Cisco CCNP Wireless 350-101 Practice Test Questions and Exam Dumps Part 19 Q361-380

View Full Cisco CCNP Wireless 350-101 Exam Dumps and Practice Test Dumps

 

Question 361: Which AP operating mode allows a Cisco access point to serve wireless clients while using the controller for centralized management and forwarding client traffic through CAPWAP?

  1. Monitor mode
  2. Sniffer mode
  3. Local mode
  4. Rogue Detector mode

Correct Answer: 3. Local mode

Explanation:
Local mode is the traditional controller-based operating mode for Cisco lightweight access points. In this mode, the AP maintains a CAPWAP relationship with the wireless LAN controller, receives its configuration from the controller, and normally tunnels client data through the CAPWAP data channel to the controller. Monitor mode is used primarily for wireless monitoring and security functions, while Sniffer mode is intended for packet capture. Rogue Detector mode focuses on identifying rogue devices from the wired network. Local mode is therefore the appropriate operating mode when an AP is expected to provide normal client service under centralized controller management.

Question 362: Which Cisco wireless mechanism can help an AP locate controllers by resolving a controller-related DNS hostname?

  1. DHCP Snooping
  2. DNS discovery
  3. WMM
  4. RADIUS accounting

Correct Answer: 2. DNS discovery

Explanation:
Cisco access points can use DNS-based discovery as one of several methods for locating a wireless LAN controller. When the appropriate DNS information is available, the AP can resolve the configured controller-related hostname and obtain an IP address for potential controller communication. This method can be useful in deployments where DHCP Option 43 is not being used or where DNS-based discovery is preferred. DHCP Snooping is a Layer 2 security feature, WMM provides wireless QoS, and RADIUS accounting records session information. DNS discovery is therefore the mechanism associated with locating a controller through DNS resolution.

Question 363: Which CAPWAP mechanism protects the control channel between a Cisco AP and controller from unauthorized modification and interception?

  1. DTLS
  2. WPA2-Personal
  3. WMM
  4. DHCP Proxy

Correct Answer: 1. DTLS

Explanation:
Datagram Transport Layer Security, or DTLS, is used to protect CAPWAP control communication between a Cisco access point and wireless LAN controller. It provides security services such as confidentiality and integrity for the control channel. This helps prevent unauthorized parties from reading or modifying sensitive control information exchanged between the AP and controller. WPA2-Personal protects WLAN client access, WMM provides QoS, and DHCP Proxy assists with DHCP processing. Understanding DTLS is important when troubleshooting CAPWAP connectivity and security because the control relationship depends on successful establishment of the protected control channel.

Question 364: Which Cisco feature can apply different RF settings to access points based on deployment characteristics such as high density or voice requirements?

  1. RF Profile
  2. AP Group
  3. Mobility Group
  4. Dynamic VLAN

Correct Answer: 1. RF Profile

Explanation:
An RF Profile allows administrators to define and apply a set of radio-frequency parameters to a selected group of access points. Different RF Profiles can be designed for environments with different requirements, such as high-density user areas, voice deployments, or other specialized coverage conditions. An AP Group controls WLAN availability, while a Mobility Group establishes relationships between controllers for mobility operations. Dynamic VLAN assignment is associated with client network segmentation. RF Profiles therefore provide a mechanism for tailoring RF behavior according to the characteristics and requirements of a deployment area.

Question 365: Which Cisco RRM feature evaluates RF conditions and can automatically change an AP’s operating channel?

  1. Dynamic VLAN Assignment
  2. Client Exclusion
  3. Dynamic Channel Assignment
  4. Web Authentication

Correct Answer: 3. Dynamic Channel Assignment

Explanation:
Dynamic Channel Assignment, or DCA, is an RRM function that evaluates RF conditions and selects appropriate operating channels for access points. The process can consider factors such as interference, channel utilization, neighboring APs, and other RF measurements. The objective is to maintain effective channel use and reduce undesirable interference. Dynamic VLAN Assignment deals with client segmentation, Client Exclusion controls access by selected clients, and Web Authentication provides portal-based access. DCA is therefore the RRM capability directly responsible for automated RF channel selection and adjustment.

Question 366: Which authentication component acts as the supplicant in a typical 802.1X wireless architecture?

  1. RADIUS server
  2. Wireless client
  3. Wireless controller
  4. DHCP server

Correct Answer: 2. Wireless client

Explanation:
In a typical 802.1X wireless architecture, the wireless client acts as the supplicant. The supplicant requests access to the network and participates in the EAP authentication exchange. The access point or wireless controller performs the authenticator role, controlling access to the WLAN and relaying authentication information to the RADIUS authentication server. The RADIUS server performs authentication and authorization based on the configured policies and credentials. DHCP provides IP addressing after network access is established and is not an 802.1X role. Understanding these three primary roles is essential when troubleshooting enterprise WLAN authentication.

Question 367: Which RADIUS response indicates that the authentication server has accepted a client’s authentication request?

  1. Access-Reject
  2. Accounting-Request
  3. Access-Accept
  4. Accounting-Response

Correct Answer: 3. Access-Accept

Explanation:
A RADIUS Access-Accept message indicates that the RADIUS server has accepted the authentication request and authorizes the network access device to permit the client, subject to the returned policies and attributes. An Access-Reject indicates that authentication or authorization was denied. Accounting-Request and Accounting-Response messages are associated with RADIUS accounting rather than the initial authentication decision. In an enterprise WLAN, the controller or AP receives the Access-Accept and can then apply relevant authorization attributes, such as VLAN assignment or session policies. Access-Accept is therefore the RADIUS response indicating successful authorization.

Question 368: Which Cisco wireless feature can help maintain WLAN availability at a remote site by allowing local client authentication when controller connectivity is lost?

  1. FlexConnect Local Authentication
  2. CleanAir
  3. RF Group
  4. Mobility Anchor

Correct Answer: 1. FlexConnect Local Authentication

Explanation:
FlexConnect Local Authentication can allow supported remote-site deployments to authenticate clients locally when the AP loses connectivity with its central controller. This capability can improve resiliency because clients do not necessarily have to depend on a continuously available controller connection for authentication. FlexConnect Local Switching can also keep client data traffic at the remote site. CleanAir focuses on RF interference, RF Groups coordinate RF management, and Mobility Anchors support specific mobility tunnel designs. FlexConnect Local Authentication is therefore the feature most directly associated with maintaining authentication availability during controller connectivity interruptions.

Question 369: Which wireless security method uses SAE for password-based authentication?

  1. WPA3-Personal
  2. WPA2-Enterprise
  3. WPA2-Personal
  4. Open System

Correct Answer: 1. WPA3-Personal

Explanation:
WPA3-Personal uses Simultaneous Authentication of Equals, or SAE, for password-based WLAN authentication. SAE improves resistance to certain offline password-guessing attacks compared with the traditional WPA2-Personal PSK mechanism. WPA2-Enterprise normally uses 802.1X and an authentication server, while WPA2-Personal uses a pre-shared key. Open System authentication does not provide comparable password-based security. WPA3-Personal is therefore the wireless security method directly associated with SAE and is an important security option for compatible modern WLAN clients and infrastructure.

Question 370: Which Cisco wireless feature can provide a logical relationship between controllers to support client mobility across controller boundaries?

  1. Mobility Group
  2. AP Group
  3. RF Profile
  4. CleanAir

Correct Answer: 1. Mobility Group

Explanation:
A Mobility Group allows Cisco wireless controllers to establish mobility relationships and exchange information needed to support client roaming across controller boundaries. This architecture can help maintain client state and facilitate appropriate mobility behavior when a client moves between APs managed by different controllers. AP Groups control WLAN availability on selected APs, RF Profiles define radio-management parameters, and CleanAir provides enhanced RF interference visibility. Mobility Groups therefore provide the controller-level framework for mobility communication and roaming in a multi-controller Cisco wireless deployment.

Question 371: Which Cisco wireless feature is designed to optimize multicast delivery by converting or selectively forwarding multicast traffic for wireless clients?

  1. Multicast optimization
  2. Client Exclusion
  3. Dynamic Channel Assignment
  4. PMF

Correct Answer: 1. Multicast optimization

Explanation:
Multicast optimization can improve wireless efficiency by handling multicast traffic in a way that reduces unnecessary airtime consumption or adapts delivery to wireless client requirements, depending on the Cisco platform and configured feature. Wireless multicast can consume significant airtime because it is commonly transmitted using conservative rates to accommodate clients with different capabilities and conditions. Optimizing multicast delivery can therefore help preserve valuable RF airtime. Client Exclusion addresses client access, DCA manages channels, and PMF protects management frames. Multicast optimization is consequently the feature most directly associated with improving multicast efficiency on WLANs.

Question 372: Which measurement is most useful for determining whether a wireless client has enough signal quality for reliable communication rather than simply strong signal strength?

  1. BSSID
  2. SNR
  3. VLAN ID
  4. DHCP lease duration

Correct Answer: 2. SNR

Explanation:
SNR provides a more meaningful indication of signal quality than signal strength alone because it compares the desired signal with the background noise level. A client can have strong RSSI but still experience poor performance if the noise floor is also high. A healthy SNR generally indicates that the receiver has sufficient separation between the desired signal and background noise. BSSID identifies a wireless network, VLAN ID identifies network segmentation, and DHCP lease duration controls address assignment behavior. SNR is therefore an important measurement when evaluating whether RF conditions are suitable for reliable wireless communication.

Question 373: Which Cisco capability provides centralized analytics for investigating wireless client onboarding and connectivity problems?

  1. DFS
  2. Wireless Assurance
  3. DHCP Proxy
  4. CAPWAP Data

Correct Answer: 2. Wireless Assurance

Explanation:
Wireless Assurance provides centralized analytics and visibility into wireless infrastructure and client experience. It can help administrators investigate issues involving onboarding, authentication, connectivity, performance, and other operational conditions by correlating information collected from the WLAN environment. DFS is associated with radar-sensitive channel management, DHCP Proxy assists with DHCP processing, and CAPWAP Data transports traffic in controller-based deployments. Wireless Assurance is therefore the capability most directly associated with analyzing client experience and identifying potential causes of WLAN problems through centralized operational visibility.

Question 374: What is the primary reason for using 20-MHz channels in a dense 2.4 GHz WLAN?

  1. To maximize channel reuse
  2. To increase the number of simultaneous SSIDs
  3. To eliminate the need for RRM
  4. To guarantee higher client data rates

Correct Answer: 1. To maximize channel reuse

Explanation:
The 2.4 GHz band provides limited usable spectrum, so using 20-MHz channels helps maximize opportunities for channel reuse. In common deployments, channels 1, 6, and 11 are selected because they can operate without overlapping when configured appropriately. Wider channels consume more spectrum and can reduce the number of usable channel assignments, which can increase contention in dense environments. Channel width alone does not guarantee higher client throughput because performance also depends on signal quality, interference, client capabilities, and airtime availability. Twenty-megahertz channels are therefore commonly preferred when efficient channel reuse is the priority in dense 2.4 GHz deployments.

Question 375: Which IEEE amendment provides network-assisted recommendations that can help a client transition to another BSS?

  1. 802.11w
  2. 802.11k
  3. 802.11v
  4. 802.11r

Correct Answer: 3. 802.11v

Explanation:
IEEE 802.11v provides mechanisms that allow the WLAN infrastructure to assist capable clients with network-directed BSS transitions. BSS Transition Management can provide recommendations about neighboring access points and help influence a client toward a more appropriate BSS. 802.11k provides neighbor and radio measurement information, 802.11r focuses on fast secure transitions, and 802.11w provides Protected Management Frames. These technologies can complement one another in a modern WLAN, but 802.11v is specifically associated with network-assisted transition recommendations.

Question 376: Which RF condition can cause increased packet retransmissions even when a client has an acceptable RSSI?

  1. High noise or interference
  2. Low DHCP utilization
  3. Short DNS cache lifetime
  4. RADIUS accounting success

Correct Answer: 1. High noise or interference

Explanation:
High RF noise or interference can corrupt wireless transmissions and cause frames to be retransmitted even when the received signal strength appears acceptable. RSSI measures the strength of the received signal but does not distinguish between a strong desired signal and a noisy RF environment. Administrators should therefore consider SNR, noise floor, channel utilization, interference reports, and retransmission statistics when investigating packet loss or reduced throughput. DHCP utilization and DNS cache behavior do not directly determine RF retransmissions, while successful RADIUS accounting does not indicate wireless frame quality. RF interference is therefore a major factor to investigate.

Question 377: Which Cisco wireless feature can detect and classify RF interference using spectrum-analysis capabilities on supported access points?

  1. CleanAir
  2. AP Group
  3. Dynamic VLAN Assignment
  4. RADIUS

Correct Answer: 1. CleanAir

Explanation:
CleanAir uses supported Cisco access-point hardware and spectrum-analysis capabilities to detect and help classify RF interference. It can provide information about non-Wi-Fi interference sources that may affect WLAN performance and can assist administrators in identifying problematic areas of the RF environment. AP Groups manage WLAN availability, Dynamic VLAN Assignment places clients into appropriate VLANs, and RADIUS provides AAA services. CleanAir is therefore the Cisco wireless feature most directly associated with enhanced spectrum awareness and interference classification.

Question 378: Which QoS access category is intended for high-priority voice traffic in WMM?

  1. AC_BE
  2. AC_BK
  3. AC_VI
  4. AC_VO

Correct Answer: 4. AC_VO

Explanation:
WMM defines AC_VO, or Voice, as the access category intended for latency-sensitive voice traffic. It receives contention parameters designed to provide higher priority access to the wireless medium than Best Effort and Background traffic. AC_VI is intended for video, AC_BE for normal best-effort traffic, and AC_BK for background traffic. Proper QoS classification and mapping are important for voice deployments because low delay and jitter are critical to call quality. AC_VO is therefore the WMM category most directly associated with high-priority voice traffic.

Question 379: Which security feature can help protect a WLAN against forged deauthentication and disassociation management frames?

  1. DHCP Proxy
  2. Protected Management Frames
  3. Dynamic Channel Assignment
  4. AVC

Correct Answer: 2. Protected Management Frames

Explanation:
Protected Management Frames, or PMF, provide protection for selected IEEE 802.11 management frames and help reduce the effectiveness of attacks involving forged deauthentication and disassociation frames. PMF is associated with IEEE 802.11w and is an important security capability in modern WLAN deployments. DHCP Proxy handles DHCP processing, Dynamic Channel Assignment manages RF channel selection, and AVC provides application visibility and control. PMF does not eliminate every wireless attack, but it strengthens protection against specific management-frame spoofing techniques. Therefore, PMF is the appropriate security feature for this requirement.

Question 380: Which approach is most appropriate for improving capacity in a high-density wireless environment?

  1. Increase transmit power on every AP to maximum
  2. Use coordinated channel reuse, appropriate channel widths, and controlled cell sizes
  3. Place every AP on the same RF channel
  4. Disable all QoS and RF-management features

Correct Answer: 2. Use coordinated channel reuse, appropriate channel widths, and controlled cell sizes

Explanation:
High-density WLAN capacity depends heavily on efficient use of available airtime. Coordinated channel reuse, appropriate channel widths, and controlled cell sizes can reduce unnecessary contention and improve spatial reuse. Simply increasing transmit power can enlarge coverage cells and increase co-channel contention, while placing every AP on the same channel can create excessive competition for airtime. Disabling QoS and RF-management capabilities does not inherently improve capacity. A high-density design should instead consider client density, channel utilization, RF overlap, transmit power, channel width, and application requirements, with site surveys and performance measurements used to validate the design.