Skip to main content

Last updated: May 2026

Practice Exam

350-401 ENCORCisco Wireless Core Specialist

Test your knowledge with official exam-style questions

Questions25Passing825/1000Exam time

Questions and options are shuffled each attempt

Cisco Wireless Core SpecialistPractice Set 1: All Questions & Explanations

Full question text, answer options, and explanations for this practice set — a spoiler-free alternative is the interactive quiz above for scored, shuffled practice.

  1. . A network administrator is deploying a Cisco Catalyst 9800 WLC using tag-based architecture. When an AP joins the WLC, the AP receives its SSID configuration from which tag?

    • A. RF tag
    • B. Site tag
    • C. Policy tag(correct)
    • D. AP tag

    Explanation: In Catalyst 9800 tag-based architecture, the policy tag maps WLAN profiles to policy profiles, which defines the SSIDs an AP will broadcast. The RF tag controls radio frequency parameters such as RRM and channel width. The site tag links the AP to a site profile and a flex profile. There is no 'AP tag' in the 9800 architecture.

  2. . An AP is attempting to discover a Cisco Catalyst 9800 WLC for the first time on a network where DHCP option 43 is not configured. The AP is on a different subnet than the WLC. Which discovery method will the AP attempt after the local subnet broadcast fails?

    • A. DNS lookup for cisco-lwapp-controller.local-domain
    • B. DNS lookup for cisco-capwap-controller.local-domain(correct)
    • C. mDNS query for _capwap._udp.local
    • D. Multicast to 239.0.0.1 on UDP port 5246

    Explanation: After a local subnet broadcast fails, the AP performs a DNS lookup for cisco-capwap-controller appended with the domain suffix received from DHCP. This is a standard CAPWAP discovery fallback. LWAPP was the predecessor protocol (option A) and is not used in modern CAPWAP discovery. mDNS (option C) is not part of the standard CAPWAP join process. The CAPWAP multicast address is 239.0.0.1 but it is only valid within the local subnet, not across subnets.

  3. . A company is migrating its wireless network from WPA2-Personal to WPA3-Personal. Which key exchange mechanism does WPA3-Personal use that replaces the Pre-Shared Key (PSK) handshake used in WPA2-Personal?

    • A. EAP-TLS with certificate-based mutual authentication
    • B. SAE (Simultaneous Authentication of Equals)(correct)
    • C. TKIP with 256-bit key derivation
    • D. CCMP with Diffie-Hellman key exchange

    Explanation: WPA3-Personal replaces WPA2's PSK four-way handshake with SAE (Simultaneous Authentication of Equals), also known as Dragonfly. SAE provides forward secrecy and resistance to offline dictionary attacks because each association uses a unique session key. EAP-TLS (option A) is used in WPA3-Enterprise, not Personal mode. TKIP (option C) is deprecated and not used in WPA3. CCMP with DH (option D) does not describe any defined Wi-Fi security mode.

  4. . In the Cisco Catalyst 9800 WLC tag-based architecture, which component defines the RF behavior for an AP, including the RRM parameters, DCA, and TPC settings?

    • A. Policy profile
    • B. WLAN profile
    • C. RF tag(correct)
    • D. Site tag

    Explanation: The RF tag on the Catalyst 9800 links to an RF profile that defines radio frequency parameters including RRM (Radio Resource Management), DCA (Dynamic Channel Assignment), TPC (Transmit Power Control), and band-specific settings. The policy profile defines client connectivity parameters such as VLAN, QoS, and session timeout. The WLAN profile defines the SSID, security type, and radio policy. The site tag defines whether the AP operates in local or FlexConnect mode and associates the AP to a flex profile.

  5. . An AP has completed the CAPWAP discovery phase and received a join response from the Catalyst 9800 WLC. The AP then downloads its image and configuration. In which state does the AP transition to after configuration download is complete and before it begins passing client traffic?

    • A. Discovery state
    • B. Join state
    • C. Configure state
    • D. Run state(correct)

    Explanation: The CAPWAP state machine progresses: Discovery → Join → Image Data (if upgrade needed) → Configure → Run. After the Configure state completes the download of SSID, radio, and policy configuration from the WLC, the AP moves to the Run state where it begins beaconing and passing client traffic. Discovery is the initial state. Join is where the AP selects a WLC and sends a Join Request. Configure is the state just before Run where configuration is downloaded.

  6. . A wireless engineer is troubleshooting a voice SSID on a Catalyst 9800 WLC. A voice client associated on the 5 GHz band reports choppy audio. The 802.11 DCF mechanism is in use. Which value describes the SIFS (Short Inter-Frame Space) that a station must wait before transmitting an ACK frame after receiving a data frame in the 5 GHz band?

    • A. 16 microseconds(correct)
    • B. 10 microseconds
    • C. 2 microseconds
    • D. 50 microseconds

    Explanation: In the 802.11a/n/ac/ax 5 GHz band, the SIFS is 16 microseconds. SIFS is the shortest inter-frame space and is used for high-priority frame exchanges that must not be interrupted: ACKs, CTS responses, and BlockACK frames. The DIFS (DCF Inter-Frame Space) is 34 microseconds in 5 GHz (SIFS + 2 × slot time = 16 + 2×9 = 34 µs). 2 microseconds is not a standard IFS value in 802.11. 50 microseconds is not a standard IFS value.

  7. . A wireless engineer is configuring a FlexConnect AP at a branch office. The WAN link to the central Cisco Catalyst 9800 WLC has failed. Which traffic forwarding behavior occurs for clients associated to an SSID configured for FlexConnect local switching during a WAN outage?

    • A. All client traffic is dropped until the WLC CAPWAP tunnel is restored
    • B. Client traffic is locally switched at the AP to the local LAN; new client authentications using local RADIUS cache can continue(correct)
    • C. Client traffic is forwarded to the nearest WLC discovered by DNS during the outage
    • D. Client traffic falls back to central switching via the backup WLC configured in the FlexConnect group

    Explanation: FlexConnect local switching allows the AP to bridge client traffic directly to the local VLAN without tunneling it back to the WLC. When the WAN link (and thus CAPWAP tunnel) fails, locally switched SSIDs continue to operate in standalone mode. If the AP has a local authentication cache (FlexConnect ACL or local RADIUS credentials), new authentications can also succeed. Central-switched SSIDs will go down because they require the CAPWAP tunnel. Options A, C, and D all describe behaviors that require WLC connectivity.

  8. . On a Cisco Catalyst 9800 WLC, an engineer is configuring a WLAN for local switching in FlexConnect mode. A FlexConnect ACL must be applied to restrict client traffic at the AP. Where is a FlexConnect ACL applied on the Catalyst 9800?

    • A. Applied directly to the WLAN profile under the security tab
    • B. Applied to the flex profile and associated to the AP via the site tag
    • C. Applied to the policy profile under the FlexConnect tab(correct)
    • D. Applied to the AP join profile under the AP policy tab

    Explanation: On the Catalyst 9800, FlexConnect ACLs are configured under the policy profile's FlexConnect tab and are applied per WLAN. The policy profile governs the client policy including VLAN assignment, QoS, and FlexConnect-specific settings. The flex profile (associated via site tag) controls AP-level FlexConnect settings like local VLAN mappings and VLAN-ACL mappings but not per-WLAN client ACLs. The WLAN profile defines SSID parameters but not ACL enforcement at the AP. The AP join profile governs AP management parameters.

  9. . A wireless engineer is designing a 802.11ax (Wi-Fi 6) deployment. The network must support simultaneous downlink transmissions to multiple clients on the same channel at the same time. Which 802.11ax feature enables this capability?

    • A. OFDM with 64-QAM modulation
    • B. DL OFDMA with multi-user resource unit allocation(correct)
    • C. TWT (Target Wake Time) scheduling
    • D. BSS Coloring for spatial reuse

    Explanation: 802.11ax (Wi-Fi 6) introduces DL OFDMA (Downlink Orthogonal Frequency Division Multiple Access) which allows the AP to divide the channel into resource units (RUs) and simultaneously transmit to multiple clients in a single TXOP. This is a fundamental advancement over 802.11ac which could only transmit to one client at a time per TXOP (even with MU-MIMO). OFDM with 64-QAM (option A) describes 802.11a/g modulation, not an 802.11ax-specific multi-user feature. TWT (option C) is an 802.11ax feature for IoT power saving, not simultaneous multi-client transmission. BSS Coloring (option D) reduces co-channel interference from neighboring BSSs but does not enable simultaneous transmissions to multiple clients.

  10. . A client laptop is attempting to associate to a wireless SSID. According to 802.11 CSMA/CA with DCF, what must a station verify before initiating a transmission after waiting a DIFS period?

    • A. The station must verify the channel is idle for a DIFS period and then immediately transmit
    • B. The station must verify the channel is idle for a DIFS period and then wait an additional random backoff before transmitting(correct)
    • C. The station must send an RTS frame after the DIFS period and wait for a CTS before transmitting
    • D. The station must receive a beacon from the AP before it is permitted to transmit

    Explanation: In 802.11 DCF (Distributed Coordination Function), a station that senses the channel idle for a DIFS period does not immediately transmit. It enters a random backoff window (a random number of slot times) and counts down the backoff while the channel remains idle. Only when the backoff counter reaches zero does the station transmit. This randomized backoff is the core collision avoidance mechanism of CSMA/CA. Option A describes a collision-prone protocol (like CSMA/CD). Option C (RTS/CTS) is an optional DCF enhancement for hidden-node mitigation, not the mandatory baseline behavior. Option D describes the association process, not the per-frame transmission procedure.

  11. . An engineer is deploying a Cisco Catalyst 9800 WLC and configuring the tag-based AP provisioning system. The engineer creates a policy tag that binds a WLAN profile to a policy profile. Where must the policy tag be assigned for it to take effect on an AP?

    • A. Assigned to the RF profile under the radio configuration
    • B. Assigned directly to the AP under the AP configuration(correct)
    • C. Assigned to the flex profile under the site configuration
    • D. Assigned to the WLAN profile under the advanced tab

    Explanation: On the Catalyst 9800, all three tags (policy tag, site tag, and RF tag) are assigned directly to individual APs under AP > General configuration, or via a default tag set for APs that have not been explicitly configured. The policy tag binding determines which WLAN-to-policy-profile mappings the AP uses. RF profiles are assigned to AP radio interfaces, not via the tag system. The flex profile is referenced by the site tag, not the policy tag. There is no tag assignment under the WLAN profile.

  12. . A wireless security engineer is reviewing the WPA3 transition mode deployment on a Catalyst 9800 WLC. In WPA3 transition mode (WPA3/WPA2 mixed mode), which security behavior is enforced?

    • A. WPA3 clients must use SAE; WPA2 clients are rejected and must upgrade firmware
    • B. WPA3 clients use SAE; WPA2 clients use PSK; both can associate to the same SSID(correct)
    • C. All clients use SAE but WPA2 clients may downgrade to PSK if SAE handshake fails
    • D. The SSID broadcasts both WPA2 and WPA3 information elements; clients must use WPA3 or TKIP

    Explanation: WPA3 Transition Mode (also called WPA3/WPA2 mixed mode) allows WPA3 clients to authenticate using SAE while WPA2 clients authenticate using PSK (WPA2-Personal) on the same SSID. This provides a migration path without requiring all clients to support WPA3 simultaneously. Option A is incorrect because WPA2 clients are not rejected in transition mode. Option C describes a downgrade behavior that would undermine SAE's security benefits. Option D is incorrect because TKIP is deprecated and not permitted in WPA3 configurations.

  13. . A security analyst discovers that clients on a wireless SSID can communicate directly with each other at Layer 2. The analyst needs to prevent client-to-client communication on the same SSID without creating separate SSIDs. Which Catalyst 9800 feature accomplishes this?

    • A. Enable P2P blocking on the policy profile(correct)
    • B. Configure a FlexConnect ACL to deny inter-client traffic
    • C. Enable Dynamic ARP Inspection on the client VLAN
    • D. Configure private VLANs (PVLANs) on the upstream switch

    Explanation: P2P (peer-to-peer) blocking on the Catalyst 9800 policy profile prevents clients associated to the same SSID from directly communicating with each other, even when on the same VLAN. The WLC drops or redirects inter-client frames before they are forwarded. FlexConnect ACLs (option B) are applied at the AP level but are designed for VLAN-based access control, not wireless peer isolation. Dynamic ARP Inspection (option C) prevents ARP spoofing but does not block peer data communication. Private VLANs (option D) work at Layer 2 on switches and would require every client to be on an isolated PVLAN port, which is complex and separate from the WLC configuration.

  14. . An enterprise wireless network uses 802.1X/EAP with a Cisco ISE RADIUS server. The EAP method in use passes the client's username and password inside a TLS tunnel. Mutual authentication is performed; the server presents a certificate and the client authenticates via MSCHAPv2 inside the tunnel. Which EAP method is described?

    • A. EAP-TLS
    • B. EAP-FAST
    • C. PEAP (Protected EAP) with MSCHAPv2(correct)
    • D. EAP-TTLS with PAP inner method

    Explanation: PEAP (Protected EAP) with MSCHAPv2 is the most widely deployed enterprise EAP method. It creates an outer TLS tunnel using the server's certificate (providing server authentication), then performs MSCHAPv2 username/password authentication inside the tunnel. The client does not need a certificate, only the server does. EAP-TLS (option A) requires both the server and client to present certificates — there is no username/password. EAP-FAST (option B) uses PAC (Protected Access Credential) files, not TLS certificates, for tunnel establishment. EAP-TTLS (option D) is similar to PEAP but uses a different inner method; with PAP (not MSCHAPv2) as specified.

  15. . A wireless engineer is using Cisco Catalyst Center's wireless assurance features to investigate a high client onboarding failure rate at a specific AP. Which Catalyst Center feature provides a per-client view of the full association, authentication, and DHCP timeline with event-level details?

    • A. Network heatmap view under the wireless floor map
    • B. Client 360 view showing the onboarding timeline events(correct)
    • C. AP detail page showing the RF neighbor list
    • D. Assurance issues dashboard showing global health scores

    Explanation: Cisco Catalyst Center's Client 360 view provides a comprehensive timeline for individual clients showing each step of the onboarding process: 802.11 association, 802.1X authentication (and EAP exchange steps), DHCP exchange, and WebAuth if applicable. Each event is timestamped with success or failure indicators and error codes. The heatmap (option A) shows RF coverage and signal strength across a floor plan, useful for coverage design but not per-client event detail. The AP detail page (option C) shows AP-level statistics and neighbor lists. The assurance issues dashboard (option D) shows aggregate health scores, not per-client onboarding event sequences.

  16. . A network engineer needs to automate the deployment of a new WLAN profile on a Cisco Catalyst 9800 WLC. The engineer wants to use RESTCONF with YANG models. Which URL path prefix is used to access RESTCONF on a Catalyst 9800 running IOS XE?

    • A. https://<wlc-ip>/api/v1/
    • B. https://<wlc-ip>/restconf/data/(correct)
    • C. https://<wlc-ip>/mgmt/restconf/
    • D. https://<wlc-ip>/netconf/data/

    Explanation: RESTCONF on Cisco IOS XE (including Catalyst 9800) uses the base URL path /restconf/data/ to access data resources, following RFC 8040. The root resource is /restconf/ and data nodes are accessed under /restconf/data/. YANG modules can be discovered at /restconf/yang-library-version. Option A (/api/v1/) is used by the Cisco NX-OS REST API, not IOS XE RESTCONF. Option C (/mgmt/restconf/) is not a valid IOS XE path. Option D (/netconf/data/) confuses NETCONF (which uses XML over SSH on port 830) with RESTCONF.

  17. . An automation engineer is using Ansible to configure multiple Cisco Catalyst 9800 WLCs. The playbook must retrieve the current list of WLANs configured on the WLC using the cisco.ios collection. Which Ansible module is most appropriate for executing a show command and returning the structured output?

    • A. cisco.ios.ios_command with register to capture output(correct)
    • B. cisco.ios.ios_config with lines parameter
    • C. ansible.netcommon.cli_config with rollback enabled
    • D. cisco.ios.ios_facts to enumerate interface statistics

    Explanation: The cisco.ios.ios_command module is used to run arbitrary show commands on IOS/IOS XE devices and capture the output using the register keyword. The output can then be parsed with TextFSM or Genie for structured data extraction. ios_config (option B) is used to push configuration changes, not retrieve information. ansible.netcommon.cli_config (option C) is also a configuration module. ios_facts (option D) collects a predefined set of facts (interfaces, neighbors, etc.) but does not execute arbitrary show commands or return WLAN-specific data.

  18. . A network engineer is deploying a Cisco Catalyst 9800-CL (cloud-based WLC) on VMware ESXi. Which deployment model does the 9800-CL represent in the context of WLC virtualization?

    • A. WLC deployed as a physical appliance with hardware-assisted wireless processing
    • B. WLC deployed as a virtual machine on a hypervisor, providing WLC functionality without dedicated hardware(correct)
    • C. WLC embedded directly in a Cisco Catalyst 9000 series switch
    • D. WLC deployed as a container on Cisco Application Hosting on IOS XE

    Explanation: The Cisco Catalyst 9800-CL is a cloud/virtual form factor of the 9800 WLC that runs as a virtual machine on hypervisors such as VMware ESXi, KVM, or in public clouds (AWS, Azure). It provides the same IOS XE-based WLC functionality as the hardware 9800-40 or 9800-80 appliances without requiring dedicated hardware. Option A describes the 9800-40 or 9800-80 physical appliances. Option C describes the embedded wireless controller feature on Catalyst 9000 switches (C9300/C9500 with a wireless license). Option D describes application hosting (IOx/AppHosting) for third-party apps on IOS XE, not the WLC itself.

  19. . An AP is broadcasting a 2.4 GHz SSID on channel 6 and a 5 GHz SSID on channel 36. A neighboring AP is also on channel 6 for 2.4 GHz but on a different non-overlapping 5 GHz channel. The 2.4 GHz environment shows high co-channel interference. Which of the following changes would MOST effectively reduce co-channel interference on 2.4 GHz?

    • A. Increase the Tx power on both APs on channel 6 to improve SNR for associated clients
    • B. Reduce the Tx power on the APs to shrink cell sizes and configure non-overlapping channels (1, 6, 11) with adequate inter-AP spacing(correct)
    • C. Change both APs to channel 3 to use a less crowded 2.4 GHz channel
    • D. Enable 802.11ax BSS Coloring to eliminate co-channel interference between the two APs

    Explanation: Co-channel interference on 2.4 GHz is reduced by: (1) using only non-overlapping channels 1, 6, and 11, and (2) reducing Tx power to shrink the cell size so that only clients near each AP are competing for the same channel. Increasing Tx power (option A) increases the interference footprint, making the problem worse. Channel 3 (option C) overlaps with both channels 1 and 6, which creates adjacent-channel interference — worse than co-channel interference. BSS Coloring (option D) is an 802.11ax spatial reuse feature that helps stations identify whether a detected signal is from their BSS or another BSS, allowing them to ignore the other-BSS signal in some cases, but it does not eliminate contention between two APs on the same channel that are within range of each other's clients.

  20. . A network engineer is reviewing a Python script that uses the Cisco Catalyst Center SDK to retrieve all wireless clients. The API call returns a JSON response. The engineer needs to extract the MAC address of each client from the nested JSON. The response structure is: {"response": [{"macAddress": "aa:bb:cc:dd:ee:ff", "ipv4Address": "10.1.1.1"}]}. Which Python expression correctly extracts the MAC address of the first client?

    • A. response['macAddress']
    • B. response['response'][0]['macAddress'](correct)
    • C. response[0]['macAddress']
    • D. response['response']['macAddress']

    Explanation: The JSON structure has a top-level key 'response' whose value is a list of client objects. To access the first client's MAC address: first access response['response'] to get the list, then [0] to get the first item in the list, then ['macAddress'] to get the value. Option A is missing the intermediate 'response' key and list index. Option C skips the 'response' key. Option D tries to access 'macAddress' on a list object (response['response'] returns a list), which would raise a TypeError.

  21. . A Cisco Catalyst 9800 WLC is configured with two APs in a FlexConnect group. Both APs serve the same SSID with local switching. A client roams from AP1 (VLAN 10, subnet 10.1.10.0/24) to AP2 (VLAN 20, subnet 10.1.20.0/24). The client retains its original IP address 10.1.10.50/24. After roaming to AP2, what happens to traffic from the client destined to the default gateway?

    • A. The WLC creates a GRE tunnel between AP1 and AP2 to maintain the client's IP on VLAN 10 via AP2
    • B. The client's traffic is sent from AP2 on VLAN 20 with the client's original IP 10.1.10.50; return traffic for 10.1.10.50 is routed back to the 10.1.10.0/24 gateway and the client will not receive it without re-authentication(correct)
    • C. FlexConnect seamless roaming automatically reassigns the client a new IP address from VLAN 20's DHCP scope
    • D. The WLC anchors the client's VLAN 10 traffic via the anchor WLC at the central site, maintaining connectivity across subnets

    Explanation: This is a Layer 3 roaming scenario in FlexConnect with local switching. Since each AP locally switches to a different VLAN/subnet, there is no centralized WLC data path to maintain subnet continuity. When the client moves to AP2 on VLAN 20, its traffic is injected into VLAN 20 with the original IP (10.1.10.50), which is foreign to that subnet. Return traffic routed to 10.1.10.0/24 goes to the original subnet's gateway, and because the client is no longer reachable there, connectivity breaks. The client must renew its IP address via DHCP on the new subnet. Option A (inter-AP GRE tunnel) is used in centralized mode, not FlexConnect local switching. Option C is incorrect — FlexConnect does not automatically trigger DHCP renewal on roam. Option D (anchor WLC) applies to guest anchoring or mobility tunneling in centralized mode, not FlexConnect L3 roaming.

  22. . An enterprise network uses 802.1X wireless authentication with Cisco ISE. An engineer discovers that the ISE server certificate has expired, and PEAP-MSCHAPv2 authentications are failing. Clients running Windows 10 with default supplicant settings are rejecting the server. Which condition in the EAP exchange causes the client to reject the authentication?

    • A. The RADIUS shared secret between the WLC and ISE has changed, causing RADIUS Access-Reject messages
    • B. The client's supplicant validates the ISE server certificate during TLS handshake; an expired certificate fails validation and the supplicant sends an EAP-Failure to terminate the session(correct)
    • C. The AP cannot form the CAPWAP tunnel to the WLC because the CAPWAP control channel uses the ISE certificate for encryption
    • D. The WLC rejects the EAP-Response/Identity from the client because the ISE RADIUS certificate is in the WLC's untrusted certificate store

    Explanation: In PEAP, the outer TLS handshake requires the client supplicant to validate the RADIUS server's (ISE's) certificate. Windows 10's default 802.1X supplicant validates the server certificate chain including expiry date. When the certificate is expired, the TLS handshake fails and the supplicant terminates the EAP exchange. The WLC relays the EAP messages as RADIUS packets; it does not inspect or validate the ISE certificate itself. Option A (RADIUS shared secret mismatch) would produce RADIUS decryption failures or Access-Reject but is unrelated to certificate expiry. Option C is incorrect — CAPWAP uses a separate PKI/self-signed cert between the AP and WLC, independent of ISE. Option D is incorrect — the WLC acts as a RADIUS proxy/authenticator and does not validate the EAP server certificate.

  23. . A wireless engineer is analyzing a 5 GHz 802.11ax BSS. The AP supports 4×4:4 MU-MIMO and 160 MHz channel width. The engineer wants to determine the maximum theoretical PHY data rate for a single spatial stream with 1024-QAM modulation at MCS11, 160 MHz channel width, and 0.8 µs GI. What is the approximate maximum single-stream PHY rate?

    • A. 600 Mbps
    • B. 1201 Mbps(correct)
    • C. 2402 Mbps
    • D. 9608 Mbps

    Explanation: For 802.11ax at 160 MHz with MCS11 (1024-QAM 5/6 coding) and 0.8 µs GI, the single spatial stream (NSS=1) PHY rate is approximately 1201 Mbps. The formula uses subcarrier count (980 data subcarriers for 160 MHz in 802.11ax), symbol duration (12.8 µs + 0.8 µs GI = 13.6 µs), bits per subcarrier (10 bits for 1024-QAM × 5/6 coding). With 4 spatial streams, the maximum 4×4 MU-MIMO rate at 160 MHz MCS11 is approximately 4804 Mbps. 600 Mbps (option A) is a common 802.11n rate (4-stream 40 MHz). 2402 Mbps (option C) is the 2-stream 160 MHz MCS11 rate. 9608 Mbps (option D) is the approximate 8-stream 160 MHz theoretical maximum.

  24. . A wireless engineer is using Cisco Catalyst Center wireless assurance and notices that a specific AP shows a high 'client onboarding time' metric, consistently over 8 seconds for 802.1X clients. The AP hardware and radio health are normal. The Client 360 view shows the 802.11 association step completes in under 100 ms but the RADIUS authentication step takes over 7 seconds. Which component is MOST likely causing the delay?

    • A. The WLC is processing too many CAPWAP control messages from the AP, causing WLC CPU overload
    • B. The RADIUS server (ISE) response time is high, indicating ISE processing delay, AD query delay, or network latency between the WLC and ISE(correct)
    • C. The client supplicant is slow to generate the EAP-Response because the client CPU is overloaded
    • D. The AP is dropping CAPWAP data frames due to MTU mismatch between the AP and the WLC

    Explanation: The Client 360 timeline shows that the 802.11 association (the wireless layer) completes quickly. The 7-second delay is in the RADIUS authentication phase, which involves the WLC sending RADIUS Access-Request to ISE and waiting for RADIUS Access-Accept or Access-Reject. Delays in this phase are caused by: ISE policy processing (complex authorization policies, AD group lookups), Active Directory query latency (DC unreachable or slow), or network latency/packet loss between the WLC and ISE. The AP and CAPWAP are not involved in RADIUS message exchange — that occurs between the WLC and ISE directly. Client supplicant CPU (option C) would delay the EAP-Response message in the wireless exchange, but this would show as a wireless-phase delay, not RADIUS phase. CAPWAP MTU issues (option D) would cause data forwarding problems, not authentication delays.

  25. . A security engineer is configuring Management Frame Protection (MFP) on a Cisco Catalyst 9800 WLC. Infrastructure MFP is enabled. An AP detects an 802.11 deauthentication frame that has been transmitted without a valid MFP signature. What action does the AP take when it detects this anomaly?

    • A. The AP immediately disconnects all clients on that SSID and forces re-authentication
    • B. The AP reports the anomaly as a rogue management frame event to the WLC, which logs it and can generate an alarm(correct)
    • C. The AP responds with a protected deauthentication frame to block the attacking station
    • D. The AP increases the Tx power to override the attacking station's signal

    Explanation: Cisco Infrastructure MFP (iMFP) adds a message integrity check (MIC) to management frames sent by APs. When an AP receives a management frame (such as a deauthentication) that lacks a valid iMFP signature or has an invalid one, the AP treats it as a rogue management frame and reports the event to the WLC. The WLC logs the anomaly and can generate an SNMP trap or alarm for the security team. Infrastructure MFP is a detection mechanism — it does not automatically disconnect clients (option A) or transmit counter-frames (option C). Tx power adjustment (option D) is not a security response mechanism.