Cisco CCNP 300-425 Practice Test Questions and Exam Dumps Part18 Q341-360

View Full Cisco CCNP 300-425 Exam Dumps and Practice Test Dumps.


Question 341. What must the FlexConnect native VLAN match

  1. Client SSID
  2. Controller management VLAN
  3. Switch port native VLAN
  4. RADIUS VLAN

Correct Answer: 3. Switch port native VLAN

Explanation:

The native VLAN configured in the Flex profile must match the native VLAN configured on the switch port where the FlexConnect access point is connected. Cisco recommends using an 802.1Q trunk for FlexConnect AP connectivity when locally switched WLANs require several VLANs. A mismatch between the AP native VLAN and the switch native VLAN can cause connectivity and management problems. Cisco also recommends keeping the native VLAN consistent across access points that belong to the same physical site and site tag.

Question 342. Which site tag option is disabled to place an AP in FlexConnect mode

  1. Enable Local Site
  2. Central DHCP
  3. AAA Override
  4. Client Steering

Correct Answer: 1. Enable Local Site

Explanation:

To configure access points for FlexConnect operation, the site tag should have Enable Local Site disabled and should reference the appropriate Flex profile. This tells the Catalyst 9800 that the AP belongs to a remote or FlexConnect site rather than a normal local site. After a new site tag is applied, the AP can reset its CAPWAP relationship and rejoin the controller with the new operating characteristics. The Flex profile then supplies site specific settings such as native VLAN configuration, local VLAN mappings, authentication information, and other branch related parameters.

Question 343. How can a locally switched FlexConnect VLAN be specified without creating that VLAN globally on the controller

  1. Use a DNS name
  2. Use a policy ACL
  3. Use a mobility anchor
  4. Enter the VLAN ID directly

Correct Answer: 4. Enter the VLAN ID directly

Explanation:

For a locally switched FlexConnect WLAN, administrators can enter the VLAN ID directly in the wireless policy profile. Cisco notes that the VLAN does not need to exist globally on the controller when it is used only for local switching at the remote site. The VLAN information is pushed to the FlexConnect AP, which locally bridges client traffic into the corresponding branch VLAN. This approach is convenient when different branch sites use straightforward local VLAN numbering and do not need a globally defined controller VLAN for that client traffic.

Question 344. Where is a VLAN name mapped to a local VLAN number for FlexConnect

  1. RF profile
  2. Flex profile
  3. AP join profile
  4. Mobility group

Correct Answer: 2. Flex profile

Explanation:

When a locally switched WLAN uses a VLAN name instead of directly using a VLAN number, the site specific mapping between that VLAN name and the actual branch VLAN ID is configured in the Flex profile. This allows the same logical policy to be reused while different sites can map that policy to the appropriate local VLAN number. Cisco notes that the VLAN name must be created globally and the Flex profile must supply the corresponding local mapping. This is particularly useful in distributed deployments where branch VLAN numbering differs between sites.

Question 345. Which FlexConnect state works in both connected and standalone modes

  1. Central authentication with central switching
  2. Central authentication with local switching
  3. Local authentication with central switching
  4. Local authentication with local switching

Correct Answer: 4. Local authentication with local switching

Explanation:

Local authentication with local switching can operate while the FlexConnect AP is connected to the controller and while it is operating in standalone mode after losing controller connectivity. In this design, the AP performs local client authentication and also bridges client data directly into the branch network. This reduces dependency on the WAN and centralized controller for essential branch wireless service. Cisco contrasts this behavior with central authentication modes, which require controller connectivity because authentication processing depends on the centralized controller path.

Question 346. Which FlexConnect mode requires controller connectivity

  1. Local authentication with local switching
  2. Central authentication with local switching
  3. Standalone local authentication
  4. Local switching only

Correct Answer: 1. Central authentication with local switching

Explanation:

Central authentication with local switching requires the FlexConnect AP to remain connected to the wireless controller. In this mode, the controller manages client authentication while the AP locally bridges client data after authentication succeeds. Cisco states that this state is valid only in connected mode because the controller must participate in the authentication process. If WAN or controller connectivity is lost, new clients cannot rely on that centralized authentication workflow. Branches that need authentication survivability during outages should consider supported local authentication designs instead.

Question 347. Who switches client data in central authentication with local switching

  1. RADIUS server
  2. Wireless controller
  3. FlexConnect AP
  4. DHCP server

Correct Answer: 3. FlexConnect AP

Explanation:

In central authentication with local switching, the controller handles the client’s authentication process, but the FlexConnect access point switches the user’s data locally. After authentication succeeds, the controller informs the AP that the client is authorized and the AP begins forwarding the client traffic into the local branch network. This design preserves centralized authentication policy while avoiding the need to tunnel all normal application data across the WAN. It is useful for branches with reliable controller connectivity but where local data forwarding provides better efficiency and application access.

Question 348. Who authenticates clients in FlexConnect local authentication mode

  1. DNS server
  2. Access point
  3. Mobility anchor
  4. RF leader

Correct Answer: 2. Access point

Explanation:

With FlexConnect local authentication, the access point participates directly in authenticating wireless clients instead of requiring every authentication exchange to traverse the WAN to the controller. Cisco supports configurations where the AP communicates with a local RADIUS server at the remote site. Combined with local switching, this design improves branch survivability because authentication and data forwarding can continue locally when controller connectivity is unavailable. The Flex profile contains site specific local authentication settings such as the RADIUS server group used by the FlexConnect AP.

Question 349. What does VLAN based central switching do when a client VLAN is not available locally on the AP

  1. Redirects traffic to the controller
  2. Deletes the WLAN
  3. Reboots the AP
  4. Changes the client SSID

Correct Answer: 1. Redirects traffic to the controller

Explanation:

VLAN based central switching provides a fallback mechanism for FlexConnect deployments when a VLAN assigned to a client is not defined locally on the AP. Instead of simply dropping the traffic, the wireless infrastructure can redirect the client’s traffic toward the controller for centralized switching. This is especially useful when an AAA server dynamically assigns VLANs and a particular branch does not locally support every possible VLAN. The feature therefore provides additional flexibility for distributed enterprise authorization policies while preserving connectivity for clients assigned to unsupported local VLANs.

Question 350. What must exist on the controller for VLAN based central switching

  1. A sniffer profile
  2. A sensor profile
  3. A bridge group
  4. The corresponding VLAN

Correct Answer: 4. The corresponding VLAN

Explanation:

For VLAN based central switching to work, the VLAN to which traffic is redirected must be defined on the wireless controller. The controller becomes responsible for centrally forwarding traffic when the required VLAN is not available locally on the FlexConnect AP. If the corresponding controller VLAN does not exist, the controller cannot properly provide the centralized data path. Designers using dynamic VLAN assignment should therefore coordinate branch VLAN definitions with controller VLAN configuration when VLAN based central switching is part of the intended fallback design.

Question 351. Which feature is not supported with VLAN based central switching

  1. 802.1X
  2. MAC filter
  3. AAA override
  4. Local switching

Correct Answer: 2. MAC filter

Explanation:

Cisco states that VLAN based central switching is not supported with MAC filter authentication. VLAN based central switching is designed to redirect traffic to the controller when an assigned VLAN is unavailable locally at the FlexConnect AP. Although it supports important distributed authorization scenarios, not every authentication method can be combined with the feature. Designers should verify feature compatibility whenever multiple FlexConnect functions are combined because branch WLAN behavior can differ significantly depending on authentication, switching, VLAN assignment, and controller connectivity choices.

Question 352. What is the purpose of an OfficeExtend AP

  1. Extend the corporate WLAN to a remote home office
  2. Replace the enterprise controller
  3. Detect DFS radar only
  4. Provide outdoor mesh backhaul only

Correct Answer: 3. Extend the corporate WLAN to a remote home office

Explanation:

Cisco OfficeExtend allows an enterprise access point located at an employee residence or other remote site to securely extend the corporate wireless network across the Internet. The employee can connect to enterprise WLAN services with an experience similar to being physically located in the corporate office. The AP maintains a secure relationship with the centralized wireless controller, which can be located in a protected enterprise or DMZ environment. OfficeExtend is particularly useful for remote workers who require consistent corporate wireless access without deploying a complete branch network architecture.

Question 353. What secures communication between an OfficeExtend AP and the controller

  1. WEP
  2. GRE only
  3. Telnet
  4. DTLS

Correct Answer: 4. DTLS

Explanation:

Cisco OfficeExtend uses DTLS to secure communications between the remote access point and the wireless controller. The OfficeExtend AP may operate across an untrusted Internet connection, making encrypted control and data communication essential for enterprise security. DTLS protects the CAPWAP relationship and allows the remote AP to provide corporate WLAN access without exposing internal wireless traffic directly to the public network. Designers must also make sure required controller addressing, firewall, NAT, and Internet reachability are available so the remote AP can successfully establish the secure connection.

Question 354. Which AP operating mode is used as the base for OfficeExtend on Catalyst 9800

  1. FlexConnect
  2. Monitor
  3. Sniffer
  4. Sensor

Correct Answer: 1. FlexConnect

Explanation:

OfficeExtend functionality on the Catalyst 9800 is based on FlexConnect operation. Cisco documentation describes OfficeExtend as an option available to a FlexConnect AP that adds features intended for remote home office deployments. FlexConnect already supports operation across WAN connections and allows per WLAN decisions about local or central traffic forwarding. OfficeExtend extends that model with additional remote worker capabilities such as personal local SSIDs and split tunneling. This makes FlexConnect the architectural foundation for OfficeExtend rather than dedicated monitoring modes such as Sniffer or Sensor.

Question 355. What does OfficeExtend split tunneling determine

  1. AP channel width
  2. Controller software version
  3. Client transmit power
  4. Which traffic is local and which traffic is centralized

Correct Answer: 4. Which traffic is local and which traffic is centralized

Explanation:

OfficeExtend split tunneling provides granular control over how traffic from a remote wireless client is forwarded. Administrators can define which destinations should be accessed directly through the local home network and which traffic must be sent through the secure tunnel toward the enterprise wireless controller. This can reduce unnecessary bandwidth consumption across the corporate tunnel while maintaining centralized handling for protected enterprise resources. Cisco implements the design with traffic policy and access control definitions associated with the OfficeExtend and FlexConnect configuration.

Question 356. What is the main benefit of AP image predownload

  1. Change antenna gain
  2. Reduce upgrade outage time
  3. Increase controller licenses
  4. Create mobility tunnels

Correct Answer: 2. Reduce upgrade outage time

Explanation:

AP image predownload sends the software image required for a controller upgrade to access points before the actual activation occurs. The AP continues operating while the image is downloaded, so the image transfer itself does not require the AP to stop serving clients. After the controller is upgraded, the AP already has the matching software available and can switch to that image rather than spending additional time downloading it. Cisco recommends AP predownload as a way to reduce wireless service disruption during planned controller software upgrades.

Question 357. What can an AP do after a controller upgrade when its new image was predownloaded

  1. Join and register more quickly
  2. Change its physical antenna
  3. Become a controller
  4. Skip CAPWAP permanently

Correct Answer: 1. Join and register more quickly

Explanation:

When the required upgrade image has already been downloaded to an AP, the access point does not need to spend additional time retrieving that image after the controller upgrade. It can boot the appropriate software and proceed directly through discovery and registration with the upgraded controller. Cisco describes this as one of the main benefits of image predownload because older workflows required an AP to discover the upgraded controller, download the new image, reload again, and then repeat discovery. Predownload eliminates that extra image transfer stage during the outage window.

Question 358. How many AP image predownloads are supported per WNCD instance in the referenced Cisco guidance

  1. 25
  2. 50
  3. 100
  4. 500

Correct Answer: 2. 100

Explanation:

Cisco documentation for Catalyst 9800 image predownload identifies a supported limit of up to 100 access point image predownloads per WNCD instance on the controller. The WNCD process is responsible for portions of wireless access point and client control processing. Upgrade planning therefore needs to account for controller scale and process distribution rather than attempting to transfer images to an unlimited number of access points at once. Large environments should monitor predownload status carefully and verify that all intended APs successfully receive the required image before the controller software activation begins.

Question 359. What is the default staggered AP upgrade percentage documented by Cisco

  1. 25 percent
  2. 5 percent
  3. 15 percent
  4. 50 percent

Correct Answer: 3. 15 percent

Explanation:

Cisco documents 15 percent as the default percentage of access points selected per iteration in a staggered rolling AP upgrade. Instead of reloading every AP simultaneously, the controller upgrades smaller groups so neighboring access points can continue serving clients while each group is unavailable. Administrators can select different supported percentages according to coverage density, upgrade duration, and disruption tolerance. A smaller percentage reduces the number of APs unavailable at one time but increases the overall duration of the upgrade. Proper RF overlap is important for a successful rolling upgrade strategy.

Question 360. Which APs does rolling upgrade prioritize for upgrade first

  1. APs with the most clients
  2. Anchor APs only
  3. Highest power APs
  4. APs without clients

Correct Answer: 3. APs without clients

Explanation:

Cisco rolling AP upgrade logic attempts to upgrade access points without connected clients before selecting APs that are actively serving clients. This reduces user disruption because idle APs can be reloaded without forcing client devices to roam. When APs with clients must eventually be upgraded, client steering can help move compatible clients toward neighboring APs before the selected AP reloads. The overall upgrade process also selects AP groups according to neighbor information so too many nearby access points are not normally taken offline at the same time.