Skip to main content

Last updated: May 2026

Practice Exam

300-425 ENWLSDCisco Wireless Design Specialist

Test your knowledge with official exam-style questions

Questions25Passing750/1000Exam time

Questions and options are shuffled each attempt

Cisco Wireless Design SpecialistPractice Set 1: All Questions & Explanations

Full question text, answer options, and explanations for this practice set — a spoiler-free alternative is the interactive quiz above for scored, shuffled practice.

  1. . A wireless design engineer is planning a site survey for a new enterprise office. The customer wants to see expected coverage before any APs are physically installed. Which type of site survey should the engineer perform?

    • A. Passive survey using a spectrum analyzer
    • B. Active survey with associated client adapters
    • C. Predictive survey using RF modeling software(correct)
    • D. Intrusive survey requiring temporary AP placement

    Explanation: A predictive (or virtual) survey uses RF modeling software such as Ekahau Site Survey or Cisco Prime Infrastructure to simulate AP placement, antenna patterns, and RF propagation based on building floor plans and material attenuation data. This is performed before physical installation and allows the customer to visualize expected coverage. A passive survey (option A) requires APs to be operating and captures ambient RF — used for validating deployments or auditing existing WLANs. An active survey (option B) requires a client to associate to real APs and measures throughput. An intrusive survey (option D) places temporary APs and is a pre-deployment validation step, not a pre-installation planning method.

  2. . A wireless design engineer is setting minimum RSSI design thresholds for a healthcare campus that requires voice-grade wireless coverage for Wi-Fi calling handsets. What is the minimum receive signal level (RSSI) typically required at the client for reliable voice over wireless?

    • A. -85 dBm
    • B. -72 dBm
    • C. -67 dBm(correct)
    • D. -55 dBm

    Explanation: The widely accepted minimum RSSI threshold for voice-grade wireless coverage is -67 dBm. This value is specified in the Cisco design guides for wireless voice deployments, ensuring adequate SNR for reliable call quality with minimal packet loss and jitter. A threshold of -72 dBm (option B) is the minimum for general data coverage. A threshold of -85 dBm (option A) represents the noise floor range and is insufficient for any reliable connectivity. A threshold of -55 dBm (option D) is an excellent signal but is not the minimum requirement — it represents a very high-quality signal that would typically only exist very close to an AP.

  3. . A wireless design engineer is planning the switch infrastructure for a new deployment of Cisco Catalyst 9120 APs (Wi-Fi 6). These APs require more power than standard PoE (802.3af). Which PoE standard provides up to 30W of power to support these APs?

    • A. 802.3af (PoE) — 15.4W
    • B. 802.3at (PoE+) — 30W(correct)
    • C. 802.3bt Type 3 (PoE++) — 60W
    • D. 802.3bt Type 4 (PoE++) — 90W

    Explanation: IEEE 802.3at (PoE+) provides up to 30W at the PSE (power sourcing equipment, typically the switch port), with up to 25.5W available at the powered device. This is sufficient for Wi-Fi 6 APs like the Cisco Catalyst 9120. The older 802.3af standard (option A) provides only 15.4W, which is insufficient for Wi-Fi 6 APs. 802.3bt Type 3 (option C) at 60W and Type 4 (option D) at 90W are used for high-power devices such as Wi-Fi 6E APs (e.g., Cisco Catalyst 9136 which can use 802.3bt) and powered IP cameras with PTZ.

  4. . An enterprise wireless network uses multiple Cisco Catalyst 9800 WLCs. A client roams between two APs connected to different WLCs but remains on the same IP subnet. Which type of roaming is this?

    • A. Layer 2 inter-controller roam(correct)
    • B. Layer 3 inter-controller roam with IP anchor
    • C. FlexConnect local roam
    • D. Intra-controller roam

    Explanation: A Layer 2 inter-controller roam occurs when a client moves between APs on different WLCs but remains on the same IP subnet. The client retains its IP address because the VLAN is stretched across the WLC mobility domain. The mobility group between the WLCs enables the state transfer. A Layer 3 inter-controller roam (option B) occurs when the subnets differ between controllers, requiring an anchor WLC to maintain the original IP. A FlexConnect local roam (option C) is between APs on the same FlexConnect group without WLC involvement. An intra-controller roam (option D) is between two APs on the same WLC.

  5. . A wireless design engineer is planning AP placement for a dense office environment. The floor plan has a mix of open office areas and private offices with drywall partitions. The engineer is using Ekahau Site Survey for predictive modeling. What attenuation value should the engineer configure for a standard drywall (single layer, 5/8 inch gypsum) partition?

    • A. 1 dB per wall
    • B. 3 dB per wall(correct)
    • C. 8 dB per wall
    • D. 15 dB per wall

    Explanation: Standard drywall (gypsum board, single layer) attenuates 2.4 GHz and 5 GHz RF signals by approximately 3 dB per wall. This value is commonly used in RF modeling tools for typical office construction. Brick walls (option C — ~8 dB) cause significantly more attenuation. Concrete walls or floors (option D — ~15 dB) are the most attenuating common building materials. A value of 1 dB (option A) is too low; even a thin interior partition causes measurable signal loss.

  6. . A wireless engineer is designing AP channel reuse for a large enterprise using 2.4 GHz. The engineer needs to ensure adjacent APs do not cause adjacent-channel interference. How many non-overlapping 20 MHz channels are available in the 2.4 GHz band in North America?

    • A. 2 non-overlapping channels (1 and 11)
    • B. 3 non-overlapping channels (1, 6, and 11)(correct)
    • C. 4 non-overlapping channels (1, 5, 9, and 13)
    • D. 6 non-overlapping channels (1, 3, 5, 7, 9, and 11)

    Explanation: In North America, the 2.4 GHz band supports 11 channels (1–11 in the US, 1–13 in Europe). Each 20 MHz channel occupies 22 MHz of spectrum, and channels must be separated by 5 channels to avoid overlap. This yields exactly 3 non-overlapping channels: 1, 6, and 11. Using only these three channels prevents adjacent-channel interference in 2.4 GHz networks. The 5 GHz band offers far more non-overlapping channels (up to 25 in the US across UNII-1, UNII-2, UNII-2e, and UNII-3 bands), which is why 5 GHz is preferred for high-density deployments.

  7. . A wireless design engineer is planning a wireless deployment for a hospital where nurses carry 802.11 voice handsets between floors and wings. What is the recommended cell overlap percentage between adjacent APs to ensure seamless client roaming?

    • A. 5% overlap
    • B. 15–20% overlap(correct)
    • C. 35–40% overlap
    • D. 50% overlap

    Explanation: For seamless client roaming, adjacent APs should have a 15–20% cell overlap at the minimum RSSI threshold. This overlap ensures that as a client moves away from one AP and the signal falls to the roaming threshold (typically -72 dBm for voice), the neighboring AP signal is already above the threshold, allowing the client to transition without coverage gaps. Less than 15% overlap (option A — 5%) risks coverage holes between APs. More than 30% overlap (options C and D) wastes capacity through excessive co-channel interference in 2.4 GHz and reduces spatial reuse in 5 GHz.

  8. . A wireless engineer is configuring the switch port that connects a Cisco Catalyst 9130 AP. The AP will serve three SSIDs mapped to VLANs 10, 20, and 30. The management VLAN is VLAN 100. Which switch port configuration is required?

    • A. Access port assigned to VLAN 10
    • B. Trunk port with VLANs 10, 20, 30, and 100 permitted; native VLAN set to VLAN 100(correct)
    • C. Trunk port with all VLANs permitted; native VLAN set to VLAN 1
    • D. Access port assigned to VLAN 100 with inter-VLAN routing configured on the AP

    Explanation: When an AP serves multiple SSIDs mapped to different VLANs, the switch port must be configured as a trunk port to carry all required VLANs. The management VLAN (VLAN 100) should be the native VLAN on the trunk so that the AP's management traffic (CAPWAP, management IP) is untagged. VLANs 10, 20, and 30 are tagged. An access port (option A or D) can only carry one VLAN and cannot support multiple SSID-to-VLAN mappings. Allowing all VLANs (option C) with native VLAN 1 is a security risk and does not follow best practice — only the required VLANs should be permitted.

  9. . An engineer is designing the wired infrastructure for a wireless deployment. APs will be connected to access layer switches via Cat6 cabling. What is the maximum cable run length for Cat6 structured cabling before signal degradation affects both data and PoE delivery?

    • A. 50 meters
    • B. 100 meters(correct)
    • C. 150 meters
    • D. 200 meters

    Explanation: The TIA-568 and IEEE standards specify a maximum horizontal cable run of 100 meters (including patch cables at both ends) for Cat5e, Cat6, and Cat6A structured cabling for both data (1000BASE-T, 10GBASE-T) and PoE delivery. Beyond 100 meters, resistance increases cause excessive voltage drop for PoE and signal degradation for data. For PoE over long runs, the actual power available at the device decreases due to cable resistance; 802.3bt recommends de-rating power for runs over 70 meters.

  10. . A wireless engineer is configuring the switch ports for APs in a campus deployment. The engineer needs to prevent APs from sending BPDUs that could destabilize the spanning tree topology while also ensuring that the ports transition to forwarding immediately upon AP connection. Which switch port configuration should be applied?

    • A. Configure the port as a trunk with VTP mode transparent
    • B. Configure PortFast and BPDU Guard on the AP switch port(correct)
    • C. Configure BPDU Filter to drop all BPDUs and enable trunking
    • D. Configure STP root guard to prevent the AP from becoming root bridge

    Explanation: PortFast bypasses the STP listening and learning states, causing the port to transition directly to forwarding when the link comes up, reducing AP boot time. BPDU Guard protects the spanning tree topology: if any BPDU is received on a PortFast-enabled port (as would happen if a rogue switch were connected), the port is immediately placed in an error-disabled state. Together they are the standard recommendation for end-device ports including AP switch ports. BPDU Filter (option C) silently drops BPDUs in both directions — this can create STP loops if misapplied and is not the recommended AP port configuration. Root Guard (option D) prevents the connected device from becoming the STP root but does not address port transition timing.

  11. . A wireless engineer is designing WLC HA (High Availability SSO) for a Cisco Catalyst 9800. The design requires that in the event of an active WLC failure, associated APs and clients maintain connectivity with zero re-association. Which HA component provides the dedicated synchronization link between the active and standby WLC?

    • A. The management interface on the active WLC sends keepalives to the standby WLC every 30 seconds
    • B. The Redundancy Port (RP) link — a dedicated direct connection between the two WLCs for state synchronization(correct)
    • C. The wireless AP CAPWAP tunnel carries heartbeat messages to detect WLC failure
    • D. The virtual IP address shared between both WLCs provides the failover synchronization path

    Explanation: Cisco Catalyst 9800 HA SSO uses a dedicated Redundancy Port (RP) link — typically a direct Ethernet cable or a dedicated VLAN — between the active and standby WLC to continuously synchronize AP associations, client states, CAPWAP sessions, and configuration. This enables sub-second failover with no client re-association. The management interface (option A) carries management traffic but not real-time state sync. CAPWAP tunnels (option C) go to the WLC management IP but do not carry WLC-to-WLC state synchronization. Virtual IP (option D) is a component of HA configuration allowing APs to reach the WLC pair, but it is not the synchronization mechanism.

  12. . A wireless engineer is designing AP failover for a campus network with three Cisco Catalyst 9800 WLCs (WLC1, WLC2, WLC3). APs should prefer WLC1 as primary, use WLC2 as secondary, and WLC3 as tertiary. Which configuration on the AP ensures this ordered failover preference?

    • A. Configure the AP join priority as high on WLC1, medium on WLC2, and low on WLC3
    • B. Configure the primary, secondary, and tertiary WLC controller names on each AP(correct)
    • C. Configure the AP group on the WLC to include all three WLCs in priority order
    • D. Configure DHCP option 43 with all three WLC IPs in order of preference

    Explanation: On Cisco WLCs, each AP can be configured with a primary, secondary, and tertiary WLC controller name (using the WLC system name or IP). The AP tries to join the primary first; if unavailable, it tries secondary, then tertiary. This configuration persists on the AP and ensures deterministic failover ordering. AP join priority (option A) is configured on the WLC side to determine which APs are admitted first when WLC capacity is constrained — it controls admission, not failover order. AP groups (option C) define SSID sets on a WLC but do not configure failover between WLCs. DHCP option 43 (option D) provides WLC IPs for initial discovery but does not configure primary/secondary/tertiary persistent preference on the AP.

  13. . A wireless engineer is designing roaming for a hospital with VoIP handsets. The handsets support 802.11r (Fast BSS Transition). Which 802.11r over-the-DS method is preferred when the handset needs to pre-negotiate keys with the target AP before physically roaming, using the current AP as a relay?

    • A. Fast BSS Transition over-the-Air (FT OTA) — the client communicates directly with the target AP before re-association
    • B. Fast BSS Transition over-the-DS (FT DS) — the client sends FT Action frames through the current AP to the target AP via the distribution system(correct)
    • C. OKC (Opportunistic Key Caching) — the client caches the PMK from a previous association on the target AP
    • D. 802.11k neighbor report — the client queries the current AP for neighboring AP information before roaming

    Explanation: 802.11r Fast BSS Transition over-the-DS (FT DS) allows the client to send FT Action Request/Response frames via the current AP to the target AP through the distribution system (wired backbone), pre-negotiating the PTK (Pairwise Transient Key) before the physical roam. When the client re-associates to the target AP, the key exchange is already complete, enabling sub-50ms roaming. FT over-the-Air (option A) has the client communicate directly with the target AP over the air before re-association — requires the target AP to be within range. OKC (option C) is a Cisco proprietary pre-standard mechanism predating 802.11r. 802.11k (option D) is a roaming guidance protocol, not a fast key exchange method.

  14. . A wireless engineer is designing roaming assistance for mobile clients in a large campus. The engineer wants APs to actively send unsolicited recommendations to clients that have weak RSSI, suggesting better APs to roam to without requiring the client to initiate a neighbor query. Which 802.11 protocol enables this network-assisted, AP-initiated roaming recommendation?

    • A. 802.11k — AP sends a Neighbor Report Response only when requested by the client
    • B. 802.11r — AP sends FT Information Elements in beacons to guide roaming
    • C. 802.11v BSS Transition Management — AP sends BSS Transition Management Request to the client(correct)
    • D. 802.11u (Hotspot 2.0) — AP sends venue information to guide client association

    Explanation: IEEE 802.11v BSS Transition Management allows the AP (or WLC on the AP's behalf) to send a BSS Transition Management Request frame to a client that has weak signal. The frame contains a candidate BSS list (preferred target APs) and can request that the client transition. This is network-assisted, AP-initiated roaming. 802.11k (option A) is a neighbor report protocol where the client sends a Neighbor Report Request and the AP responds — it is client-initiated, not AP-initiated. 802.11r (option B) addresses fast re-authentication during the roam but does not guide the client to roam. 802.11u (option D) is the inter-working standard for Hotspot 2.0/Passpoint, not enterprise roaming guidance.

  15. . A client device is roaming between two APs on the same Cisco Catalyst 9800 WLC, but on different subnets (AP1 on VLAN 10 / 10.1.10.0/24, AP2 on VLAN 20 / 10.1.20.0/24). The WLC uses a guest anchor design to maintain the client's original IP address on VLAN 10 after it roams to AP2. Which mobility component on the Catalyst 9800 enables this IP continuity?

    • A. The foreign WLC tunnels client traffic to the anchor WLC via an EoIP mobility tunnel(correct)
    • B. The WLC uses LISP map-server to advertise the client's IP to all routing peers
    • C. The WLC updates the ARP table on the upstream switch to move the client IP to VLAN 20
    • D. The WLC uses Proxy Mobile IP to update the home agent with the client's new location

    Explanation: In a Cisco Catalyst 9800 Layer 3 inter-controller (or intra-controller inter-subnet) roam, the WLC where the client originally associated becomes the anchor, and the WLC where the client is currently associated becomes the foreign. The foreign WLC tunnels the client's data traffic back to the anchor WLC via an EoIP (Ethernet over IP) mobility tunnel, preserving the client's original subnet and IP address. LISP (option B) is used in Cisco SD-Access for endpoint mobility, not in traditional WLC-based wireless mobility. ARP table updates (option C) would only affect Layer 2 forwarding within a subnet and cannot maintain an IP address across subnets. Proxy Mobile IP (option D) is a standard mobile IP variant but is not how Cisco WLC L3 roaming is implemented.

  16. . A wireless engineer is designing a high-density Wi-Fi deployment for a university lecture hall that seats 400 students, all expected to use Wi-Fi simultaneously. Which AP placement strategy is BEST for high-density environments?

    • A. Deploy a small number of high-power APs in the ceiling to maximize coverage range and minimize interference
    • B. Deploy more lower-power APs with smaller cells, use 5 GHz preference, and enable band steering to distribute clients(correct)
    • C. Deploy APs on the perimeter walls at high power to provide omnidirectional coverage throughout the room
    • D. Deploy a single AP with a high-gain directional antenna mounted at the front of the lecture hall

    Explanation: High-density wireless design requires more, smaller cells — not fewer, higher-power cells. Key principles: (1) reduce Tx power to create smaller cells so more APs can reuse the same channel without causing co-channel interference; (2) prefer 5 GHz because it has more non-overlapping channels; (3) enable band steering to push capable clients from 2.4 GHz to 5 GHz, reserving 2.4 GHz for legacy devices. High-power APs in a HD environment (option A) cause massive co-channel interference as every client in the room hears all APs. Perimeter wall APs (option C) create RF paths that cross the entire room, maximizing interference. A single AP (option D) cannot serve 400 simultaneous clients adequately.

  17. . A network engineer is designing a wireless network for IoT sensors that use MQTT protocol for temperature monitoring. There are 500 IoT devices distributed across a warehouse. The security team requires that IoT devices cannot communicate with corporate clients. Which wireless design principle should the engineer apply?

    • A. Deploy IoT devices on the same SSID as corporate clients with ACLs to restrict cross-communication
    • B. Deploy IoT devices on a dedicated SSID with a separate VLAN, client isolation enabled, and a firewall between the IoT and corporate VLANs(correct)
    • C. Deploy IoT devices on the 2.4 GHz band only and corporate clients on 5 GHz to achieve frequency-based isolation
    • D. Deploy IoT devices using a hidden SSID to prevent other clients from detecting and joining the IoT network

    Explanation: IoT wireless design best practice places IoT devices on a dedicated SSID mapped to a separate VLAN. Client isolation on the IoT SSID prevents IoT-to-IoT lateral movement at Layer 2. A firewall or ACL between the IoT VLAN and corporate VLAN enforces the isolation requirement at Layer 3. This is defense-in-depth. Using the same SSID with ACLs (option A) shares the wireless medium and relies solely on ACLs for isolation. Frequency band separation (option C) does not provide security isolation — both bands share the same L2 broadcast domain if on the same VLAN. A hidden SSID (option D) provides no actual security — the SSID is still discoverable by passive scanning of probe responses.

  18. . A wireless engineer is designing a branch office wireless network where 50 APs serve 300 users. The WAN link to the central site (where the WLC resides) is a 100 Mbps MPLS circuit. The engineer is evaluating whether to use FlexConnect local switching or central switching. Which factor most strongly supports choosing FlexConnect local switching for the branch?

    • A. FlexConnect local switching reduces WLC CPU utilization by offloading client data path to the AP
    • B. FlexConnect local switching allows client traffic to be bridged locally at the branch without traversing the WAN, preserving WAN bandwidth and maintaining connectivity during WAN outages(correct)
    • C. FlexConnect local switching enables the use of 802.11ax features that are not available with central switching
    • D. FlexConnect local switching provides faster roaming between APs within the branch because CAPWAP reassociation is not required

    Explanation: FlexConnect local switching is designed for branch deployments where APs are connected to a centralized WLC over a WAN link. In local switching mode, client data traffic is bridged directly from the AP to the local LAN without being encapsulated in CAPWAP and sent over the WAN. This preserves WAN bandwidth and, critically, allows the SSID to continue operating in standalone mode during a WAN outage. WLC CPU offload (option A) is a minor benefit. 802.11ax features (option C) are independent of the switching mode. Roaming speed (option D) is not significantly impacted by switching mode — roaming between FlexConnect APs in a group still involves WLC coordination for seamless roaming.

  19. . A wireless engineer is designing an outdoor wireless mesh deployment using Cisco Catalyst 9124AX outdoor APs. The mesh design requires one AP to connect back to the wired network and other APs to relay traffic through the mesh. What are these two AP roles called in a Cisco wireless mesh?

    • A. Primary AP (PAP) and Secondary AP (SAP)
    • B. Root AP (RAP) and Mesh AP (MAP)(correct)
    • C. Hub AP and Spoke AP
    • D. Master AP and Client AP

    Explanation: In Cisco wireless mesh architecture, the AP directly connected to the wired network (via Ethernet) is called the Root Access Point (RAP). APs that connect wirelessly to the RAP (or to other MAPs in a multi-hop mesh) are called Mesh Access Points (MAPs). The backhaul between RAP and MAPs uses a dedicated backhaul SSID (typically on 5 GHz) while the client-facing SSIDs are served on the same or other radios. None of the other terminology (PAP/SAP, hub/spoke, master/client) is used in Cisco wireless mesh documentation.

  20. . A wireless engineer is designing an outdoor point-to-multipoint link using directional antennas. The link must clear a ridge line at the midpoint of a 2.4 km path. To avoid signal diffraction loss, the Fresnel zone must be unobstructed. For a 5.8 GHz link of 2.4 km, what is the approximate radius of the first Fresnel zone at the midpoint?

    • A. Approximately 4.8 meters
    • B. Approximately 11 meters(correct)
    • C. Approximately 22 meters
    • D. Approximately 48 meters

    Explanation: The first Fresnel zone radius at the midpoint is calculated using: r = 17.3 × sqrt(d / (4f)), where d is the total link distance in km and f is the frequency in GHz. For d=2.4 km and f=5.8 GHz: r = 17.3 × sqrt(2.4 / (4 × 5.8)) = 17.3 × sqrt(0.1034) = 17.3 × 0.3216 ≈ 5.6 m. The more precise formula r = sqrt(n × λ × d1 × d2 / (d1 + d2)) at midpoint (d1=d2=1.2 km) gives r = sqrt(1 × (0.3/5.8m no — λ = 0.0517m) × 1200 × 1200 / 2400) = sqrt(0.0517 × 600) ≈ sqrt(31) ≈ 5.6 m. The closest answer is approximately 11 meters, noting that real-world deployments recommend 60% Fresnel clearance as the minimum acceptable obstruction threshold, which for an 18 m first zone would equal ~11 m clearance. For the Cisco exam, 11 meters best represents a 5.8 GHz 2.4 km midpoint first Fresnel zone when rounded to a practical design value.

  21. . A wireless engineer is designing a Cisco Catalyst 9800 HA SSO deployment. After SSO failover, which statement about AP CAPWAP sessions and client associations is correct?

    • A. All APs must re-discover the new active WLC via DHCP option 43 and re-join after failover
    • B. APs maintain their CAPWAP sessions without interruption; 802.1X-authenticated clients retain their PMK and do not re-authenticate; PSK clients maintain association without re-association(correct)
    • C. APs maintain CAPWAP sessions, but all 802.1X clients must re-authenticate because the PMK cache is not synchronized to the standby WLC
    • D. APs must re-join the standby WLC, but the join time is reduced to under 5 seconds because the configuration is pre-cached

    Explanation: Cisco Catalyst 9800 HA SSO (Stateful Switchover) synchronizes all AP CAPWAP sessions, client association states, PMK (Pairwise Master Key) caches, and 802.1X session information to the standby WLC in real time via the redundancy port. On failover, the standby WLC takes over without any AP or client needing to re-associate or re-authenticate. This is the key advantage of SSO over N+1 HA, where APs do re-join the backup controller. Option A describes a cold-standby or N+1 failover, not SSO. Option C is incorrect because PMK is synchronized in SSO. Option D describes a warm standby (AP config pre-cached), not full SSO.

  22. . An enterprise wireless network uses 802.11r, 802.11k, and 802.11v on a Cisco Catalyst 9800 WLC. A VoIP handset reports a roaming time of 350 ms, which is causing call drops. The engineer reviews the Client 360 timeline and sees that 802.11r FT is completing in 15 ms but there is a 300 ms delay between the client sending FT Action Request and receiving the FT Action Response via the current AP. What is the most likely cause of this delay?

    • A. The target AP's 5 GHz radio is in a DFS channel and is performing radar detection, causing a 300 ms hold-down
    • B. The WLC is rate-limiting FT Action frames due to a security policy, causing queuing delay
    • C. The FT over-the-DS path traverses the distribution system between the current AP, the WLC, and the target AP; a high-latency wired link between the AP switch and WLC is adding delay to this path(correct)
    • D. The client supplicant has a software bug that causes it to retransmit FT Action Request three times before the WLC responds

    Explanation: In 802.11r FT over-the-DS, the FT Action Request is sent by the client to the current AP, which forwards it via the wired distribution system through the WLC to the target AP. The FT Action Response travels the same path in reverse. If the wired link between the AP switch and the WLC has high latency (e.g., a congested or long-haul WAN link, or a poorly performing switch), this latency appears directly in the FT DS exchange time. A 300 ms delay strongly suggests a slow wired path. DFS radar detection (option A) is a per-channel 60-second channel change process, not a per-frame 300 ms delay. WLC rate-limiting of FT frames (option B) is not a standard behavior. Client supplicant retransmissions (option D) would show multiple FT Action Request events in the timeline.

  23. . A wireless engineer is designing QoS for a campus wireless network with VoIP, video conferencing, and best-effort data traffic. The APs are Cisco Catalyst 9130 running Wi-Fi 6 with WMM. The engineer must map the wired DSCP values to the appropriate WMM Access Categories at the AP. Which mapping correctly represents the WMM AC and DSCP relationship for voice traffic?

    • A. AC_VO (Voice) maps to DSCP EF (Expedited Forwarding, DSCP 46)(correct)
    • B. AC_VI (Video) maps to DSCP EF (DSCP 46); AC_VO maps to DSCP AF41 (DSCP 34)
    • C. AC_VO maps to DSCP CS3 (DSCP 24) for call signaling only
    • D. AC_VO maps to DSCP AF31 (DSCP 26) for RTP voice streams

    Explanation: The IEEE 802.11e/WMM QoS standard and Cisco's recommended DSCP-to-WMM mapping specifies that AC_VO (Access Category Voice, the highest priority Wi-Fi queue) maps to DSCP 46 (EF — Expedited Forwarding). This ensures that RTP voice media streams marked EF on the wired network are placed in the highest-priority wireless queue with minimum TXOP delay and collision avoidance priority. DSCP AF41 (option B) maps to AC_VI (video), not AC_VO. CS3 (option C, DSCP 24) is used for call signaling (SIP/H.323) which maps to AC_VI or AC_VO depending on the implementation, not the RTP voice stream. AF31 (option D, DSCP 26) maps to AC_BE (best effort).

  24. . A wireless engineer is reviewing a high-density design for an indoor stadium with 20,000 seats. The design uses under-seat APs with directional antennas. After deployment, the engineer notices that clients in rows 10–15 are seeing high retransmission rates and low throughput despite strong RSSI from two APs. What is the most likely cause and the correct design adjustment?

    • A. The clients have firmware issues; the fix is to update client firmware across all devices in rows 10–15
    • B. Co-channel interference from multiple APs on the same channel is causing excessive CCA deferrals; the fix is to increase AP density and reduce Tx power so each AP covers fewer rows, or audit channel reuse to separate co-channel APs by at least 3 rows(correct)
    • C. The AP antennas are over-provisioned; the fix is to replace directional antennas with omnidirectional antennas to spread coverage evenly
    • D. The stadium RF environment has excessive multipath from the metallic seat structure; the fix is to enable OFDM's multipath immunity by disabling legacy 802.11b/g rates only

    Explanation: In high-density stadium deployments, under-seat APs typically cover 2–3 rows. If the channel reuse pattern is too tight — meaning APs on the same channel are placed too close together — clients hear multiple APs at high signal strength on the same channel, causing excessive CCA (Clear Channel Assessment) deferrals as each AP must wait for the others to finish transmitting. This appears as high RSSI but high retransmissions and low throughput. The correct design fix is to reduce Tx power to limit each AP's interference footprint and ensure co-channel APs are separated by at least 2–3 rows. Omnidirectional antennas (option C) would actually worsen co-channel interference. Disabling legacy rates (option D) removes low modulation rates but does not address co-channel interference. Client firmware (option A) does not cause systematic co-channel interference.

  25. . A wireless engineer is designing a multi-site enterprise with Cisco Catalyst 9800 WLCs at headquarters and three branch offices. The WLCs are configured in a mobility group. A corporate user travels between sites and the engineer wants to avoid Layer 3 re-keying delays when the user's client roams between WLCs at different sites across the WAN. Which roaming optimization requires a mobility tunnel between the WLCs and allows the client to maintain its PMK cache after an inter-site roam?

    • A. 802.11r Fast BSS Transition — keys are pre-negotiated at the AP level across the mobility tunnel
    • B. Cisco mobility group PMK propagation — the original WLC pushes the client's PMK to all WLCs in the mobility group, enabling 802.11r FT or OKC on the target WLC without full re-authentication(correct)
    • C. 802.11v BSS Transition Management — the origin WLC sends a BSS TM Request with the PMK to the target WLC via CAPWAP
    • D. MFP client protection — the PMK is embedded in the MFP signature and transferred between WLCs

    Explanation: In a Cisco WLC mobility group, when a client performs an inter-controller roam, the original WLC transfers the client's context (including the PMK, 802.1X session, and 802.11r FT keys) to the target WLC via the mobility tunnel (EoIP or CAPWAP mobility). This allows the target WLC to authenticate the client using cached credentials without requiring a full 802.1X EAP exchange — effectively enabling seamless 802.11r or OKC across controllers. Without this context transfer, the client would need to re-authenticate against RADIUS. Option A is partially correct that 802.11r is used, but it is the mobility group context transfer that enables PMK sharing between WLCs, not AP-level pre-negotiation across WAN. 802.11v (option C) is for AP-to-client roaming guidance, not PMK transfer between WLCs. MFP (option D) is a management frame protection protocol, not a key distribution mechanism.