{"id":22667,"date":"2026-09-26T06:51:28","date_gmt":"2026-09-26T06:51:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=22667"},"modified":"2026-09-26T06:51:28","modified_gmt":"2026-09-26T06:51:28","slug":"cisco-ccnp-300-425-practice-test-questions-and-exam-dumps-part17-q321-340","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/cisco-ccnp-300-425-practice-test-questions-and-exam-dumps-part17-q321-340\/","title":{"rendered":"Cisco CCNP 300-425 Practice Test Questions and Exam Dumps Part17 Q321-340"},"content":{"rendered":"<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/300-425-exam-dumps\"><b>Cisco CCNP 300-425 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/p>\n<p><b><br \/>\n<\/b><b>Question 321. What does AAA override allow a RADIUS server to change<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AP antenna type<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Client policy attributes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controller hardware<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> RF channel width only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Client policy attributes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AAA override allows attributes returned by a RADIUS server to override locally configured wireless policy settings for an authenticated client. These attributes can influence VLAN assignment, access control lists, quality of service, and other supported client policies. This makes identity based wireless networking possible because two clients connected to the same WLAN can receive different network treatment according to their authentication results. AAA override is configured under the Catalyst 9800 wireless policy profile. It is especially useful when Cisco ISE or another RADIUS platform centrally determines user authorization.<\/span><\/p>\n<p><b>Question 322. What is required before RADIUS can dynamically override a client VLAN<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Monitor mode<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local DHCP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sniffer mode<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AAA override<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. AAA override<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AAA override must be enabled in the wireless policy profile before the RADIUS server can dynamically override the normal client VLAN assignment. Once enabled, supported RADIUS attributes can return a VLAN ID, VLAN name, or VLAN group for the authenticated client. This allows the same SSID to place different users into different network segments according to identity or authorization policy. Without AAA override, the normal VLAN configured in the wireless policy profile remains the primary client assignment. Dynamic VLAN design is commonly combined with centralized enterprise authentication systems.<\/span><\/p>\n<p><b>Question 323. Which RADIUS attribute can carry a VLAN name or VLAN ID<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Tunnel Private Group ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Calling Station ID<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> NAS IP Address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Framed MTU<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Tunnel Private Group ID<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Tunnel Private Group ID attribute can carry the VLAN information returned to the Catalyst 9800 during client authentication. Cisco identifies RADIUS attribute 81 as supporting a VLAN ID, VLAN name, or VLAN group name for dynamic client assignment. Other tunnel related attributes are also used as part of standard RADIUS VLAN authorization. AAA override must be enabled in the wireless policy profile so the returned VLAN information can supersede the locally configured assignment. This approach allows centralized identity systems to place users into appropriate network segments dynamically.<\/span><\/p>\n<p><b>Question 324. What happens when AAA VLAN fallback is enabled and the assigned VLAN is unavailable<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller reboots<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The client enters monitor mode<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The policy profile VLAN is used<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The AP changes channels<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. The policy profile VLAN is used<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AAA VLAN fallback provides backup connectivity when a VLAN returned by the authentication server is unavailable on the controller or site. When fallback is enabled, the Catalyst 9800 can place the client into the VLAN configured in the wireless policy profile instead of simply denying network access. This is useful in distributed environments where one central AAA policy may return VLANs that are not present at every location. The feature therefore improves client connectivity while still allowing centralized dynamic VLAN assignment whenever the requested VLAN is available.<\/span><\/p>\n<p><b>Question 325. What occurs if both the AAA assigned VLAN and fallback policy VLAN are unavailable<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> The client receives the management VLAN automatically<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The client is excluded<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The AP reloads<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> The controller creates the VLAN<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. The client is excluded<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">In a central switching deployment, if the AAA assigned VLAN is unavailable and the VLAN configured in the wireless policy profile is also not defined, Cisco treats the configuration as invalid and excludes the client. VLAN fallback can only preserve connectivity when a valid fallback network exists. The controller does not automatically create missing VLANs. Designers using dynamic authorization should therefore make sure that required VLANs or suitable fallback VLANs are consistently defined at the locations where clients can connect.<\/span><\/p>\n<p><b>Question 326. What does per client bidirectional rate limiting control<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Total client bandwidth<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AP antenna gain<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Controller licensing<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mobility group size<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Total client bandwidth<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Per client bidirectional rate limiting places an aggregate bandwidth limit on each wireless client in both upload and download directions. The configured rate applies to the total traffic generated by the client rather than separately limiting every application flow. For example, if a client simultaneously runs a video stream and a file transfer, both applications share the same overall bandwidth allowance. This prevents users from exceeding intended bandwidth limits simply by opening several traffic flows. Cisco implements the feature through QoS client policies applied in the wireless policy profile.<\/span><\/p>\n<p><b>Question 327. Which class map is required for the documented per client rate limit design<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Voice class only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Video class only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Default class<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Multicast class<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Default class<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco documents per client bidirectional rate limiting using a policy map containing the default class map. When the default class contains a valid police rate and the policy is attached as the QoS client policy, the access point applies the rate limit to each connected client. Cisco also notes that adding another class map prevents the documented per client rate limiting behavior from operating on the AP. Designers should therefore distinguish simple aggregate client rate limiting from more complex application or class based QoS policy designs.<\/span><\/p>\n<p><b>Question 328. Where does central switching send wireless client traffic<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Directly to the branch switch only<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Directly to the Internet<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> To the RADIUS server<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Through CAPWAP to the controller<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. Through CAPWAP to the controller<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Central switching sends wireless user traffic through the CAPWAP tunnel from the access point to the centralized wireless controller. The controller then maps the traffic to the appropriate client VLAN or network interface. This is the normal centralized forwarding model for local mode access points. It differs from FlexConnect local switching, where client traffic can be placed directly onto the branch LAN by the AP. Designers should consider WAN topology, controller placement, application paths, security policy, and bandwidth when choosing between centralized and local forwarding architectures.<\/span><\/p>\n<p><b>Question 329. What does central DHCP do for wireless clients<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sends DHCP traffic through the controller<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Disables DHCP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Uses only AP local addresses<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Converts DHCP to DNS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Sends DHCP traffic through the controller<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Central DHCP causes DHCP traffic received from wireless clients to be forwarded centrally through the controller. The controller then sends the DHCP packets into the appropriate client VLAN according to the configured policy. This can be used together with centralized switching and authentication in a standard campus deployment. In FlexConnect designs, central DHCP can also be selected when client data forwarding and network services require a centralized architecture. Designers should make sure the DHCP server and relay paths are reachable from the client VLANs used by the wireless policy profile.<\/span><\/p>\n<p><b>Question 330. Where is the normal client VLAN configured for a Catalyst 9800 WLAN policy<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> RF profile<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Policy profile<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AP certificate<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mobility group<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Policy profile<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Catalyst 9800 wireless policy profile contains the normal VLAN assignment used for clients associated with the WLAN. The policy profile also contains many other client forwarding and service settings. A policy tag maps a WLAN profile to its corresponding policy profile and applies that combination to access points. If AAA override is enabled, the authentication server can return a different VLAN for an individual client. Without a valid override, the policy profile VLAN normally determines where centrally switched client traffic is placed.<\/span><\/p>\n<p><b>Question 331. What does a RADIUS realm use to choose an authentication server<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AP serial number<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Client RSSI<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> User domain information<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Channel number<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. User domain information<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A RADIUS realm uses the domain portion of the user&#8217;s Network Access Identifier to select an appropriate authentication or accounting server. This allows one WLAN to serve users from different organizations or identity domains while routing their AAA requests toward different RADIUS systems. Realm based designs are useful in environments with multiple authentication domains, partner organizations, or federated wireless access requirements. The wireless controller examines the user identity information and applies the configured realm mapping rather than sending every authentication request to the same server group.<\/span><\/p>\n<p><b>Question 332. What can RADIUS realms control besides authentication requests<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Accounting requests<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> AP transmit power<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> DFS channels<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antenna polarization<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Accounting requests<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Catalyst 9800 RADIUS realm support can direct both authentication and accounting requests according to the domain information contained in the user Network Access Identifier. This provides consistent AAA routing for environments where different identity realms must use different RADIUS infrastructure. Authentication validates the user, while accounting records session related activity according to the configured AAA design. Realm based server selection gives administrators greater control than sending every WLAN user to one common RADIUS server regardless of the identity domain contained in the username.<\/span><\/p>\n<p><b>Question 333. Which feature can authenticate a wireless client by MAC address<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> BSS Coloring<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> TPC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> OFDMA<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> MAC filtering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. MAC filtering<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">MAC filtering can authenticate or authorize a wireless client according to its device MAC address. Catalyst 9800 supports local authentication as well as external AAA based approaches for MAC filtering. This can be useful for devices that cannot perform normal 802.1X authentication, such as certain printers, sensors, and specialized equipment. MAC addresses are not strong secrets and can be spoofed, so MAC filtering should not normally be considered equivalent to certificate based authentication. It is best used when device limitations or specific network access requirements justify it.<\/span><\/p>\n<p><b>Question 334. What format does Cisco require for a locally configured MAC authentication username<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Colon separated MAC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Twelve hexadecimal characters without separators<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Dotted decimal address<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Eight character hostname<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Twelve hexadecimal characters without separators<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">For local MAC filtering authentication, Cisco requires the MAC address username in a continuous hexadecimal format without normal punctuation separators. Cisco documentation gives the format as twelve hexadecimal characters similar to abcdabcdabcd. The address is configured as a local username before the WLAN is configured to use MAC filtering for local authentication. Using the correct format is important because a colon separated or hyphen separated MAC address will not match the expected local authentication entry. External AAA deployments can use their own supported identity database formatting rules.<\/span><\/p>\n<p><b>Question 335. What must be enabled in the policy profile for the documented MAC filtering SSID design<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AAA override<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Hyperlocation<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mesh CAC<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Sniffer mode<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AAA override<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco&#8217;s documented Catalyst 9800 MAC authentication SSID configuration enables AAA override in the wireless policy profile. This allows authorization information returned during MAC based authentication to influence the client policy applied by the controller. MAC filtering can be associated with a local or external authorization method depending on the deployment. Because many devices using MAC authentication are specialized endpoints with limited security capability, designers should combine this mechanism with appropriate segmentation and access restrictions instead of treating the MAC address itself as strong proof of identity.<\/span><\/p>\n<p><b>Question 336. Which setting can a Catalyst 9800 policy profile contain<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Building wall material<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Spectrum analyzer model<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Client access control policy<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antenna mounting bracket<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. Client access control policy<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Catalyst 9800 policy profile can contain client service settings such as VLAN assignment, access control lists, quality of service configuration, mobility anchor information, timers, and switching behavior. The WLAN profile defines wireless network characteristics while the policy profile determines much of the treatment clients receive after connecting. This separation makes the Catalyst 9800 configuration model reusable because one WLAN can be combined with different policies in different deployment areas when required. Physical RF characteristics such as wall attenuation and antenna mounting are design inputs rather than policy profile attributes.<\/span><\/p>\n<p><b>Question 337. Which three settings are normally enabled for a local mode centrally switched WLAN<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Monitor Sniffer and Bridge<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Central switching Central authentication and Central DHCP<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Local switching Local DHCP and Local authentication<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Mesh Sensor and SE Connect<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Central switching Central authentication and Central DHCP<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco guidance for a normal local mode WLAN indicates that the policy profile should use central switching, central authentication, and central DHCP when those services are handled through the wireless controller. Central switching tunnels user traffic through CAPWAP to the controller. Central authentication keeps the authentication workflow centralized, while central DHCP forwards client address assignment traffic through the controller into the appropriate VLAN. This design is common in campus environments where the controller and centralized services are reachable through high capacity infrastructure rather than a constrained branch WAN.<\/span><\/p>\n<p><b>Question 338. How does per client rate limiting handle several simultaneous application flows<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Each flow gets the full limit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Only the first flow is permitted<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Video bypasses the limit<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> All flows share one aggregate limit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4. All flows share one aggregate limit<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Per client bidirectional rate limiting applies one aggregate bandwidth limit across all traffic generated by a wireless client. If the client runs several applications at the same time, the combined traffic remains subject to the configured client rate. This corrects a limitation of older per flow approaches where every individual stream could receive the complete configured limit and a user could therefore exceed the intended total bandwidth. The aggregate method is useful for guest networks and other deployments where administrators want predictable and fair bandwidth consumption per connected device.<\/span><\/p>\n<p><b>Question 339. What can AAA override dynamically provide to individual wireless clients<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AP firmware<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> Antenna gain<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> VLAN QoS and ACL attributes<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> RF channel plans<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. VLAN QoS and ACL attributes<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AAA override enables RADIUS authorization to dynamically apply supported attributes such as VLAN assignment, quality of service, and access control lists to individual wireless clients. This is a key identity networking capability because users on the same SSID can receive different access policies according to their identity, device type, role, or authorization result. The attributes returned by the AAA server take precedence over corresponding local settings where the feature supports the override. Cisco ISE is commonly used to provide this type of centralized policy decision in enterprise wireless environments.<\/span><\/p>\n<p><b>Question 340. What is the valid VLAN ID range documented for Catalyst 9800 override VLANs<\/b><\/p>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> 1 through 4094<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 1 through 255<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 1 through 1024<\/span><\/li>\n<li><b><\/b><span style=\"font-weight: 400;\"> 1 through 8192<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. 1 through 4094<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cisco documents the valid VLAN ID range as 1 through 4094 when defining VLANs that can be assigned through RADIUS override. These VLANs must exist in the controller and surrounding wired infrastructure where required for centrally switched traffic. Dynamic authorization does not automatically create missing network segments. Designers should therefore coordinate wireless VLAN assignment with switching, routing, DHCP, security, and AAA policy configuration. If the AAA server returns an unavailable VLAN, the client can be excluded unless the supported AAA VLAN fallback feature has been configured to provide an alternate policy profile VLAN.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Cisco CCNP 300-425 Exam Dumps and Practice Test Dumps. Question 321. What does AAA override allow a RADIUS server to change AP antenna type Client policy attributes Controller hardware RF channel width only Correct Answer: 2. Client policy attributes Explanation: AAA override allows attributes returned by a RADIUS server to override locally configured [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22667"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=22667"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22667\/revisions"}],"predecessor-version":[{"id":22668,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/22667\/revisions\/22668"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=22667"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=22667"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=22667"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}