Cisco CCNP Wireless 350-101 Practice Test Questions and Exam Dumps Part 13 Q241-260

View Full Cisco CCNP Wireless 350-101 Exam Dumps and Practice Test Dumps

 

Question 241: Which Cisco AP mode allows client traffic to be switched locally at a remote site while the AP remains centrally managed?

  1. Monitor mode
  2. FlexConnect mode
  3. Sniffer mode
  4. Rogue Detector mode

Correct Answer: 2. FlexConnect mode

Explanation:

FlexConnect mode allows Cisco access points at remote locations to remain managed by a centralized wireless LAN controller while supporting local traffic forwarding. When Local Switching is configured, client traffic can be placed directly onto the branch LAN instead of being tunneled across the WAN to the controller. This can reduce WAN bandwidth consumption and improve resiliency at remote sites. Monitor and Sniffer modes are intended for specialized monitoring and packet capture, while Rogue Detector mode focuses on rogue-device detection. Therefore, FlexConnect mode is appropriate for centrally managed APs that require distributed branch connectivity.

Question 242: Which Cisco wireless feature allows an AP to continue providing locally switched client access when communication with the controller is temporarily lost?

  1. FlexConnect Standalone
  2. CleanAir
  3. RRM
  4. AVC

Correct Answer: 1. FlexConnect Standalone

Explanation:

FlexConnect can allow an appropriately configured remote AP to continue providing certain locally switched WLAN services when connectivity to the central controller is temporarily unavailable. This behavior can improve resiliency at branch locations where WAN or controller connectivity may be interrupted. The exact authentication and WLAN services available during controller loss depend on the deployment and configuration. CleanAir provides RF intelligence, RRM manages radio resources, and AVC provides application visibility and control. Therefore, FlexConnect Standalone operation is the feature associated with maintaining local wireless service during a temporary controller connectivity failure.

Question 243: Which CAPWAP protocol component is used to establish secure control communication between a lightweight AP and its controller?

  1. CAPWAP control channel
  2. CAPWAP data channel
  3. DHCP Option 43
  4. RADIUS Accounting

Correct Answer: 1. CAPWAP control channel

Explanation:

The CAPWAP control channel carries management and control communication between a lightweight access point and its wireless LAN controller. CAPWAP control traffic is protected using DTLS in standard secure CAPWAP operation, helping protect management information exchanged between the AP and controller. The CAPWAP data channel carries client traffic in centralized forwarding deployments. DHCP Option 43 can assist with controller discovery, while RADIUS Accounting provides session information. Therefore, the CAPWAP control channel is the component responsible for secure AP-to-controller control communication.

Question 244: Which AP discovery mechanism can provide controller information to a Cisco lightweight AP through DHCP?

  1. DHCP Option 43
  2. WMM
  3. PMF
  4. 802.11k

Correct Answer: 1. DHCP Option 43

Explanation:

DHCP Option 43 can provide vendor-specific controller discovery information to Cisco lightweight access points. After obtaining an IP address through DHCP, an AP can use the information supplied in Option 43 to identify potential wireless LAN controllers and begin the discovery process. WMM provides wireless QoS, PMF protects supported management frames, and 802.11k provides radio measurement information. Therefore, DHCP Option 43 is the mechanism specifically associated with providing controller discovery information to a Cisco lightweight AP through DHCP.

Question 245: Which authentication architecture uses a wireless client, authenticator, and authentication server as its three primary roles?

  1. 802.1X
  2. WPA2-Personal
  3. Open Authentication
  4. Static WEP

Correct Answer: 1. 802.1X

Explanation:

IEEE 802.1X defines an access-control architecture involving three primary roles: the supplicant, authenticator, and authentication server. The wireless client acts as the supplicant, the AP or controller performs the authenticator role, and a RADIUS server commonly acts as the authentication server. This architecture enables centralized authentication and authorization policies. WPA2-Personal instead relies on a shared key, while Open Authentication and legacy static WEP do not provide the same centralized three-role authentication architecture. Therefore, 802.1X is the technology that uses these three primary roles.

Question 246: Which RADIUS attribute can be used to communicate the VLAN or group information assigned to an authenticated wireless user?

  1. User-Name
  2. Tunnel-Private-Group-ID
  3. NAS-IP-Address
  4. Acct-Session-Id

Correct Answer: 2. Tunnel-Private-Group-ID

Explanation:

The RADIUS Tunnel-Private-Group-ID attribute can be used as part of dynamic VLAN assignment information returned by the authentication server. In an appropriately configured Cisco wireless environment, the RADIUS server can return authorization attributes that allow authenticated clients to be placed into a particular VLAN according to policy. User-Name identifies the user, NAS-IP-Address identifies the network access server, and Acct-Session-Id is associated with accounting records. Therefore, Tunnel-Private-Group-ID is the RADIUS attribute most directly associated with communicating the private group or VLAN assignment.

Question 247: Which Cisco wireless component determines which WLANs are advertised by a particular group of access points?

  1. AP Group
  2. RF Group
  3. Mobility Anchor
  4. RRM

Correct Answer: 1. AP Group

Explanation:

An AP Group allows administrators to control which WLANs are associated with selected access points. This is useful in environments where different buildings, floors, departments, or locations should advertise different WLANs. RF Groups are associated with coordinated RF management, Mobility Anchors support mobility traffic termination, and RRM manages radio resources. AP Groups therefore provide a mechanism for organizing access points and associating specific WLAN configurations with those APs. This can reduce unnecessary WLAN advertisements and help tailor wireless services to different areas of an organization.

Question 248: Which wireless security method uses SAE to establish authentication for a password-based personal WLAN?

  1. WPA2-Enterprise
  2. WPA3-Personal
  3. PEAP
  4. EAP-TLS

Correct Answer: 2. WPA3-Personal

Explanation:

WPA3-Personal uses Simultaneous Authentication of Equals (SAE) for password-based authentication. SAE replaces the traditional WPA2-Personal PSK authentication approach and provides stronger protection against offline password-guessing attacks. WPA2-Enterprise uses 802.1X, while PEAP and EAP-TLS are enterprise EAP authentication methods. Therefore, WPA3-Personal is the security mode associated with SAE. Understanding this distinction is important when comparing personal and enterprise wireless authentication architectures.

Question 249: Which feature can provide wireless clients with network-assisted recommendations to transition from one BSS to another?

  1. 802.11v
  2. 802.11r
  3. 802.11k
  4. 802.11w

Correct Answer: 1. 802.11v

Explanation:

IEEE 802.11v provides network-assisted management capabilities, including BSS Transition Management. A network can use supported 802.11v mechanisms to provide a client with information or recommendations regarding potential transition candidates. 802.11k focuses on radio measurements and Neighbor Reports, while 802.11r provides Fast BSS Transition to reduce roaming authentication delay. 802.11w provides management-frame protection. Therefore, 802.11v is the amendment most directly associated with network-assisted BSS transition recommendations.

Question 250: Which wireless metric indicates how much the desired signal exceeds the measured noise level?

  1. Channel width
  2. SNR
  3. EIRP
  4. BSSID

Correct Answer: 2. SNR

Explanation:

Signal-to-Noise Ratio (SNR) describes the relationship between the desired wireless signal and the surrounding noise level. A higher SNR generally indicates that the receiver has a clearer distinction between the intended signal and background RF noise. Channel width describes the amount of spectrum used by a transmission, EIRP describes effective radiated power, and BSSID identifies a specific wireless BSS. SNR is therefore the metric that most directly indicates how strongly the desired signal stands above the measured noise level and is an important indicator of RF quality.

Question 251: Which Cisco wireless feature can provide application visibility and allow administrators to identify applications consuming network resources?

  1. AVC
  2. PMF
  3. RF Profile
  4. CAPWAP Discovery

Correct Answer: 1. AVC

Explanation:

Application Visibility and Control (AVC) provides visibility into application traffic and can help administrators understand how network resources are being consumed. Depending on the platform and configuration, AVC can also support application-aware control and policy functions. PMF protects supported management frames, RF Profiles define radio parameters, and CAPWAP Discovery helps APs locate controllers. Therefore, AVC is the Cisco wireless capability most directly associated with identifying applications and providing application-level visibility into network traffic.

Question 252: Which Cisco feature can help identify a wireless device that is connected to the wired network but is also operating as a rogue access point?

  1. RRM
  2. Rogue Detector
  3. TWT
  4. WMM

Correct Answer: 2. Rogue Detector

Explanation:

A Rogue Detector is designed to help identify rogue access points by correlating information observed in the wireless environment with information available from the wired network. This can help administrators determine whether a detected wireless device is connected to the organization’s wired infrastructure. RRM manages radio resources, TWT coordinates client wake periods, and WMM provides wireless QoS. Rogue AP detection is an important wireless security function because unauthorized access points can create security and connectivity risks. Therefore, Rogue Detector functionality is the appropriate choice for this scenario.

Question 253: Which wireless attack commonly uses forged deauthentication frames to forcibly disconnect clients from an access point?

  1. DHCP starvation
  2. Deauthentication attack
  3. DNS poisoning
  4. ARP inspection

Correct Answer: 2. Deauthentication attack

Explanation:

A deauthentication attack uses forged or maliciously generated deauthentication frames to force wireless clients to disconnect from an access point. If management frames are not adequately protected, an attacker may exploit this behavior to disrupt connectivity or facilitate other attacks. Protected Management Frames can help protect supported management traffic against certain forged-frame attacks. DHCP starvation targets address allocation, DNS poisoning targets name-resolution information, and ARP inspection addresses Layer 2 address-security issues. Therefore, the attack described is a deauthentication attack.

Question 254: Which wireless security feature is specifically designed to protect management frames against spoofing?

  1. PMF
  2. WMM
  3. OFDMA
  4. RRM

Correct Answer: 1. PMF

Explanation:

Protected Management Frames (PMF) provide security for supported IEEE 802.11 management frames. PMF can help prevent attackers from successfully using forged management messages such as deauthentication and disassociation frames to disrupt wireless connectivity. WMM is designed for wireless QoS, OFDMA improves spectrum efficiency by using resource units, and RRM manages radio resources. Therefore, PMF is the feature specifically associated with protecting supported management frames against spoofing and certain forms of wireless disruption.

Question 255: Which Wi-Fi 6 feature can improve spectrum efficiency by allowing multiple clients to transmit or receive using different resource units within a channel?

  1. OFDMA
  2. PMF
  3. 802.11r
  4. TWT

Correct Answer: 1. OFDMA

Explanation:

Orthogonal Frequency-Division Multiple Access (OFDMA) divides a wireless channel into smaller resource units that can be allocated to different clients. This enables more efficient use of available spectrum, particularly when many clients have smaller amounts of data to transmit or receive. TWT focuses on coordinated wake and sleep periods, PMF provides management-frame protection, and 802.11r improves roaming performance. Therefore, OFDMA is the Wi-Fi 6 technology most directly associated with assigning different resource units within a channel to multiple clients.

Question 256: Which Cisco platform capability provides centralized analytics and visibility into wireless client experience and infrastructure health?

  1. Wireless Assurance
  2. DHCP Option 43
  3. CAPWAP Data Channel
  4. RADIUS Accounting

Correct Answer: 1. Wireless Assurance

Explanation:

Wireless Assurance provides centralized analytics and operational visibility for wireless infrastructure and clients. It can use telemetry and collected network information to help administrators understand client connectivity, RF conditions, performance, and infrastructure health. DHCP Option 43 assists with controller discovery, the CAPWAP data channel transports client traffic in centralized architectures, and RADIUS Accounting provides session-related accounting information. Therefore, Wireless Assurance is the capability most directly associated with centralized analysis of wireless client experience and infrastructure health.

Question 257: Which RF condition occurs when multiple access points use the same channel and their coverage areas overlap?

  1. Co-channel interference
  2. DNS interference
  3. Authentication overlap
  4. DHCP interference

Correct Answer: 1. Co-channel interference

Explanation:

When multiple access points use the same RF channel and their coverage areas overlap, devices may need to contend for access to the same wireless medium. This condition is commonly described as co-channel interference or, more precisely in many WLAN contexts, co-channel contention. Proper channel reuse and cell-size planning are important for controlling the impact of same-channel deployments. DNS and DHCP do not describe RF overlap conditions, and authentication overlap is not an RF interference category. Therefore, overlapping AP coverage on the same channel is associated with co-channel contention.

Question 258: Which Cisco wireless feature helps detect unauthorized access points operating within or near the WLAN environment?

  1. RRM
  2. Rogue AP Detection
  3. WMM
  4. TWT

Correct Answer: 2. Rogue AP Detection

Explanation:

Rogue AP Detection helps identify unauthorized wireless access points detected by the wireless infrastructure. Administrators can use information about detected devices to investigate potential security risks and determine whether an access point is connected to the organization’s network or operating externally. RRM focuses on radio resource management, WMM provides traffic prioritization, and TWT coordinates client activity and power saving. Rogue access points can introduce security vulnerabilities and RF interference, making detection an important component of wireless security monitoring. Therefore, Rogue AP Detection is the appropriate feature.

Question 259: Which RF design principle is especially important when deploying WLANs in a high-density environment?

  1. Maximize transmit power on every AP
  2. Use the widest available channels everywhere
  3. Carefully manage channel reuse and cell size
  4. Disable all neighboring APs

Correct Answer: 3. Carefully manage channel reuse and cell size

Explanation:

High-density wireless deployments require careful management of available airtime and RF spectrum. Appropriate channel reuse and cell sizing help prevent excessive co-channel contention and make better use of the available channels. Increasing transmit power indiscriminately can create overly large cells and increase contention, while using very wide channels everywhere can reduce the number of channels available for reuse. Therefore, careful channel reuse and cell-size management are fundamental design principles for high-density WLANs.

Question 260: Which Cisco technology dynamically manages RF conditions, while an RF Profile provides configured radio parameters for a group of APs?

  1. RRM and RF Profile
  2. WMM and PMF
  3. AVC and DHCP Proxy
  4. CAPWAP and RADIUS

Correct Answer: 1. RRM and RF Profile

Explanation:

RRM dynamically evaluates RF conditions and can adjust radio parameters such as channel assignment and transmit power based on network conditions. An RF Profile, in contrast, provides configured radio settings and policy parameters that can be applied to groups of access points operating in a particular RF environment. The two functions therefore complement each other: RRM provides dynamic RF management, while RF Profiles establish configured radio behavior and constraints. WMM, PMF, AVC, DHCP Proxy, CAPWAP, and RADIUS perform different wireless networking functions. Therefore, RRM and RF Profile correctly describe the relationship.