Last updated: May 2026
350-401 ENCOR — Cisco Certified Internetwork Expert (CCIE) Enterprise Wireless
Test your knowledge with official exam-style questions
Questions and options are shuffled each attempt
▶Cisco Certified Internetwork Expert (CCIE) Enterprise Wireless — Practice Set 1: All Questions & Explanations
Full question text, answer options, and explanations for this practice set — a spoiler-free alternative is the interactive quiz above for scored, shuffled practice.
. In an SD-Access fabric deployment, an Embedded Wireless Controller (EWC) is running on a Cisco Catalyst 9120 AP. Which statement correctly describes a fundamental architectural difference between EWC and a centralized Cisco Catalyst 9800 WLC in terms of control-plane placement?
- A. EWC runs the WLC control plane on the AP itself, eliminating the need for a separate physical or virtual WLC appliance, while centralized 9800 runs the control plane on a dedicated device that all APs must reach via CAPWAP.(correct)
- B. EWC requires CAPWAP tunnels to a Cisco DNA Center appliance for all management functions, while centralized 9800 WLC communicates directly with Cisco DNA Center without CAPWAP.
- C. EWC supports a maximum of 500 APs per fabric site, while centralized 9800 WLC is limited to 100 APs per physical chassis.
- D. EWC offloads client data traffic to the underlay fabric using VXLAN, while centralized 9800 WLC always hairpins all client traffic through the controller.
Explanation: EWC embeds the Catalyst 9800 WLC software directly on select Catalyst 9100 series APs, so the AP itself acts as both the controller and an access point, supporting up to 100 APs and 2000 clients per EWC cluster. A centralized Catalyst 9800 WLC (hardware appliance or VM) runs the control plane on a dedicated platform and all APs form CAPWAP tunnels to it. The other options describe incorrect behaviors: EWC does not require CAPWAP to DNA Center, AP limits are different, and VXLAN data-plane handling is a fabric function unrelated to this distinction.
. A network architect is deploying a wireless mesh network across a large outdoor campus. The root AP (RAP) is connected to the wired distribution switch via Ethernet. Three mesh APs (MAPs) form hops to reach distant areas. Which statement is TRUE regarding the backhaul SSID in this design?
- A. The backhaul SSID is a hidden SSID visible only to mesh APs; client devices can associate to the backhaul SSID if they know the SSID name.
- B. The backhaul SSID is used exclusively for MAP-to-RAP (or MAP-to-MAP) mesh link formation and is not advertised for client associations; client traffic rides on separately configured access SSIDs.(correct)
- C. In a default outdoor mesh deployment, the backhaul radio and the client-access radio must operate on the same channel to simplify co-channel interference management.
- D. The RAP must be configured as a FlexConnect AP with local switching enabled for backhaul traffic to function correctly in a mesh topology.
Explanation: In Cisco Aironet and Catalyst outdoor mesh deployments, the backhaul SSID is a dedicated wireless link used solely for inter-AP communication between MAPs and the RAP (or daisy-chained MAPs). Client devices cannot and do not associate to the backhaul SSID. Client SSIDs are configured separately on the access radio. Option A is wrong because clients are explicitly prevented from using the backhaul SSID. Option C is wrong — backhaul and access radios typically operate on different channels (commonly 5 GHz for backhaul, 2.4 GHz for access) to reduce interference. Option D is incorrect; mesh RAPs use local mode or mesh mode, not FlexConnect.
. A Cisco Catalyst Center wireless assurance deployment shows a client 360 view. The client onboarding score drops specifically at the DHCP phase. Which weighted scoring factor does Cisco Catalyst Center apply that would cause this specific phase failure to most impact the overall client health score?
- A. The DHCP phase failure has no individual weighting; all four onboarding phases (Association, Authentication, DHCP, DNS) contribute equally at 25% each.
- B. DHCP is a Layer 3 connectivity indicator and carries higher weight than Layer 2 phases because Catalyst Center considers IP reachability more critical than 802.11 association for overall health.
- C. Catalyst Center's client health score is computed from multiple sub-scores including onboarding, connectivity, and roaming; a DHCP failure drives the onboarding sub-score to zero, which feeds into the composite client health score and can produce a score below 3 (out of 10) depending on configured thresholds.(correct)
- D. DHCP failures are excluded from the client health score and instead appear only in the issues dashboard as a P2 issue, with no effect on the numerical health score displayed in the client 360 view.
Explanation: Cisco Catalyst Center computes client health as a composite of sub-scores: the onboarding experience (association, authentication, DHCP, DNS each contribute), connectivity quality (RSSI, SNR, data rate), and roaming experience. A DHCP failure causes the onboarding sub-score to fail entirely for that client session. This cascades into the composite health score, which is displayed on a 1–10 scale. Option A is incorrect because the phases have different implied impact on connectivity. Option B mischaracterizes Catalyst Center's actual scoring model. Option D is incorrect — DHCP failures absolutely affect the displayed health score.
. An 802.11ax (Wi-Fi 6) AP is configured to use OFDMA for uplink transmissions. A client requests a 26-tone RU allocation. What does this RU size correspond to in terms of channel utilization, and what is the primary benefit of this allocation for this client?
- A. A 26-tone RU represents a 2 MHz sub-channel within a 20 MHz channel; it allows the AP to simultaneously serve multiple low-bandwidth clients (such as IoT sensors) in the uplink direction, reducing latency compared to legacy OFDM where only one client transmits at a time.(correct)
- B. A 26-tone RU represents the entire 20 MHz channel assigned exclusively to one client, providing maximum throughput by using all available subcarriers.
- C. A 26-tone RU is only valid in the downlink direction (DL-OFDMA); uplink OFDMA in 802.11ax uses fixed 52-tone RUs minimum.
- D. A 26-tone RU triggers BSS coloring to change the color bit to 1, indicating a partial channel usage to neighboring BSSes.
Explanation: In 802.11ax, OFDMA divides the channel into Resource Units (RUs) of different sizes: 26-tone (~2 MHz), 52-tone (~4 MHz), 106-tone (~8 MHz), 242-tone (20 MHz), 484-tone (40 MHz), and 996-tone (80 MHz). A 26-tone RU uses approximately 2 MHz of a 20 MHz channel, allowing the AP to multiplex up to 9 simultaneous UL-OFDMA transmissions in one 20 MHz channel. This dramatically benefits IoT and low-bandwidth devices by reducing latency and improving efficiency. Option B is wrong — 26-tone is a small sub-channel, not the whole channel. Option C is wrong — UL-OFDMA supports all RU sizes including 26-tone. Option D confuses RU allocation with BSS coloring, which is a separate 802.11ax feature.
. An engineer is troubleshooting co-channel interference in a dense 802.11ax deployment. The AP reports receiving frames with a BSS Color value of 7, while the local BSS is configured with BSS Color 3. Which action does the AP take based on spatial reuse and BSS coloring rules defined in 802.11ax?
- A. The AP discards the frame immediately without decoding the header because the BSS Color mismatch indicates the frame is from a different BSS, and the medium is considered free for the local BSS to transmit.
- B. The AP applies inter-BSS spatial reuse: it compares the RSSI of the inter-BSS frame against the OBSS PD (Overlapping BSS Packet Detect) threshold; if the RSSI is below the threshold, the AP can ignore the virtual carrier sense and transmit concurrently, increasing spectrum utilization.(correct)
- C. BSS Color 7 triggers a color collision event, causing both the local AP and the remote AP to simultaneously initiate a Color Change Announcement to color 0 (disabled state) until an administrator manually reassigns colors.
- D. The AP must defer transmission for a full SIFS + DIFS backoff period whenever it detects any inter-BSS frame regardless of RSSI, because 802.11ax spatial reuse only applies to frames within the same BSS.
Explanation: 802.11ax BSS Coloring enables spatial reuse via OBSS PD (Overlapping BSS Packet Detection). When an AP receives a frame with a different BSS Color (inter-BSS frame), it checks the received RSSI against a dynamic OBSS PD threshold (default -82 dBm, adaptive range -62 to -82 dBm). If the inter-BSS signal is below this threshold, the AP treats the medium as available and can begin its own transmission concurrently — increasing spatial reuse in dense deployments. Option A is incorrect: the AP does decode enough of the PPDU to read the BSS Color in the SIG-A field but does not discard — it makes a CCA decision based on RSSI. Option C is wrong; color collisions trigger a Color Change Announcement but not to color 0. Option D contradicts the entire purpose of spatial reuse in 802.11ax.
. A Cisco Catalyst 9136 AP is operating in the 6 GHz band as a Standard Power AP. Which regulatory mechanism does this AP use to determine allowable EIRP levels for its operating channel, and what is the primary function of this mechanism?
- A. The AP uses Low Power Indoor (LPI) rules, which allow up to 5 dBm EIRP on all 6 GHz channels without any external coordination because LPI devices have inherently low power limits.
- B. The AP uses Automated Frequency Coordination (AFC), which queries an AFC system via an authenticated API to obtain maximum permissible EIRP and allowable frequencies for its geographic location, ensuring protection of incumbent fixed microwave users in the U-NII-5 through U-NII-8 bands.(correct)
- C. The AP uses Dynamic Frequency Selection (DFS) radar detection, scanning for radar signatures on 6 GHz channels before transmitting, similar to the 5 GHz DFS mechanism for weather and military radar protection.
- D. The AP uses Very Low Power (VLP) rules, which permit outdoor operation at up to 14 dBm EIRP and do not require AFC consultation because VLP devices are limited to short range.
Explanation: In the 6 GHz band (U-NII-5 through U-NII-8), Standard Power APs must use Automated Frequency Coordination (AFC). An AFC system is a database-driven service that, given the AP's geographic coordinates and antenna parameters, returns the maximum allowed EIRP and permitted channels, protecting incumbent fixed-satellite and fixed microwave services. AFC allows Standard Power APs to operate at up to 36 dBm EIRP outdoors. Option A describes LPI (Low Power Indoor), which allows up to 24 dBm EIRP indoors without AFC. Option C is wrong — 6 GHz does not use DFS radar detection; that is a 5 GHz mechanism. Option D describes VLP, which is a very short-range mode (up to 14 dBm) that also does not require AFC but is not Standard Power.
. An 802.11ax AP is communicating with a Wi-Fi 6 certified client. The AP advertises support for 0.8 µs, 1.6 µs, and 3.2 µs guard intervals. The network engineer configures the AP to mandate a 3.2 µs guard interval for all HE transmissions. What is the trade-off compared to using a 0.8 µs guard interval?
- A. A 3.2 µs guard interval increases overhead per symbol, reducing throughput relative to 0.8 µs, but provides greater resilience to multipath delay spread in high-echo environments such as warehouses, eliminating inter-symbol interference at larger delay spreads.(correct)
- B. A 3.2 µs guard interval is only valid for 2.4 GHz operation in 802.11ax; on 5 GHz and 6 GHz, 802.11ax mandates the 0.8 µs guard interval for maximum throughput.
- C. A 3.2 µs guard interval reduces the OFDM symbol duration from 12.8 µs to 6.4 µs, effectively halving the number of subcarriers and reducing spectral efficiency.
- D. There is no throughput trade-off; 3.2 µs and 0.8 µs guard intervals result in identical PHY rates because the guard interval time is not counted toward the data symbol duration in 802.11ax.
Explanation: In 802.11ax, the OFDM symbol duration is 12.8 µs (4x longer than 802.11ac's 3.2 µs symbol). Guard intervals add cyclic prefix overhead: 0.8 µs GI yields total symbol duration of 13.6 µs, while 3.2 µs GI yields 16 µs total. The longer guard interval reduces throughput because more of each symbol period is overhead, but it provides resilience against multipath delay spreads up to 3.2 µs, which is beneficial in environments like warehouses or large open spaces where reflected signals arrive with significant delay. 802.11ac supported only 0.8 µs GI; 802.11ax added 1.6 µs and 3.2 µs options. Options B, C, and D are all factually incorrect.
. A network engineer wants to maximize power savings for battery-operated IoT sensors using 802.11ax Target Wake Time (TWT). Which statement best describes how TWT achieves power savings compared to legacy DTIM-based power save?
- A. TWT allows the AP and client to negotiate a specific schedule of wake times and sleep intervals; the client sleeps for deterministic periods and wakes only at agreed TWT service periods, eliminating the need to wake at every DTIM beacon interval and reducing unnecessary radio activity.(correct)
- B. TWT replaces DTIM beacons entirely; APs using TWT no longer transmit DTIM beacons, and all clients must use TWT agreements to receive buffered frames.
- C. TWT works by aggregating all buffered frames into a single burst transmitted at a TWT wake time, but the client must still acknowledge each frame individually using legacy ACK, so power savings are minimal for high-packet-rate applications.
- D. TWT requires clients to remain in active mode continuously during the TWT service period, which means power consumption increases during data exchange but decreases between TWT windows.
Explanation: Target Wake Time (TWT) in 802.11ax allows an AP and a STA to negotiate wake-up schedules through TWT Setup and TWT Response frames. The client wakes only at the agreed TWT service period (which can be seconds or minutes apart for IoT), transmits or receives its data, then returns to sleep. This contrasts sharply with legacy U-APSD/DTIM power save, where clients must wake at each DTIM beacon interval (typically every 100-300 ms) to check for buffered traffic. TWT reduces unnecessary radio activation by orders of magnitude for infrequent-data IoT devices. Option B is wrong — DTIM beacons continue for non-TWT clients. Option C inaccurately describes the mechanism. Option D contradicts the fundamental TWT design — clients sleep between TWT windows.
. An enterprise deploys 802.11ax APs with 8x8 MU-MIMO. A client device reports supporting only 2 spatial streams. During a DL MU-MIMO transmission, the AP simultaneously serves 4 clients. What is the AP's maximum number of simultaneous spatial streams across all clients in this MU-MIMO group, and what mechanism does the AP use to prevent spatial streams destined for one client from interfering with another?
- A. The AP can transmit up to 8 simultaneous spatial streams across the MU-MIMO group (bounded by the AP's 8 antenna chains); it uses beamforming with null-steering (zero-forcing precoding) to direct each client's spatial streams toward that client's antenna(s) while placing signal nulls in the directions of other clients in the same group.(correct)
- B. The AP transmits exactly 4 spatial streams — one per client — regardless of per-client stream capability; MU-MIMO in 802.11ax is limited to 1 stream per client to simplify the receiver design.
- C. The AP uses OFDMA subcarrier assignment to isolate each client's spatial streams to non-overlapping subcarrier ranges, preventing inter-client interference without requiring beamforming feedback.
- D. MU-MIMO in 802.11ax is only supported in the uplink direction (UL MU-MIMO); downlink transmissions use SU-MIMO only, so the described scenario is not possible.
Explanation: 802.11ax supports DL MU-MIMO with up to 8 simultaneous spatial streams across all co-scheduled clients, bounded by the AP's antenna count. The AP can serve multiple clients in the same MU-MIMO group, allocating spatial streams per client (e.g., 2 streams to client A, 2 streams to client B, etc.) as long as total streams do not exceed 8. Interference suppression is achieved via explicit beamforming: clients send beamforming feedback matrices (compressed steering matrices from sounding) that the AP uses to compute zero-forcing or conjugate beamforming precoding vectors, placing signal nulls toward unintended clients. Option B is incorrect — per-client stream count is not limited to 1. Option C confuses MU-MIMO with OFDMA; they are separate mechanisms (though 802.11ax can combine them). Option D is wrong — 802.11ax supports both DL and UL MU-MIMO.
. A Cisco Catalyst Center wireless assurance deployment shows that an AP cluster has a degraded RF health score. The root cause analysis points to co-channel interference (CCI). Which Cisco RRM mechanism is the PRIMARY automated response on the Catalyst 9800 WLC to mitigate CCI, and what parameter does it adjust?
- A. RRM Dynamic Channel Assignment (DCA) monitors RSSI from neighboring APs and adjusts the operating channel of affected APs to minimize CCI, aiming to maximize channel separation across the deployment based on real-time neighbor data.(correct)
- B. RRM Coverage Hole Detection (CHD) detects CCI by measuring client RSSI below a threshold and increases AP transmit power to overcome the interference, effectively raising the signal-to-noise ratio above the CCI floor.
- C. RRM Flexible Radio Assignment (FRA) converts all 2.4 GHz radios to 5 GHz operation, eliminating the 2.4 GHz band where most CCI occurs, without any channel or power changes to existing 5 GHz radios.
- D. RRM Transmit Power Control (TPC) is the primary CCI mitigation tool; it reduces all AP transmit powers to the minimum threshold (–10 dBm), shrinking cell coverage to eliminate all overlap between neighboring APs.
Explanation: Cisco's Radio Resource Management (RRM) Dynamic Channel Assignment (DCA) is the primary mechanism for CCI mitigation. DCA continuously collects RSSI measurements from neighboring APs and interference sources using RRM neighbor messages and off-channel scanning, then algorithmically assigns channels to maximize separation between co-channel APs. TPC (option D) addresses coverage and capacity via power adjustments but its goal is not to eliminate overlap — some overlap is required for seamless roaming. CHD (option B) detects coverage holes by tracking clients with low RSSI and increases power to fill gaps, which is the opposite of CCI mitigation. FRA (option C) can help by moving radios off 2.4 GHz but is not the primary targeted CCI response.
. A Cisco Catalyst 9800 WLC HA SSO pair experiences a split-brain condition. Which mechanism on the C9800 is specifically designed to prevent a split-brain scenario where both units simultaneously become active, and how does it work?
- A. The Redundancy Management Interface (RMI) serves as a dedicated management path between the active and standby controllers; if the RP (redundancy port) keepalives fail but the RMI is reachable, the standby does NOT take over, preventing split-brain because the RMI acts as the tiebreaker confirming the active controller is still reachable from the management network.(correct)
- B. The C9800 SSO pair uses a VRRP-like virtual IP mechanism; whichever unit holds the virtual IP is considered active, and a hardware lock prevents both units from claiming the virtual IP simultaneously.
- C. Split-brain is prevented exclusively by the RP (redundancy port) keepalive timer; if keepalives are missed for three consecutive intervals, the standby immediately takes over, ensuring only one active controller exists at any time.
- D. The C9800 uses a BFD session over the CAPWAP control plane to all joined APs; the unit that maintains the higher BFD session count is designated active, preventing split-brain by consensus.
Explanation: Catalyst 9800 HA SSO uses two interfaces for redundancy signaling: the Redundancy Port (RP) for state synchronization and keepalives, and the Redundancy Management Interface (RMI) as a secondary health check path. If RP keepalives fail (e.g., a cable fault), the RMI is consulted — if the RMI is still reachable (the standby can ping the active via the management network), the standby does NOT preempt to prevent split-brain. Only if BOTH RP and RMI are unreachable does the standby conclude the active has truly failed and take over. This dual-path validation is Cisco's explicit split-brain prevention mechanism for C9800 HA. Options B, C, and D describe mechanisms that either do not exist or function differently on the C9800.
. Cisco Spaces (formerly CMX) is deployed for location tracking in an enterprise campus. An engineer compares RSSI-based location versus angle-of-arrival (AoA) location. Which statement accurately describes a key technical difference between these two methods?
- A. RSSI-based location requires a minimum of three APs to perform trilateration using signal strength, offering approximately 5–15 meter accuracy; AoA uses directional antenna arrays on the AP to measure the angle from which a client's signal arrives, enabling sub-meter accuracy for compatible Bluetooth 5.1 or Wi-Fi Fine Timing Measurement devices.(correct)
- B. RSSI-based location is only supported in the 5 GHz band; AoA operates exclusively on the 2.4 GHz band because lower frequencies propagate more consistently for angle estimation.
- C. AoA location is provided natively by all Catalyst 9100 series APs without additional hardware; RSSI-based location requires the optional Cisco location module add-in card.
- D. Both RSSI and AoA achieve identical accuracy of approximately 1 meter in all environments; the primary difference is that AoA requires less AP density than RSSI-based trilateration.
Explanation: RSSI-based trilateration (used in Cisco Spaces/CMX) collects signal strength measurements from multiple APs and estimates distance from path-loss models, then triangulates position with roughly 5–15 meter accuracy depending on AP density and environment. Angle-of-Arrival (AoA) uses multi-element antenna arrays (available in select Catalyst 9100 APs and dedicated IoT radio modules) to measure the phase difference of a signal across antennas, computing the angle of arrival and enabling sub-meter accuracy — particularly effective with Bluetooth 5.1 AoA beacons and 802.11mc FTM. Option B is wrong about band restrictions. Option C is wrong — AoA requires specific hardware (e.g., Catalyst 9130 IoT radio or BLE module). Option D is incorrect; the two methods have substantially different accuracy characteristics.
. An enterprise security team mandates WPA3-Enterprise 192-bit mode (Suite B) for all executive wireless clients. Which combination of components is required to satisfy the 192-bit Security mode specification?
- A. GCMP-256 for data encryption, BIP-GMAC-256 for management frame protection, EAP-TLS with certificates using RSA-2048 or ECDSA P-256 minimum, and PMF (Protected Management Frames) mandatory.
- B. GCMP-256 for data encryption, BIP-GMAC-256 for management frame protection, EAP-TLS with certificates using RSA-3072 or ECDSA P-384 minimum, and PMF (Protected Management Frames) mandatory.(correct)
- C. CCMP-256 for data encryption, BIP-CMAC-256 for management frame protection, EAP-PEAP with MSCHAPv2, and PMF optional.
- D. GCMP-128 for data encryption, BIP-CMAC-128 for management frame protection, EAP-TLS with any RSA key length, and PMF mandatory.
Explanation: WPA3-Enterprise 192-bit Security mode (defined in IEEE 802.11-2020 and Wi-Fi Alliance WPA3 spec) requires: GCMP-256 (AES Galois/Counter Mode Protocol with 256-bit key) for pairwise and group cipher; BIP-GMAC-256 (Broadcast/Multicast Integrity Protocol using GMAC-256) for management frame integrity; EAP-TLS as the mandatory EAP method with a minimum of RSA-3072, ECDSA P-384, or DH-3072 key strength; and mandatory PMF (Protected Management Frames, IEEE 802.11w). RSA-2048/P-256 (option A) falls short of the 192-bit security equivalence requirement. CCMP-256/BIP-CMAC-256 with PEAP (option C) does not meet Suite B cipher requirements. GCMP-128/BIP-CMAC-128 (option D) is WPA3-Enterprise standard mode, not 192-bit mode.
. An engineer configures WPA3-Personal with SAE on a Cisco Catalyst 9800 WLAN. A security team member asks about SAE's resistance to offline dictionary attacks compared to WPA2-Personal (PSK). Which property of SAE's dragonfly handshake provides this resistance?
- A. SAE uses a 256-bit pre-shared key instead of a passphrase, making brute-force attacks computationally infeasible compared to WPA2's variable-length passphrase.
- B. SAE derives a fresh Pairwise Master Key (PMK) for each authentication through a zero-knowledge proof exchange; an attacker capturing the 4-way handshake cannot perform offline dictionary attacks because the PMK is never directly derivable from the passphrase without completing the interactive protocol, and each exchange uses a new random commitment value.(correct)
- C. SAE provides the same level of protection against offline dictionary attacks as WPA2-PSK but adds forward secrecy by rotating the PSK every 30 minutes using a TOTP-based mechanism.
- D. SAE prevents offline dictionary attacks by encrypting the 4-way handshake with the AP's public RSA key, so a passive eavesdropper cannot decrypt the exchanged nonces used to verify the passphrase.
Explanation: SAE (Simultaneous Authentication of Equals) uses the Dragonfly key exchange (based on the Diffie-Hellman principle with a password element derived from the passphrase). Each authentication creates a unique PMK through a commit-confirm exchange that incorporates fresh random scalars and elements. A passive attacker capturing the SAE exchange frames cannot run an offline dictionary attack because the protocol is interactive — verifying a passphrase guess requires completing an active exchange with the other party. This is fundamentally different from WPA2-PSK, where the MIC in the 4-way handshake is directly verifiable offline given a passphrase guess. Option A is wrong — SAE still uses a passphrase. Option C incorrectly claims SAE and WPA2-PSK have equivalent offline attack resistance. Option D describes RSA encryption, which SAE does not use.
. An enterprise deploys OWE (Opportunistic Wireless Encryption) transition mode on a guest SSID to support both legacy WPA2-Open clients and OWE-capable clients. How does OWE transition mode work at the 802.11 level?
- A. A single SSID broadcasts two BSS: one open (no security IE) for legacy clients and one hidden OWE BSS with the same SSID name but with the OWE AKM suite in the RSN IE; the OWE BSS advertises the open BSS's BSSID in a vendor-specific IE, allowing OWE-capable clients to discover and associate to the encrypted OWE BSS while legacy clients use the open one.(correct)
- B. OWE transition mode works by downgrading OWE clients to WPA2-CCMP if the AP detects that more than 50% of associated clients are legacy devices, ensuring broad compatibility.
- C. In OWE transition mode, the AP uses a single BSS that advertises both open and OWE AKMs in the same RSN IE; the client selects which AKM to use during the Association Request, and the AP accommodates both types simultaneously on the same BSSID.
- D. OWE transition mode requires 802.1X infrastructure; the RADIUS server determines whether to issue an OWE or open session token based on the client's advertised capabilities in the EAP Identity response.
Explanation: OWE transition mode (defined in Wi-Fi Alliance OWE spec and RFC 8110) uses a paired BSS approach: the AP runs two co-located BSSes sharing the same SSID. The open BSS (no RSN IE for security) serves legacy open-network clients. The OWE BSS is hidden (not broadcast in beacons with a visible SSID) and carries the OWE AKM (00-0F-AC:18) in its RSN IE. The open BSS beacon contains a vendor-specific Transition Mode IE that advertises the OWE BSS's BSSID, allowing OWE-capable supplicants to discover the OWE BSS and perform a Diffie-Hellman key exchange during association for encryption without a pre-shared key. Legacy clients simply use the open BSS. Option B describes automatic downgrade, which OWE does not do. Option C is wrong — you cannot have a single BSS serving both open and OWE clients simultaneously. Option D confuses OWE with 802.1X.
. On a Cisco Catalyst 9800 WLC, a security engineer enables WPA3 with PMF (Protected Management Frames) set to 'Required' on a WLAN. What is the effect on WPA2-only clients attempting to associate to this WLAN?
- A. WPA2-only clients will associate successfully using CCMP-128 because PMF Required only mandates MFP for management frames and does not affect the data cipher negotiation.
- B. WPA2-only clients will be rejected during association because PMF Required means the AP will only accept association requests from STAs that advertise the MFP Capable and MFP Required bits in their RSN IE; a WPA2-only client that does not support PMF cannot set these bits and will receive an Association Response with status code 31 (MFP policy violation).(correct)
- C. WPA2-only clients will associate in a downgrade mode where PMF is applied only to deauthentication and disassociation frames, and data frames remain unprotected, satisfying both WPA3 PMF policy and WPA2 client compatibility.
- D. PMF Required causes the AP to silently drop all probe responses to WPA2 clients before association begins, making the SSID invisible to those devices even if they are within range.
Explanation: When PMF is configured as 'Required' (MFPR=1 in the RSN Capabilities field of the AP's RSN IE), the AP mandates that associating STAs also support and require MFP. The AP checks that the client's RSN IE includes the Management Frame Protection Capable (MFPC) and Management Frame Protection Required (MFPR) bits. A WPA2-only client that does not support 802.11w will not set these bits, and the AP will reject the Association Request with IEEE 802.11 status code 31 (Association denied because the Information Elements advertising the 802.11w Management Frame Protection policy are inconsistent). Option A is incorrect — PMF Required does affect association eligibility. Option C describes a partial/optional PMF application that does not satisfy 'Required' policy. Option D is incorrect — the AP still broadcasts probe responses.
. During a wireless security audit, an analyst discovers that WPA3-Enterprise is configured but RADIUS accounting is not logging session keys. The compliance team requires forward secrecy for session records. Which attribute of WPA3-Enterprise directly provides per-session forward secrecy at the key derivation level?
- A. WPA3-Enterprise requires the use of PMK caching (PMKSA), which stores the PMK per client; each new session reuses the cached PMK, providing consistent encryption keys that can be audited by the RADIUS server.
- B. WPA3-Enterprise mandates EAP methods that produce a fresh PMK for every authentication session derived from ephemeral key material (e.g., EAP-TLS with ephemeral Diffie-Hellman); compromise of long-term credentials (e.g., the certificate private key) does not allow retroactive decryption of past sessions because each session's keying material was derived from non-reused ephemeral DH parameters.(correct)
- C. Forward secrecy in WPA3-Enterprise is achieved by the WLC rotating the Group Temporal Key (GTK) every 60 seconds, ensuring that a leaked GTK only exposes a 60-second window of multicast traffic.
- D. WPA3-Enterprise provides forward secrecy through the 4-way handshake replay counter; each frame uses an incrementing counter, so captured frames cannot be replayed to derive historical session keys.
Explanation: Forward secrecy in WPA3-Enterprise is achieved through EAP methods that incorporate ephemeral Diffie-Hellman key exchanges (e.g., EAP-TLS with DHE or ECDHE cipher suites, or EAP-PWD). Each authentication session generates unique ephemeral DH key pairs; the resulting PMK is derived from this ephemeral material. Even if an attacker later compromises the long-term private key of the certificate, they cannot compute the ephemeral DH shared secret from recorded handshake traffic, so past session keys remain protected. Option A describes PMKSA caching, which actually works against forward secrecy by reusing PMKs. Option C describes GTK rotation, which is a multicast security measure unrelated to per-session forward secrecy. Option D describes replay protection, not forward secrecy.
. A network engineer uses the Cisco Catalyst Center REST API to programmatically provision a new AP to a specific site and assign it a floor map location. Which HTTP method and API endpoint category would be used to add the AP to the inventory and assign it to a building floor?
- A. GET /dna/intent/api/v1/network-device to retrieve the AP's device ID, followed by POST /dna/intent/api/v1/site-member to assign the AP to a site using its device ID and the target site's siteId.(correct)
- B. PUT /dna/intent/api/v1/wireless/accesspoint-configuration to push AP-specific configuration including site assignment, antenna gain, and channel, using the AP's Ethernet MAC address as the primary key in the request body.
- C. PATCH /dna/system/api/v1/site/{id}/member/ap to add an AP to a site; Catalyst Center does not support POST for AP site membership operations.
- D. DELETE /dna/intent/api/v1/network-device/{id} followed by POST /dna/intent/api/v1/network-device to re-add the AP with updated site information; Catalyst Center requires device deletion before site reassignment.
Explanation: Catalyst Center's Intent API follows a standard pattern: first retrieve the device's UUID via GET /dna/intent/api/v1/network-device (filtering by hostname or management IP), then assign to a site using the site membership API. The site assignment endpoint (v1/site-member or equivalent v2 endpoint) accepts a POST with the device ID array and target siteId. Option B describes the AP configuration API (which is used for RF and antenna settings, not site assignment). Option C is incorrect about PATCH-only restriction. Option D is incorrect — site reassignment does not require device deletion; Catalyst Center supports direct reassignment.
. An Ansible playbook uses the cisco.ios collection to create a new SSID on a Catalyst 9800 WLC. The playbook runs idempotently. On the second run, the WLAN profile already exists with identical parameters. Which behavior is expected, and what Ansible mechanism enables it?
- A. Ansible re-applies the WLAN configuration on every run regardless of current state; the cisco.ios modules do not perform state checks and always push configuration, resulting in 'changed=true' on every execution.
- B. The cisco.ios module for wireless (or cisco.dnac collection for Catalyst Center) checks desired state against current device state; if the WLAN profile exists with matching parameters, the module returns 'changed=false' and makes no changes to the device, demonstrating idempotent behavior.(correct)
- C. Ansible idempotency for WLC configuration requires manually coding a 'when' condition checking a pre-task that queries the current WLAN list; without this custom logic, Ansible will always attempt to create the WLAN and fail with a duplicate-entry error.
- D. WLAN creation via Ansible on Catalyst 9800 is not idempotent because the WLC CLI does not return structured output; Ansible falls back to raw module execution, which has no state-awareness.
Explanation: Cisco's Ansible collections (cisco.ios, cisco.dnac, or the network resource modules designed for C9800) implement declarative state management: modules accept a 'state: present' or 'state: merged' parameter and compare the desired configuration against the device's running state (retrieved via show commands or API calls). If the configuration already matches, the module returns 'changed=false' without pushing any CLI commands. This is the core of Ansible's idempotency for network automation. Option A is incorrect — well-written network modules do perform state comparisons. Option C describes manual workarounds that are unnecessary with proper resource modules. Option D is incorrect — Catalyst 9800 supports NETCONF and REST API backends that provide structured output enabling idempotent operations.
. A network engineer writes a Python script using the Catalyst Center REST API to create a new SSID. The API call to POST /dna/intent/api/v1/wireless/ssid returns HTTP 202 Accepted with a task ID. The engineer immediately queries the SSID list and finds the SSID absent. What does HTTP 202 indicate, and what must the engineer do to confirm successful SSID creation?
- A. HTTP 202 indicates a synchronous operation that completed successfully but with warnings; the SSID should appear within 5 seconds without any additional API calls.
- B. HTTP 202 indicates the request was accepted and queued as an asynchronous task; the engineer must poll GET /dna/intent/api/v1/task/{taskId} until the task's 'isError' field is false and 'endTime' is populated, confirming successful provisioning before querying the SSID list.(correct)
- C. HTTP 202 is an error code indicating partial configuration; the engineer must retry the POST request until HTTP 200 is received, which confirms full SSID creation.
- D. HTTP 202 means the RADIUS server for the SSID was unreachable during provisioning; the SSID is created in a suspended state and requires manual activation via the Catalyst Center GUI.
Explanation: Catalyst Center's Intent API uses an asynchronous task model for provisioning operations. HTTP 202 (Accepted) indicates the server received the request and created a task, but the operation has not necessarily completed yet. The response body contains a taskId. The engineer must poll GET /dna/intent/api/v1/task/{taskId} at intervals, checking the task status fields: 'isError' (boolean for failure), 'progress' (status string), and 'endTime' (populated when complete). Once the task shows completion without error, the provisioned resource (SSID) will be visible in subsequent GET calls. Option A incorrectly describes 202 as synchronous. Option C incorrectly treats 202 as an error. Option D invents a RADIUS-related meaning for 202.
. A network engineer needs to automate the deployment of a new RF profile across 200 APs using Catalyst Center APIs. The design calls for setting the minimum data rate to 12 Mbps on 5 GHz and enabling CleanAir. Which sequence of API operations reflects the correct Catalyst Center workflow?
- A. POST /dna/intent/api/v1/wireless/rf-profile to create the RF profile with the desired parameters, then POST /dna/intent/api/v1/network-profile/wireless to associate the RF profile to a network profile, then assign the network profile to the target site using POST /dna/intent/api/v1/site-profile.(correct)
- B. POST /dna/intent/api/v1/wireless/rf-profile to create the RF profile, then directly PATCH each of the 200 APs individually via /dna/intent/api/v1/network-device/{id}/config, which is more efficient than using site-based assignment.
- C. PUT /dna/intent/api/v1/wireless/rf-profile/{name} replaces all existing RF profiles in the system; each PUT call must include all 200 AP MAC addresses in the request body to associate the profile to specific devices.
- D. The RF profile can only be created via the Catalyst Center GUI; the REST API does not expose RF profile creation or management endpoints.
Explanation: Catalyst Center uses a hierarchical workflow for wireless provisioning: (1) create an RF Profile defining radio parameters (minimum data rates, CleanAir, RRM settings) via POST /dna/intent/api/v1/wireless/rf-profile; (2) create or update a Wireless Network Profile that references the RF profile along with SSID profiles; (3) assign the Network Profile to a site hierarchy level (building or floor) using the site-profile assignment API. All APs at that site inherit the RF profile through site-based provisioning, avoiding the need to configure each AP individually. Option B is incorrect — Catalyst Center does not offer a per-device RF profile PATCH endpoint; site-based assignment is the correct mechanism. Option C incorrectly describes PUT behavior. Option D is wrong — the RF profile API is fully documented and supported.
. Cisco Catalyst Center is configured with a building topology for a 10-floor corporate campus. An engineer opens the 'Heatmap' view for Floor 3. The heatmap shows predicted RSSI coverage but does not reflect a recently installed AP. What is the most likely cause?
- A. The heatmap in Catalyst Center is generated entirely from live RF data collected via RRM neighbor messages; if the new AP has not yet established 10 RRM neighbor relationships, it is excluded from the heatmap calculation.
- B. The new AP has not been placed on the floor map in Catalyst Center's building editor; Catalyst Center uses the manually placed AP positions and their antenna patterns to compute the predictive heatmap, so APs without a map placement are excluded from the visualization.(correct)
- C. Heatmap generation requires the AP to have been associated with at least 50 client devices to gather sufficient RSSI samples; new APs without client history are hidden.
- D. The AP is visible in the heatmap but rendered in grayscale to indicate it is newly discovered; the engineer must refresh the browser cache to see it in the correct color coding.
Explanation: Catalyst Center's wireless heatmap uses a predictive RF model based on floor map data, AP placement coordinates, wall/obstruction attenuation values, and AP antenna patterns. APs must be explicitly placed on the floor map (drag-and-drop or bulk import via CSV) in the Design > Network Hierarchy > Building > Floor view. An AP that has been discovered and joined the WLC but has not been placed on the floor map will not appear in the heatmap, because the predictive model has no positional reference for it. Option A incorrectly describes heatmap generation as purely RRM-neighbor-based. Option C is wrong — client association history is not a prerequisite for heatmap inclusion. Option D invents a grayscale behavior that does not exist.
. A Cisco Catalyst 9800 WLC is configured with a FlexConnect AP group. A client roams between two FlexConnect APs in the same FlexConnect group at a remote site. Both APs are configured for local switching on the client's VLAN. What is the correct behavior for client state during intra-site FlexConnect roaming, and how does the C9800 handle this differently from inter-site roaming?
- A. During intra-site FlexConnect roaming within the same group, the client's L2 state (keys, QoS markings) is synchronized between APs via the FlexConnect group master AP (the AP that anchors the client context); re-authentication is avoided. Inter-site roaming requires a full re-authentication because group context is not shared across sites.(correct)
- B. FlexConnect APs never cache client state locally; all roaming events (intra or inter-site) require a CAPWAP control plane round-trip to the C9800 WLC for re-authentication and key regeneration.
- C. Intra-site FlexConnect roaming and inter-site roaming are handled identically by C9800; both trigger a full 802.1X re-authentication if PMK caching (PMKSA) is not pre-configured.
- D. FlexConnect local switching mode requires all roaming to be handled at Layer 3 via IP mobility; L2 roaming between FlexConnect APs is not supported, so clients receive a new IP address on each roam.
Explanation: In Cisco FlexConnect group intra-site roaming, FlexConnect APs in the same group share client state via a designated master AP (usually the AP with the highest IP address or manually configured). The master AP maintains a client session cache (PMK, PTK, QoS, VLAN binding) for all clients in the group. When a client roams to a new AP in the same group, the new AP retrieves the client context from the master AP, enabling seamless roaming without re-authentication. For inter-site roaming (different FlexConnect groups or different C9800 mobility domains), this group-level cache sharing does not exist, and the WLC handles roaming through its mobility tunnel infrastructure, which may require re-authentication depending on OKC/PMKSA cache availability on the WLC. Options B, C, and D contradict Cisco's FlexConnect group architecture.
. After a software upgrade on a Cisco Catalyst 9800 HA SSO pair, an engineer runs verification and finds that the standby WLC is in 'STANDBY HOT' state. Which statement correctly describes what 'STANDBY HOT' means and what it implies for failover time?
- A. 'STANDBY HOT' means the standby controller has synchronized all active client sessions, AP join states, WLAN configurations, and mobility data from the active controller; in this state, failover is stateful and virtually hitless for client sessions, with AP re-join time near zero.(correct)
- B. 'STANDBY HOT' means the standby controller is powered on and reachable via the management network but has not synchronized client state; failover results in all APs re-joining from scratch and all clients re-authenticating.
- C. 'STANDBY HOT' is a warning state indicating the standby is running a different software version than the active; the engineer must manually synchronize versions before failover is allowed.
- D. 'STANDBY HOT' means both controllers are simultaneously active in an active-active cluster; client sessions are load-balanced between them with automatic failover if one unit fails.
Explanation: In Catalyst 9800 HA SSO, 'STANDBY HOT' is the desired fully synchronized state. It means the standby controller has completed bulk synchronization of all runtime state from the active: AP join records, client association and authentication states, WLAN/policy configurations, mobility tunnel states, and FIB tables. When the active fails, the standby transitions to active with all this state intact — APs do not need to re-join (they simply continue operating because their CAPWAP sessions are preserved), and existing client sessions survive the failover without re-authentication. This is called stateful switchover (SSO). Option B describes a cold-standby scenario. Option C invents a software mismatch meaning. Option D incorrectly describes SSO as active-active load balancing.
. A CCIE candidate is asked to design a multi-site enterprise wireless network where corporate clients at Site A can roam to Site B without re-authentication. WPA3-Enterprise with EAP-TLS is in use. The sites have separate Catalyst 9800 WLCs but share a common RADIUS infrastructure. Which mobility architecture and key caching mechanism enables seamless inter-site roaming without re-authentication?
- A. Configure the two Catalyst 9800 WLCs in a mobility group with inter-controller mobility tunnels (EoIP over CAPWAP); enable opportunistic key caching (OKC/PMKID) on both WLCs; when a client roams from Site A to Site B WLC, the target WLC retrieves the client's PMKSA from the mobility anchor or via PMKID lookup, allowing a fast 4-way handshake without full EAP-TLS re-authentication.(correct)
- B. Configure the RADIUS server with a 30-second session timeout; clients automatically re-authenticate using cached credentials within this window, which is fast enough to be considered seamless roaming from the user experience perspective.
- C. Enable FlexConnect local switching on both WLCs; local switching caches the EAP-TLS client certificate at the AP level, so re-authentication at the target AP uses the locally cached certificate without RADIUS involvement.
- D. Seamless inter-WLC roaming with WPA3-Enterprise EAP-TLS is not possible; EAP-TLS requires full certificate chain validation on every association, and no key caching mechanism can bypass this requirement.
Explanation: For inter-site WLC roaming without re-authentication, the two Catalyst 9800 WLCs must be in the same mobility group (or connected via mobility peers), establishing EoIP-over-CAPWAP mobility tunnels. Opportunistic Key Caching (OKC), also called PMKID-based caching, allows the target WLC to locate the client's existing PMKSA (Pairwise Master Key Security Association) either locally cached or via the mobility anchor WLC. When the client roams, it includes the PMKID in its reassociation request; if the target WLC finds a matching PMKSA, it skips full EAP-TLS exchange and proceeds directly to the 4-way handshake using the cached PMK. This satisfies WPA3-Enterprise requirements while enabling fast roaming. Option B's RADIUS timeout approach still triggers re-authentication. Option C incorrectly claims APs cache EAP-TLS certificates — they do not. Option D is wrong; OKC explicitly addresses this use case.