

Explanation:
A Cisco wireless controller uses WLAN profiles to define wireless network characteristics such as the WLAN identifier, security configuration, and other client-access settings. The WLAN can be associated with a dynamic interface, which provides connectivity to the corresponding VLAN on the wired network. This mapping allows client traffic from a particular WLAN to reach the appropriate IP subnet. RF Groups are used for coordinated RF management, CleanAir addresses interference visibility, and Mobility Groups support controller mobility relationships. Understanding WLAN-to-interface mapping is essential when designing segmented enterprise wireless networks.

Question 323: What is the primary purpose of RADIUS failover in an enterprise WLAN?

  1. To provide additional RF channels
  2. To increase antenna gain
  3. To maintain authentication availability if the primary RADIUS server becomes unavailable
  4. To encrypt CAPWAP data traffic

Correct Answer: 3. To maintain authentication availability if the primary RADIUS server becomes unavailable

Explanation:
RADIUS failover provides authentication resilience by allowing the wireless infrastructure to use an alternate RADIUS server when the primary authentication server is unavailable or fails to respond. This can help maintain enterprise WLAN access during an authentication-server outage. RADIUS servers can also provide authorization and accounting functions depending on the deployment. Failover does not increase RF capacity, change antenna gain, or provide CAPWAP encryption. CAPWAP uses its own control and data mechanisms, including DTLS protection for the control channel. RADIUS redundancy is therefore primarily an availability feature for AAA services.

Question 324: Which Cisco wireless feature can prevent a client from repeatedly attempting to connect when the client is determined to violate configured access policies?

  1. Client Exclusion
  2. DFS
  3. OFDMA
  4. AP Group

Correct Answer: 1. Client Exclusion

Explanation:
Client Exclusion allows a Cisco wireless controller to temporarily prevent a problematic client from accessing the WLAN when configured conditions are met. It can be useful for addressing repeated authentication failures, excessive association attempts, or other client behaviors that may negatively affect the wireless environment. The exact exclusion behavior depends on the configured policies and software version. DFS manages radar-sensitive RF channels, OFDMA improves wireless spectrum efficiency, and AP Groups control WLAN availability on selected APs. Client Exclusion is therefore the feature directly associated with restricting a client that repeatedly violates configured access conditions.

Question 325: Which 5 GHz feature requires an AP to monitor for radar before or during operation on certain channels?

  1. WMM
  2. DFS
  3. SNR
  4. AVC

Correct Answer: 2. DFS

Explanation:
Dynamic Frequency Selection, or DFS, applies to certain 5 GHz channels that are subject to regulatory requirements related to radar detection. An AP operating on a DFS channel may need to perform channel availability checks and monitor for radar activity. If radar is detected, the AP may be required to vacate the affected channel and select another permitted channel. WMM is a wireless QoS mechanism, SNR measures signal quality relative to noise, and AVC provides application visibility and control. DFS is therefore the feature directly associated with radar detection and regulatory channel management in supported 5 GHz bands.

Question 326: Which metric represents the difference between received wireless signal strength and the background noise level?

  1. BSSID
  2. SNR
  3. EIRP
  4. Channel width

Correct Answer: 2. SNR

Explanation:
Signal-to-Noise Ratio, or SNR, represents the difference between the desired received signal level and the background noise level, typically expressed in decibels. A higher SNR generally indicates that the receiver can distinguish the desired signal more effectively from background noise. This can contribute to better reliability and support for higher data rates, depending on the client and RF conditions. BSSID identifies a specific wireless BSS, EIRP describes effective transmitted RF power, and channel width identifies the amount of spectrum used. SNR is therefore the appropriate metric when evaluating the separation between signal and noise.

Question 327: Which Cisco wireless technology can identify an unauthorized access point connected to the wired network?

  1. Rogue AP detection
  2. DHCP Proxy
  3. WMM
  4. TPC

Correct Answer: 1. Rogue AP detection

Explanation:
Rogue AP detection is used to identify unauthorized access points that are connected to the organization’s wired infrastructure or otherwise represent a potential security concern. Cisco wireless infrastructure can use information gathered by APs and controller functions to detect and classify wireless devices. Administrators can then investigate whether an identified AP is authorized, neighboring, or potentially connected to the corporate network. DHCP Proxy handles DHCP processing, WMM provides wireless QoS, and TPC controls transmit power. Rogue AP detection is therefore the capability most directly associated with identifying unauthorized wireless infrastructure.

Question 328: In a high-density WLAN, why can using very wide channels reduce overall capacity?

  1. Wide channels always reduce RSSI
  2. Wide channels require more spectrum and leave fewer opportunities for channel reuse
  3. Wide channels disable WPA3
  4. Wide channels prevent 802.11k from operating

Correct Answer: 2. Wide channels require more spectrum and leave fewer opportunities for channel reuse

Explanation:
Wider wireless channels consume more RF spectrum for each transmission opportunity. In a high-density deployment, this can reduce the number of distinct channels available for reuse among nearby access points. Although wider channels can provide higher peak data rates under suitable conditions, they can also increase co-channel contention when many APs and clients compete for limited spectrum. Channel width should therefore be selected based on capacity requirements, client capabilities, RF conditions, and the density of the deployment. Wide channels do not inherently disable WPA3 or 802.11k, nor do they automatically reduce RSSI.

Question 329: Which Cisco RRM function primarily evaluates and manages channel selection for access points?

  1. Dynamic Transmit Power Control
  2. Dynamic Channel Assignment
  3. Client Exclusion
  4. Mobility Anchoring

Correct Answer: 2. Dynamic Channel Assignment

Explanation:
Dynamic Channel Assignment, or DCA, is an RRM function responsible for selecting appropriate RF channels for access points based on measured RF conditions and configured requirements. The goal is to reduce interference and improve channel reuse and overall wireless performance. Dynamic Transmit Power Control focuses on AP transmit power rather than channel selection. Client Exclusion controls access by problematic clients, while Mobility Anchoring is related to specific controller mobility and guest-access designs. DCA can use measurements such as interference, channel utilization, and neighboring AP information when determining suitable channel assignments.

Question 330: Which Cisco wireless feature provides centralized management of RF parameters such as channel and transmit power?

  1. RRM
  2. Web Authentication
  3. RADIUS Accounting
  4. Bonjour Gateway

Correct Answer: 1. RRM

Explanation:
Radio Resource Management, or RRM, provides automated and centralized management of important RF parameters in Cisco controller-based wireless deployments. RRM can manage functions such as Dynamic Channel Assignment and Dynamic Transmit Power Control based on measurements gathered from participating access points. This helps the wireless infrastructure respond to changing RF conditions and maintain appropriate coverage and channel assignments. Web Authentication is used for portal-based access, RADIUS Accounting records session information, and Bonjour Gateway supports service discovery across network segments. RRM is therefore the Cisco capability most directly associated with automated RF management.

Question 331: Which IEEE amendment provides Neighbor Reports that can help a wireless client identify nearby access points?

  1. 802.11r
  2. 802.11v
  3. 802.11k
  4. 802.11w

Correct Answer: 3. 802.11k

Explanation:
IEEE 802.11k provides mechanisms that allow wireless clients to obtain information about neighboring access points and radio conditions. A Neighbor Report can help a capable client identify candidate APs for roaming without having to perform a complete scan of every possible channel. This can reduce scanning overhead and improve roaming efficiency. 802.11r focuses on fast BSS transitions, 802.11v provides network-assisted BSS transition mechanisms, and 802.11w provides Protected Management Frames. Therefore, 802.11k is the amendment directly associated with Neighbor Reports.

Question 332: Which Cisco feature can provide application-level visibility to help identify what is consuming wireless network resources?

  1. AVC
  2. DFS
  3. CAPWAP Discovery
  4. RF Group

Correct Answer: 1. AVC

Explanation:
Application Visibility and Control, or AVC, provides visibility into application traffic traversing the network. It can help administrators identify applications, understand traffic consumption, and apply supported application-aware policies. This information can be valuable when investigating bandwidth usage, performance problems, or quality-of-service requirements. DFS addresses radar-related channel management, CAPWAP Discovery is used to locate controllers, and RF Groups support coordinated RF management. AVC is therefore the appropriate Cisco capability when an administrator needs visibility into application-level traffic rather than simply RF or controller connectivity information.

Question 333: What is the primary purpose of a Mobility Anchor in a Cisco wireless deployment?

  1. To provide an RF spectrum analyzer
  2. To terminate specific mobility tunnels, commonly for guest traffic
  3. To assign AP transmit power
  4. To replace the RADIUS server

Correct Answer: 2. To terminate specific mobility tunnels, commonly for guest traffic

Explanation:
A Mobility Anchor can provide a centralized termination point for mobility tunnels associated with specific WLAN designs. One common use is guest access, where client traffic can be anchored to a controller located in a controlled network or DMZ while preserving the desired traffic path. The anchor does not perform RRM transmit-power management, replace RADIUS authentication, or act as a general-purpose spectrum analyzer. Mobility Anchors are part of Cisco controller mobility architecture and can help separate guest or specialized WLAN traffic from the local controller environment. Proper mobility configuration is required for the tunnel relationship to function correctly.

Question 334: Which WLAN security method uses Simultaneous Authentication of Equals rather than a traditional pre-shared-key four-way handshake?

  1. WPA2-Personal
  2. WPA3-Personal
  3. WPA2-Enterprise
  4. Open System

Correct Answer: 2. WPA3-Personal

Explanation:
WPA3-Personal uses Simultaneous Authentication of Equals, or SAE, to provide password-based authentication. SAE improves resistance to certain offline password-guessing attacks compared with the traditional WPA2-Personal pre-shared-key approach. WPA2-Personal uses a PSK-based mechanism, while WPA2-Enterprise normally relies on 802.1X and an authentication server. Open System authentication does not provide equivalent password-based WLAN security. WPA3-Personal therefore represents the security method associated with SAE and is an important modern WLAN security option when supported by both infrastructure and clients.

Question 335: Which RF measurement is most useful for determining whether a wireless channel is already heavily occupied by transmissions and other RF activity?

  1. Channel utilization
  2. BSSID
  3. EAP method
  4. VLAN identifier

Correct Answer: 1. Channel utilization

Explanation:
Channel utilization provides an indication of how much of the available RF airtime is occupied. High utilization can result from legitimate WLAN transmissions, neighboring wireless networks, interference, retransmissions, and other RF activity. A channel with high utilization may provide less available airtime to individual clients, even when those clients have strong RSSI. BSSID identifies a wireless network, EAP methods are used for authentication, and VLAN identifiers describe network segmentation. Channel utilization is therefore a key measurement when determining whether RF congestion or contention may be contributing to poor wireless performance.

Question 336: Which wireless security technology protects selected management frames against modification or spoofing?

  1. PMF
  2. DHCP Option 43
  3. RRM
  4. OFDMA

Correct Answer: 1. PMF

Explanation:
Protected Management Frames, or PMF, provide security for selected IEEE 802.11 management frames. PMF can help protect against attacks that use forged management frames, including certain deauthentication and disassociation attacks. This protection is separate from the confidentiality provided for user data by WLAN encryption mechanisms. DHCP Option 43 is used for AP controller discovery, RRM manages RF resources, and OFDMA improves spectrum efficiency through resource-unit allocation. PMF is therefore the security technology directly associated with protecting applicable wireless management frames from spoofing and related manipulation.

Question 337: Which deployment approach is most appropriate when wireless clients at a remote branch should have their data traffic switched locally rather than tunneled to the central controller?

  1. FlexConnect Local Switching
  2. Monitor mode
  3. Sniffer mode
  4. Local mode with centralized switching

Correct Answer: 1. FlexConnect Local Switching

Explanation:
FlexConnect Local Switching allows client data traffic at a remote site to be switched onto the local wired network instead of being centrally tunneled through the wireless controller. This can reduce WAN bandwidth consumption and allow remote WLAN traffic to remain local to the branch. The AP can still maintain a controller relationship for management and configuration when connectivity is available. Monitor and sniffer modes are specialized operational modes rather than normal client-serving modes. Local mode generally uses centralized traffic forwarding through the controller. FlexConnect Local Switching is therefore appropriate for remote-site deployments requiring local data forwarding.

Question 338: Which Cisco wireless capability can collect and present client-experience information to help identify authentication, onboarding, and connectivity problems?

  1. Wireless Assurance
  2. DFS
  3. DHCP Option 43
  4. Antenna Diversity

Correct Answer: 1. Wireless Assurance

Explanation:
Wireless Assurance provides analytics and operational visibility into wireless infrastructure and client experience. It can help administrators investigate issues involving client onboarding, authentication, connectivity, performance, and other aspects of WLAN operation by correlating information from multiple network components. DFS focuses on radar-related channel behavior, DHCP Option 43 assists with controller discovery, and antenna diversity involves RF reception techniques. Wireless Assurance is therefore the capability most directly associated with analyzing client experience and providing centralized operational insight into wireless problems.

Question 339: Which condition can cause a client to experience poor throughput even when its RSSI is strong?

  1. High RF channel utilization
  2. A long DNS hostname
  3. A short DHCP lease
  4. A low RADIUS accounting interval

Correct Answer: 1. High RF channel utilization

Explanation:
Strong RSSI only indicates that the client is receiving a relatively strong desired signal. It does not guarantee that sufficient airtime is available or that the RF environment is free from contention and interference. High channel utilization can reduce the amount of airtime available to the client and cause increased contention, retransmissions, and lower effective throughput. DNS hostname length, DHCP lease duration, and RADIUS accounting intervals do not directly explain RF airtime congestion. When strong RSSI is accompanied by poor throughput, administrators should therefore examine channel utilization, interference, SNR, retransmissions, and other RF performance measurements.

Question 340: Which design practice is generally appropriate for voice over Wi-Fi deployments?

  1. Maximize AP transmit power everywhere
  2. Use overlapping RF coverage with appropriate signal and SNR targets
  3. Disable QoS to avoid prioritization overhead
  4. Use the widest possible channel on every AP

Correct Answer: 2. Use overlapping RF coverage with appropriate signal and SNR targets

Explanation:
Voice over Wi-Fi requires reliable RF coverage and sufficient overlap to support roaming between access points without creating excessive contention. A voice-oriented design should establish appropriate signal-strength and SNR targets, provide controlled cell overlap, and use suitable QoS mechanisms such as WMM. Simply maximizing transmit power can create excessive cell size and co-channel contention. Disabling QoS can negatively affect latency-sensitive traffic, while using the widest possible channels may reduce channel reuse in dense environments. Proper RF planning, capacity analysis, channel selection, and validation through site surveys are therefore important components of a successful voice WLAN design.