View Full Cisco CCNP 300-425 Exam Dumps and Practice Test Dumps.
Question 241. What does a monitor mode AP primarily do
- Serve wireless clients
- Observe wireless activity without serving clients
- Route branch traffic
- Assign DHCP addresses
Correct Answer: 2. Observe wireless activity without serving clients
Explanation:
A monitor mode access point is dedicated to observing the wireless environment rather than providing normal client access. Cisco describes monitor mode as useful for checking intrusion detection events, identifying rogue access points, tracking wireless stations, and scanning selected channels. Because the AP does not transmit normal client traffic in this mode, it can focus its radio resources on monitoring activities. Monitor mode is therefore appropriate when visibility into the RF environment is more important than providing additional client capacity. The AP can later be returned to a normal client serving mode such as Local or FlexConnect.
Question 242. Which AP mode captures packets and forwards them to a remote analyzer
- Local
- FlexConnect
- Monitor
- Sniffer
Correct Answer: 4. Sniffer
Explanation:
Sniffer mode allows a Cisco access point to capture wireless packets on a selected channel and forward those packets to a remote packet analysis system. This is useful when engineers need detailed frame level visibility while troubleshooting association, authentication, roaming, retransmission, or interference related problems. Cisco supports analyzers such as Wireshark and other compatible tools for reviewing the forwarded packet stream. An AP placed fully into sniffer mode is dedicated to packet capture and does not simultaneously provide ordinary wireless access service, so designers should avoid removing a required coverage AP from service unnecessarily.
Question 243. Which AP mode is the normal default client serving mode
- Local
- Sniffer
- Rogue
- Monitor
Correct Answer: 1. Local
Explanation:
Local mode is the standard default operating mode for a Cisco lightweight access point in a typical centralized wireless deployment. In Local mode, the AP provides a basic service set on its assigned channel and serves wireless clients. When the radio is not actively transmitting client frames, it can briefly scan other channels to measure noise, identify interference, discover rogue devices, and detect certain intrusion events. This combination of normal client service and limited background scanning makes Local mode appropriate for ordinary campus coverage where the AP must primarily provide connectivity rather than operate as a dedicated monitoring sensor.
Question 244. What can monitor mode improve for RFID deployments
- DHCP relay
- Controller software updates
- Location calculation
- Switch stacking
Correct Answer: 3. Location calculation
Explanation:
Cisco identifies improved RFID tag location calculation as one of the purposes of monitor mode. Because a monitor mode AP can concentrate on scanning and receiving wireless activity rather than serving normal clients, it can provide useful observations for location systems. The AP can monitor selected frequencies and contribute information used to determine where wireless tags or stations are located. Accurate location still depends on AP placement, RF conditions, geometry, and the location services platform. Monitor mode therefore enhances the observation side of location design but does not replace proper site planning or accurate access point placement.
Question 245. What does SE Connect mode provide
- DHCP service
- Guest anchoring
- Client roaming
- Detailed spectrum analysis access
Correct Answer: 4. Detailed spectrum analysis access
Explanation:
SE Connect mode is designed for detailed spectrum troubleshooting with Cisco Spectrum Expert and compatible CleanAir enabled access points. It allows the troubleshooting application to connect to the AP and examine spectrum information in greater detail. This can help engineers detect, classify, and locate sources of radio frequency interference in the unlicensed bands. Cisco states that an AP operating in SE Connect mode does not serve normal wireless clients, so the mode should be used for focused troubleshooting rather than ordinary production coverage. It is therefore a diagnostic mode rather than a client access design.
Question 246. Which AP mode is intended for remote wireless service assurance testing
- Bridge
- Sensor
- Rogue
- Local
Correct Answer: 2. Sensor
Explanation:
Sensor mode was introduced as part of Cisco Wireless Service Assurance to help administrators test and monitor wireless service quality, especially at remote facilities where technical staff may not be physically present. A sensor mode AP acts as a test device rather than a normal client serving access point. It can participate in automated assurance workflows that help identify connectivity issues before users report them. This makes sensor mode valuable for proactive validation of wireless service. When normal client access is needed again, the AP can be returned to a client serving mode such as Local or FlexConnect.
Question 247. What does rogue detector mode help identify
- Unauthorized wired connected APs
- DFS radar events
- AP software mismatches
- DHCP failures
Correct Answer: 1. Unauthorized wired connected APs
Explanation:
Rogue detector mode is intended to help determine whether a suspicious wireless access point is connected to the organization’s wired network. A rogue detector AP examines wired network information and helps correlate that activity with rogue wireless devices discovered by the wireless infrastructure. This distinction is important because an unknown AP that is merely visible over the air presents a different risk from an unauthorized AP actually connected to the enterprise LAN. Cisco provides a dedicated rogue AP mode in the Catalyst 9800 platform so administrators can strengthen rogue classification and security monitoring.
Question 248. What can CleanAir report in monitor mode
- User passwords
- DHCP reservations
- Air quality and interference information
- Controller licenses
Correct Answer: 3. Air quality and interference information
Explanation:
When CleanAir is enabled on an access point operating in monitor mode, Cisco can collect air quality and interference detection information for the channels being monitored. This helps administrators understand whether non WiFi energy or other interference sources are degrading the RF environment. Monitor mode can be configured to scan selected channels, Dynamic Channel Assignment channels, or channels allowed by the regulatory domain. CleanAir information complements ordinary 802.11 monitoring because performance problems can be caused by transmitters that are not normal WiFi devices and therefore may not appear in standard WLAN scans.
Question 249. What is the default mode of a Cisco lightweight AP
- Sniffer
- Local
- Rogue
- SE Connect
Correct Answer: 2. Local
Explanation:
Cisco lightweight access points use Local mode as the default operational mode in a standard controller based deployment. In this mode, the access point serves wireless clients on its assigned channel while periodically performing limited scanning activities when it is not transmitting normal client traffic. The scanning process can support rogue detection, noise measurements, interference awareness, and intrusion detection functions. Dedicated modes such as Sniffer, Monitor, Rogue Detector, Sensor, and SE Connect are selected when the AP must perform a more specialized function. Local mode therefore represents the normal production client access role.
Question 250. What happens to normal client service when an entire AP is placed in sniffer mode
- Client throughput doubles
- Clients receive higher priority
- The AP becomes a mobility anchor
- Normal client service stops
Correct Answer: 4. Normal client service stops
Explanation:
A dedicated AP operating in sniffer mode captures wireless traffic instead of providing ordinary client access. Cisco recommends using an AP that is not required for production coverage because changing a needed AP to sniffer mode can create a coverage or capacity gap. The sniffer captures frames on the configured channel and forwards them to a remote analyzer for troubleshooting. Some newer platforms also support radio level sniffer roles on suitable XOR radios, but when the AP itself is configured as a dedicated sniffer, administrators should treat it as a monitoring resource rather than a normal client serving AP.
Question 251. Which analyzer is supported for reviewing Cisco sniffer captures
- Wireshark
- DHCP Manager
- Cisco ISE only
- DNS Manager
Correct Answer: 1. Wireshark
Explanation:
Wireshark is one of the packet analysis tools supported for reviewing traffic captured by Cisco access points operating in sniffer mode. The sniffer AP captures 802.11 frames on a selected channel and sends them toward the remote analyzer. Wireshark can decode the encapsulated packet stream when configured appropriately, allowing engineers to inspect management, control, and data frames in detail. This is especially useful when troubleshooting client association, authentication, roaming, retransmissions, or protocol behavior that cannot be understood from controller counters alone. Sniffer captures provide direct visibility into actual over the air frame exchanges.
Question 252. Which radio type can support different roles on one physical AP
- DHCP radio
- Static radio
- XOR radio
- Anchor radio
Correct Answer: 3. XOR radio
Explanation:
An XOR radio can support different radio roles on supported Cisco access point models. Depending on platform and software capabilities, an XOR radio can operate in client serving, monitor, or sniffer related roles without requiring the entire access point to perform only one dedicated function. This increases deployment flexibility because a multi radio AP can use one radio for client service while another radio performs monitoring or packet capture. Cisco supports XOR radio role capabilities on several Catalyst and earlier enterprise AP families. Designers should verify the exact model and release because available radio roles differ between hardware platforms.
Question 253. What must be used to return a dedicated monitor AP to client serving operation
- DHCP renewal
- AP mode clear
- RF group reset
- Mobility restart
Correct Answer: 2. AP mode clear
Explanation:
Cisco documentation states that the AP mode should be set to Clear when returning a dedicated monitor mode AP to normal client serving operation. After the dedicated mode is cleared, the AP can return to the mode determined by its site tag, such as Local mode for a campus deployment or FlexConnect mode for a remote site. This approach prevents administrators from incorrectly forcing a CAPWAP mode when the site tag already defines the desired production behavior. Correct tagging is therefore important because it determines how the AP resumes normal service after a temporary monitoring role ends.
Question 254. What is the default rogue detection minimum RSSI value
- Negative 70 dBm
- Negative 128 dBm
- Negative 50 dBm
- Negative 80 dBm
Correct Answer: 2. Negative 128 dBm
Explanation:
Cisco documents the default rogue detection minimum RSSI as negative 128 dBm. Administrators can increase this threshold when they want the system to ignore very weak rogue signals that are unlikely to be operationally relevant. Filtering weak detections can reduce noise in environments where many distant neighboring wireless networks are visible. The allowed configuration range extends up to negative 70 dBm. Selecting an appropriate value requires understanding the building and surrounding RF environment because setting the threshold too high could hide a rogue device that is still close enough to pose a meaningful security concern.
Question 255. Which feature helps locate wireless clients with greater accuracy when combined with CMX
- Cisco Hyperlocation
- DHCP Option 43
- AP fallback
- Link aggregation
Correct Answer: 1. Cisco Hyperlocation
Explanation:
Cisco Hyperlocation is designed to improve wireless location accuracy when integrated with Cisco Connected Mobile Experiences. It uses specialized radio information and supported hardware to provide more precise estimates of where wireless clients or devices are located. Cisco documentation notes that supported Hyperlocation hardware can provide substantially better accuracy than conventional RSSI based methods. This capability is useful for asset tracking, location analytics, and context aware services. Accurate floor plans, proper access point placement, and suitable location system integration remain important because location accuracy depends on both RF measurement quality and physical deployment geometry.
Question 256. How accurate can Cisco Hyperlocation tracking become with the WSM2 module
- About twenty meters
- About ten meters
- As close as one meter
- Exactly fifty meters
Correct Answer: 3. As close as one meter
Explanation:
Cisco documentation states that location tracking accuracy with the WSM2 module can be as close as approximately one meter under suitable conditions. The WSM2 combines supported Hyperlocation capabilities with the required antenna components to improve location measurement. Actual results depend on access point placement, RF conditions, floor geometry, client characteristics, and the connected location services platform. The one meter figure should therefore be treated as a best case supported capability rather than a guaranteed result everywhere. Location focused wireless design still requires careful AP density, placement, floor mapping, and validation after deployment.
Question 257. What accuracy range can Hyperlocation Local Mode provide without the specialized radio module
- One to two meters
- Five to seven meters
- Twenty to thirty meters
- Fifty meters
Correct Answer: 2. Five to seven meters
Explanation:
Cisco states that Hyperlocation Local Mode can provide location accuracy in the approximate range of five to seven meters when the dedicated Hyperlocation radio module is not installed. This mode uses access point processing resources to perform the required location functions. It offers a way to improve location capabilities without adding the specialized module, although it does not provide the same potential precision as supported WSM hardware. Designers should choose the appropriate approach according to the business requirement for location accuracy, available hardware, AP density, and expected use cases such as analytics or asset tracking.
Question 258. How many BLE transmitters can the Cisco Hyperlocation module use
- One
- Two
- Three
- Up to five
Correct Answer: 4. Up to five
Explanation:
Cisco Hyperlocation radio modules with integrated Bluetooth Low Energy capability can use up to five BLE transmitters. The Catalyst 9800 controller can configure parameters such as beacon interval, identifier information, and transmit power. This allows wireless infrastructure to support BLE based location and proximity applications in addition to conventional WiFi services. The design can provide more granular beacon information on a per AP basis. BLE planning still requires consideration of signal propagation, beacon density, physical placement, and the application requirements because Bluetooth coverage characteristics differ from normal WiFi radio behavior.
Question 259. What must be connected for Hyperlocation BLE operation according to Cisco documentation
- DHCP server
- Spectrum Expert only
- CMX
- Mobility anchor
Correct Answer: 3. CMX
Explanation:
Cisco states that CMX must be connected for the documented Hyperlocation BLE functionality to operate. The Hyperlocation feature must also be enabled on the controller. The integrated BLE radio can then transmit configured beacon information while the location platform uses the wireless infrastructure to support location related applications. This illustrates why wireless location design involves more than access point hardware alone. Controllers, location platforms, floor maps, beacon settings, and radio placement must work together to provide useful results. A missing integration component can prevent location services from functioning even when the AP radios themselves are operating correctly.
Question 260. What does a monitor mode AP not normally transmit
- Normal WiFi client traffic
- DHCP leases
- Wired routing updates
- RADIUS passwords
Correct Answer: 1. Normal WiFi client traffic
Explanation:
A monitor mode access point does not transmit normal WiFi client traffic because it is dedicated to observing the wireless environment. Cisco specifically notes that monitor mode APs do not transmit normal 802.11 traffic and are excluded from ordinary Radio Resource Management planning. Their primary role is monitoring channels, detecting interference and rogue devices, checking intrusion events, and supporting location functions. This is why a monitor mode AP should be treated as a dedicated sensing resource rather than counted as part of the client serving capacity of the wireless design.