View Full Cisco CCNP Wireless 350-101 Exam Dumps and Practice Test Dumps
Question 341: Which protocol is used by Cisco lightweight access points to establish their control relationship with a wireless LAN controller?
- RADIUS
- CAPWAP
- SNMP
- TACACS+
Correct Answer: 2. CAPWAP
Explanation:
Control and Provisioning of Wireless Access Points, or CAPWAP, is the protocol used by Cisco lightweight access points to communicate with and be managed by a wireless LAN controller. CAPWAP provides control and data channels between the AP and controller. The control channel carries management information and is protected with DTLS, while the data channel can transport client traffic when centralized forwarding is used. RADIUS is primarily used for AAA, SNMP provides network management capabilities, and TACACS+ is commonly used for device administration. CAPWAP is therefore the protocol directly associated with AP-to-controller communication.
Question 342: Which Cisco controller interface is commonly used for out-of-band management and system recovery functions?
- Dynamic interface
- WLAN interface
- Service port
- RF interface
Correct Answer: 3. Service port
Explanation:
The service port on supported Cisco wireless LAN controllers provides a dedicated interface for out-of-band management and certain maintenance or recovery functions. It is separate from the interfaces normally used to carry production WLAN and client traffic. This separation can be useful when troubleshooting controller connectivity or performing management tasks when normal data-plane connectivity is unavailable. Dynamic interfaces are generally associated with VLANs and WLAN traffic, while WLAN interfaces represent logical wireless configurations rather than a dedicated physical management port. The service port is therefore the appropriate interface for dedicated out-of-band management functions.
Question 343: Which Cisco WLAN security architecture uses 802.1X authentication with an external authentication server?
- WPA2-Enterprise
- WPA2-Personal
- Open System
- WPA3-Personal only
Correct Answer: 1. WPA2-Enterprise
Explanation:
WPA2-Enterprise commonly uses IEEE 802.1X authentication together with an external AAA server such as RADIUS. The client acts as the supplicant, while the AP or controller acts as the authenticator and exchanges authentication information with the RADIUS server. This architecture allows organizations to use individual credentials or certificate-based authentication rather than sharing one pre-shared key among users. WPA2-Personal uses a pre-shared key, while Open System does not provide equivalent enterprise authentication. WPA3-Personal uses SAE rather than the traditional 802.1X enterprise model. WPA2-Enterprise is therefore the appropriate choice for 802.1X-based enterprise WLAN authentication.
Question 344: Which RADIUS message is commonly used by a network access device to request authentication of a wireless client?
- Accounting-Request
- Access-Accept
- Access-Request
- Accounting-Response
Correct Answer: 3. Access-Request
Explanation:
A RADIUS Access-Request message is sent by the network access device, such as a wireless controller or access point, to request authentication and authorization from a RADIUS server. The server can respond with messages such as Access-Accept or Access-Reject depending on the authentication result and configured policy. Accounting messages are used to report session information rather than initiate authentication. Understanding these RADIUS message types is important when troubleshooting enterprise WLAN authentication because it helps administrators identify whether requests are reaching the server and how the server responds to them.
Question 345: Which Cisco wireless feature can restrict a WLAN to selected access points by controlling which WLANs are advertised by those APs?
- RF Group
- AP Group
- Mobility Group
- CleanAir
Correct Answer: 2. AP Group
Explanation:
An AP Group allows administrators to control which WLANs are associated with selected access points. This is useful when different locations require different WLAN availability or when certain wireless networks should only be advertised by particular APs. The AP Group configuration can associate specific WLANs with a defined group of access points. RF Groups are related to RF management, Mobility Groups support controller mobility relationships, and CleanAir provides interference visibility. AP Groups therefore provide the appropriate mechanism for controlling WLAN advertisement across selected APs.
Question 346: Which wireless feature is most directly associated with detecting unauthorized or potentially malicious access points?
- Rogue AP detection
- WMM
- OFDMA
- DHCP Proxy
Correct Answer: 1. Rogue AP detection
Explanation:
Rogue AP detection enables the wireless infrastructure to identify access points that may be unauthorized or connected to the organization’s wired network. Cisco wireless systems can use information gathered by APs and controllers to detect and classify neighboring wireless devices. Administrators can then investigate whether a detected device is an authorized AP, a neighboring network, or a potentially dangerous rogue device. WMM handles wireless QoS, OFDMA improves spectrum efficiency, and DHCP Proxy assists with DHCP processing. Rogue AP detection is therefore the feature specifically designed to provide visibility into unauthorized wireless infrastructure.
Question 347: Which Cisco RRM capability automatically adjusts access-point transmit power based on RF conditions?
- Dynamic Channel Assignment
- Dynamic VLAN Assignment
- Dynamic Transmit Power Control
- Client Exclusion
Correct Answer: 3. Dynamic Transmit Power Control
Explanation:
Dynamic Transmit Power Control, or TPC, is an RRM function that adjusts AP transmit power according to measured RF conditions and configured requirements. Proper transmit-power control can help maintain adequate coverage while reducing excessive overlap between neighboring cells. Dynamic Channel Assignment focuses on selecting operating channels, while Dynamic VLAN Assignment is related to client network segmentation. Client Exclusion controls access for clients that meet configured exclusion conditions. TPC is therefore the RRM mechanism directly associated with automated transmit-power management and is particularly useful in controller-managed enterprise WLAN deployments.
Question 348: What is the main advantage of using 802.11r for clients that frequently roam between access points?
- It provides faster security transitions during roaming
- It increases the AP antenna gain
- It replaces the RADIUS server
- It increases the available channel width
Correct Answer: 1. It provides faster security transitions during roaming
Explanation:
IEEE 802.11r, known as Fast BSS Transition, is designed to reduce the time required for security-related operations when a client moves between compatible access points. Faster roaming is particularly useful for applications such as voice and real-time collaboration, where interruptions caused by lengthy authentication procedures can affect the user experience. 802.11r does not increase antenna gain, replace RADIUS, or change the RF channel width. It can work alongside technologies such as 802.11k and 802.11v, which provide neighboring-AP information and network-assisted transition mechanisms. Its primary purpose is faster secure roaming.
Question 349: Which measurement should be checked when determining whether the wireless signal is sufficiently above the noise floor?
- VLAN ID
- SNR
- BSSID
- DHCP lease time
Correct Answer: 2. SNR
Explanation:
Signal-to-Noise Ratio, or SNR, measures the relationship between the desired wireless signal and the background noise level. A higher SNR generally indicates that the receiver has a clearer distinction between the intended signal and background RF energy. This can support more reliable communication and, depending on client capabilities and conditions, higher data rates. RSSI alone does not provide the complete picture because a strong signal can coexist with a high noise floor. VLAN IDs, BSSIDs, and DHCP lease times are unrelated to RF signal quality. SNR is therefore the key measurement when evaluating signal quality relative to noise.
Question 350: Which wireless QoS mechanism provides separate access categories for voice, video, best-effort, and background traffic?
- CAPWAP
- WMM
- DFS
- RRM
Correct Answer: 2. WMM
Explanation:
Wi-Fi Multimedia, or WMM, provides four wireless access categories: Voice, Video, Best Effort, and Background. These categories use different contention parameters to provide differentiated access to the shared RF medium. Voice traffic can be placed in AC_VO, while video commonly uses AC_VI, normal traffic uses AC_BE, and background traffic uses AC_BK. CAPWAP provides AP-to-controller communication, DFS handles radar-sensitive channels, and RRM manages RF resources. WMM is therefore the wireless QoS mechanism directly responsible for classifying and prioritizing traffic according to these four access categories.
Question 351: Which Cisco technology can identify and help characterize sources of non-802.11 interference?
- CleanAir
- DHCP Proxy
- 802.11k
- RADIUS Accounting
Correct Answer: 1. CleanAir
Explanation:
Cisco CleanAir provides enhanced RF visibility by detecting and helping characterize sources of interference that may not be ordinary Wi-Fi transmissions. Supported Cisco hardware can use spectrum-analysis capabilities to identify interference patterns and provide information that assists administrators with RF troubleshooting. This can help distinguish interference problems from ordinary WLAN contention. DHCP Proxy handles DHCP processing, 802.11k provides neighbor and radio information, and RADIUS Accounting records client-session information. CleanAir is therefore the Cisco technology most directly associated with identifying and characterizing non-802.11 RF interference.
Question 352: In a high-density 5 GHz WLAN, which design choice can improve channel reuse and reduce excessive co-channel contention?
- Use maximum transmit power on every AP
- Use appropriate channel widths and coordinated channel assignments
- Place every AP on the same channel
- Disable all RF management
Correct Answer: 2. Use appropriate channel widths and coordinated channel assignments
Explanation:
High-density WLANs require careful management of channel width, transmit power, and channel assignments. Using appropriately sized channels can increase the number of usable channel assignments and improve spatial reuse. Coordinated channel planning can also reduce unnecessary co-channel contention between neighboring access points. Setting every AP to maximum transmit power or using the same channel everywhere can increase contention and reduce available airtime. Disabling RF management does not inherently improve capacity. A balanced RF design therefore considers channel width, reuse patterns, client density, transmit power, and actual site-survey measurements when optimizing high-density deployments.
Question 353: Which protocol provides authentication, authorization, and accounting services commonly used for enterprise WLAN access?
- CAPWAP
- RADIUS
- DHCP
- DNS
Correct Answer: 2. RADIUS
Explanation:
RADIUS is commonly used to provide AAA services for enterprise wireless networks. During 802.1X authentication, the wireless controller or AP can act as the authenticator and communicate with a RADIUS server to authenticate and authorize clients. RADIUS can also provide accounting information about client sessions. CAPWAP is used for AP-to-controller communication, DHCP provides IP addressing services, and DNS provides name resolution. RADIUS is therefore the protocol most directly associated with centralized authentication, authorization, and accounting for enterprise WLAN users.
Question 354: Which feature allows a wireless controller to use a centralized server for authenticating enterprise WLAN users?
- RADIUS
- OFDMA
- CleanAir
- DFS
Correct Answer: 1. RADIUS
Explanation:
A wireless controller can use RADIUS to communicate with a centralized authentication server for enterprise WLAN access. In an 802.1X deployment, the controller or AP relays authentication exchanges between the client and the RADIUS server. This allows organizations to centralize user authentication and apply authorization policies without maintaining a separate credential database on every AP. OFDMA improves wireless efficiency, CleanAir provides RF interference visibility, and DFS manages radar-sensitive channels. RADIUS is therefore the appropriate mechanism when centralized authentication is required for an enterprise WLAN.
Question 355: Which WLAN feature can use a web portal to require a guest user to authenticate or accept terms before receiving normal network access?
- Web authentication
- Dynamic Channel Assignment
- RF Profile
- PMF
Correct Answer: 1. Web authentication
Explanation:
Web authentication provides a browser-based access mechanism commonly used for guest WLANs. A client can associate with the WLAN and be redirected to a web portal where the user may authenticate, accept terms of use, or complete another required process. After the appropriate conditions are satisfied, the user can receive the intended network access. Dynamic Channel Assignment is an RF management function, an RF Profile defines RF parameters for groups of APs, and PMF protects certain management frames. Web authentication is therefore the feature most directly associated with portal-based guest access.
Question 356: Which Cisco wireless feature can provide a common set of RF parameters for a group of access points in a specific deployment environment?
- RF Profile
- AP Group
- Mobility Anchor
- Client Exclusion
Correct Answer: 1. RF Profile
Explanation:
An RF Profile allows administrators to define RF-related parameters that can be applied consistently to a group of access points. Depending on the controller platform and configuration, RF Profiles can be used to tailor settings for deployment environments such as high-density areas, voice-focused locations, or other specialized RF designs. AP Groups instead control WLAN availability for selected APs. Mobility Anchors are used for specific mobility tunnel designs, and Client Exclusion controls access by problematic clients. RF Profiles are therefore useful when administrators need to apply a consistent RF policy to a defined group of access points.
Question 357: Which factor should be considered when selecting an antenna for a wireless access point?
- RADIUS accounting interval
- Antenna radiation pattern and gain
- DHCP lease duration
- DNS record TTL
Correct Answer: 2. Antenna radiation pattern and gain
Explanation:
Antenna selection should consider both gain and radiation pattern because these characteristics determine how RF energy is distributed throughout the coverage area. Omnidirectional antennas generally provide broad horizontal coverage, while directional antennas concentrate energy in a particular direction. Antenna gain also affects the effective radiated power and coverage characteristics of the WLAN. RADIUS accounting intervals, DHCP lease durations, and DNS TTL values do not determine the physical RF coverage pattern. Proper antenna selection is therefore an important part of WLAN design, especially in environments where AP placement, building geometry, and coverage requirements vary significantly.
Question 358: Which Cisco capability provides analytics that can help administrators troubleshoot wireless client experience and network health?
- Wireless Assurance
- DHCP Option 43
- CAPWAP Data
- DFS
Correct Answer: 1. Wireless Assurance
Explanation:
Wireless Assurance provides operational analytics and visibility into wireless infrastructure and client experience. It can help administrators investigate issues such as client onboarding failures, authentication problems, connectivity interruptions, performance degradation, and other WLAN conditions. By correlating information from network components, assurance tools can provide a broader view than examining a single device in isolation. DHCP Option 43 assists with AP controller discovery, CAPWAP Data carries traffic between supported AP and controller deployments, and DFS manages radar-sensitive channels. Wireless Assurance is therefore the capability most directly associated with client-experience analytics and network-health visibility.
Question 359: Which RF condition can significantly reduce wireless performance even when a client has a strong RSSI?
- High channel utilization
- A long DHCP lease
- A low DNS TTL
- A large RADIUS accounting record
Correct Answer: 1. High channel utilization
Explanation:
A strong RSSI indicates that the desired wireless signal is being received at a relatively high level, but it does not indicate that the RF medium is uncongested. High channel utilization means that significant airtime is already occupied by transmissions or other RF activity. This can increase contention and reduce the airtime available to a particular client, resulting in lower effective throughput. DHCP lease duration, DNS TTL, and RADIUS accounting record size do not directly represent RF congestion. When troubleshooting poor throughput despite strong RSSI, channel utilization should therefore be examined along with SNR, interference, retransmissions, and client data rates.
Question 360: Which approach is most appropriate when validating a newly deployed wireless network against its planned RF coverage requirements?
- Change all APs to maximum power without measuring
- Perform a post-deployment wireless site survey
- Disable RRM permanently
- Test only whether clients can obtain DHCP addresses
Correct Answer: 2. Perform a post-deployment wireless site survey
Explanation:
A post-deployment wireless site survey validates whether the implemented WLAN meets the planned RF objectives. Measurements can verify signal strength, SNR, coverage, overlap, channel conditions, interference, and other design requirements across the intended service area. Merely confirming DHCP operation does not establish that the RF design is healthy, while setting every AP to maximum power can create excessive overlap and contention. Disabling RRM is also not a substitute for RF validation. A post-deployment survey provides measured evidence that the physical wireless implementation matches the intended coverage and performance design.