Implementing and Operating Cisco Wireless Core Technologies — Free Practice Questions
10 free sample questions from a bank of 64, with the correct answers and explanations. No signup required — start practising right now.
1Refer to the exhibit. A network administrator must configure a client management parameter for a wireless deployment in a multi-site enterprise. The enterprise is using Cisco ISE as the management platform to oversee wireless access policies. To meet the organization's compliance requirements, all wireless endpoints must be evaluated against a posture policy before gaining access. Which configuration change must be applied on the WLAN level of the WLC to meet the requirement?
A — config wlan … enable aaa-override lets ISE push posture results. AAA override is the WLAN-level switch that lets RADIUS/ISE override per-client policy — the prerequisite for posture-driven access.
Key concepts in this question
AAA override: WLAN option allowing the AAA server to push VLAN/ACL/secondary attributes that supersende local WLAN policy.
Posture via ISE: Posture results arrive as RADIUS authorizations — they only apply if the WLAN accepts overrides.
WLAN-level command: Legacy/AireOS-style config wlan <ssid> enable aaa-override is the WLAN-scoped knob the stem asks for.
Why A is correct
Cisco's Catalyst 9800 WLAN Security guide defines AAA override as the option that lets the AAA server dynamically override wireless policy per client — exactly what posture evaluation from ISE requires. Option A is the only choice that enables aaa-override on the WLAN; banked A confirmed.
Why the others are wrong
B. A garbled wireless profile policy line is not a complete WLAN-level posture enablement.
C. Mashes WLAN name into a radius-enable fragment — invalid syntax for posture.
D. Another mashed profile/wlan string; does not cleanly enable aaa-override.
350-101 exam tip
Posture needs aaa-override on the WLAN so ISE results win — if the answer isn't a clean config wlan … aaa-override, it's OCR soup.
2What defines device sensitivity in a wireless environment?
capability to process the signal
detection of redundant gateways
synchronization of beacon intervals
implementation of key refresh schedules
Answer: A
The short version
A — Sensitivity is the ability to process weak received signals. Better sensitivity means decoding lower-power signals.
Key concepts in this question
Receiver sensitivity: minimum signal level a radio can decode reliably.
Signal processing: demodulation of weak or noisy RF into usable frames.
Device variation: different chipsets and antennas yield different sensitivity.
Why A is correct
Device sensitivity in wireless describes how well a receiver can process a given signal, especially near the noise floor. A more sensitive device decodes weaker signals at greater range or through attenuation. Gateway redundancy, beacons, and key refresh are unrelated functions and do not define sensitivity.
Why the others are wrong
B. Redundant gateway detection is a resilience design, not a receiver RF characteristic.
C. Beacon interval synchronization aids power-save and roaming timing, not signal decode threshold.
D. Key refresh schedules govern security rekeying, not the ability to hear weak signals.
3An engineer must prevent unauthorized rogue APs from connecting to the enterprise wired network. Which Cisco feature best addresses this requirement?
CleanAir
Rogue containment
ClientLink
Optimized Roaming
Answer: B
The short version
B — Rogue containment blocks unauthorized APs from the wired network. It mitigates rogue APs plugged into enterprise ports.
Key concepts in this question
Rogue AP: unauthorized AP bridged to the corporate wired network.
Rogue containment: deauthentication and blocking of rogue clients and switch-port actions.
Detection versus prevention: WIPS classifies rogues before containment acts.
Why B is correct
Rogue containment directly addresses APs illegally connected to the wired enterprise, deauthenticating their clients and enabling the infrastructure to block the rogue's switch port. CleanAir targets non-Wi-Fi interference, while ClientLink and Optimized Roaming improve performance rather than enforcing access control.
Why the others are wrong
A. CleanAir mitigates spectrum interference from non-802.11 devices, not wired rogue connections.
C. ClientLink is beamforming that improves downlink to legacy clients, with no rogue-blocking role.
D. Optimized Roaming tunes client roaming behavior, not unauthorized AP attachment.
350-101 exam tip
Rogue on the wire equals containment; interference on the air equals CleanAir.
4An administrator configures WPA3-Personal security on a WLAN. Which authentication method is introduced with this standard?
PEAP
SAE
EAP-TLS
LEAP
Answer: B
The short version
B — WPA3-Personal introduces Simultaneous Authentication of Equals. SAE replaces WPA2's PSK handshake.
Key concepts in this question
SAE: password-authenticated key exchange resistant to offline dictionary attacks.
WPA3-Personal: SAE-based personal mode with forward secrecy.
Legacy methods: PEAP, EAP-TLS, and LEAP belong to WPA2-Enterprise or older pre-standards.
Why B is correct
WPA3-Personal replaces the WPA2 pre-shared-key handshake with Simultaneous Authentication of Equals, based on Dragonfly key exchange. SAE provides stronger brute-force resistance and forward secrecy with the same passphrase model. None of the other listed methods was introduced by WPA3.
Why the others are wrong
A. PEAP is a tunneled EAP method for WPA2-Enterprise, predating WPA3.
C. EAP-TLS is a certificate-based Enterprise authentication method, not new with WPA3-Personal.
D. LEAP is a legacy Cisco proprietary EAP method, deprecated long before WPA3.
350-101 exam tip
Personal plus WPA3 always equals SAE; Enterprise plus WPA3 equals 192-bit suite.
5Which condition is required for a line-of-sight RF connection?
Wireless multipath signal propagation to the client
MIMO connection support on both wireless radios
Delay on wireless signal delivery introduced by reflection
No physical objects between the transmitter and receiver
Answer: D
The short version
D — Line-of-sight needs a clear path with no obstructions. Physical blockage breaks the direct ray.
Key concepts in this question
Line-of-sight: unobstructed straight-line path between antennas.
Fresnel zone: clearance around the visual path needed for link quality.
Multipath contrast: reflected paths differ from the direct line-of-sight path.
Why D is correct
A line-of-sight RF connection requires no physical objects between transmitter and receiver along the direct path. Buildings, terrain, or vegetation attenuate or block the wave, defeating line-of-sight even when radios support MIMO. Multipath, delay spread, and MIMO support describe non-line-of-sight behavior, not its requirement.
Why the others are wrong
A. Multipath propagation describes reflected signals arriving via multiple paths, typical of obstructed links.
B. MIMO support improves throughput and resilience but does not create a clear physical path.
C. Reflection-induced delay is a multipath impairment, opposite of a clean line-of-sight ray.
350-101 exam tip
LOS equals eyes-onBoth antennas — any object in between means no LOS.
6Refer to the exhibit. A network administrator is working on a WLC to enable user access for contractor desktops using WPA2-Enterprise using EAP-TTLS. The administrator verified the external authentication configuration and now must test network connectivity. Which code snippet must be added to the box in the code to complete the configuration on the WLC that supports authentication with an external server?
aaa group server radius RADIUS-GRP
aaa group server aaa RADIUS-GRP
aaa server group server radius RADIUS-GRP
aaa server group server radius RADIUS-GRP
Answer: A
The short version
A — aaa group server radius RADIUS-GRP is the correct IOS form. The standard command builds a AAA server group of type radius; every other option invents invalid keywords.
Key concepts in this question
AAA server group: aaa group server radius <name> creates a named RADIUS group used by method lists.
External auth for WPA2-Enterprise: EAP-TTLS clients authenticate on the external RADIUS server referenced by that group.
Syntax trap: IOS has no 'aaa server group' or 'group server aaa' forms.
Why A is correct
IOS/IOS-XE AAA syntax is aaa group server radius <group-name> — the only well-formed option. WPA2-Enterprise with an external server points that group at the RADIUS servers used by the WLAN's auth method list; banked A confirmed.
Why the others are wrong
B. aaa group server aaa … is self-referential nonsense — the server type must be radius/tacacs+.
C. aaa server group server radius … is not an IOS command.
D. Same invalid 'aaa server group' verb as C, plus a radius keyword that still doesn't parse.
350-101 exam tip
AAA groups: aaa group server <radius|tacacs+> NAME — 'aaa server group' is a made-up verb.
7A wireless engineer wants to analyze over-the-air 802.11 frames without servicing clients. Which AP mode should be configured?
FlexConnect mode
Sniffer mode
Bridge mode
Local mode
Answer: B
The short version
B — Sniffer mode captures over-the-air frames without serving clients. It is the dedicated analysis mode.
Key concepts in this question
Sniffer mode: AP dedicates radio to capture and forward 802.11 frames.
No client service: sniffer APs do not accept associations or carry traffic.
Analysis use: feeds Wireshark or WIPS tools for protocol troubleshooting.
Why B is correct
Sniffer mode configures the AP purely as an over-the-air sensor that captures 802.11 frames and forwards them to an analyzer. It does not service clients, which matches the requirement to analyze frames without carrying user traffic. FlexConnect, Bridge, and Local modes all primarily serve or backhaul client traffic.
Why the others are wrong
A. FlexConnect mode locally switches client traffic at the branch, still serving clients.
C. Bridge mode forms mesh or point-to-point backhaul links, not a capture sensor.
D. Local mode tunnels client traffic to the WLC and serves clients normally.
350-101 exam tip
Analyze only, serve none — that phrase always means sniffer mode.
8A wireless engineer deploys multicast video streaming over WLANs. Clients experience excessive unnecessary traffic consumption. Which feature optimizes multicast delivery to wireless clients?
Multicast-to-unicast conversion
CAPWAP fragmentation
Layer 2 security filtering
Dynamic VLAN assignment
Answer: A
The short version
A — Multicast-to-unicast conversion targets delivery per client. It avoids flooding every client at lowest rates.
Key concepts in this question
Multicast over WLAN: by default sent at low basic rates to all associated clients.
Multicast-to-unicast: AP replicates group traffic as directed unicast frames.
Efficiency gain: unicast uses higher rates, retries, and only reaches subscribers.
Why A is correct
Multicast-to-unicast conversion optimizes video delivery by converting group frames into individual unicast transmissions to subscribed clients. This permits higher data rates, MAC retries, and avoids waking or burdening non-member clients, fixing the excessive-traffic symptom. Fragmentation, Layer 2 filtering, and VLAN assignment do not change multicast delivery mechanics.
Why the others are wrong
B. CAPWAP fragmentation handles large control payloads, not multicast fan-out efficiency.
C. Layer 2 security filtering enforces access policy, but does not optimize multicast replication.
D. Dynamic VLAN assignment segments users, but still floods multicast within each VLAN.
350-101 exam tip
Video over Wi-Fi wasting airtime — convert multicast to unicast for efficient retries.
9A school district is deploying Cisco Catalyst 9176 APs to remote sites with occasional WAN outages. The IT team wants the APs to attempt joining a secondary or tertiary Catalyst 9800 WLC if the primary controller is unreachable. The team must preconfigure all controller IP addresses using the AP CLI before deploying. Which set of CLI commands sets the primary, secondary, and tertiary controller IP addresses on a Catalyst 9176 AP?
capwap ap primary-base main-wlc 10.10.10.10capwap ap secondary-base backup-wlc 10.10.10.20capwap ap tertiary-base tertiary-wlc 10.10.10.30
ap join primary 10.10.10.10ap join secondary 10.10.10.20ap join tertiary 10.10.10.30
capwap ap wlc primary 10.10.10.10capwap ap wlc secondary 10.10.10.20capwap ap wlc tertiary 10.10.10.30
Answer: B
The short version
B — capwap ap primary-base commands set all three controller targets. Name plus IP pins primary, secondary, and tertiary join order.
Key concepts in this question
CAPWAP join: AP discovers and joins WLCs in configured priority order.
Primary-base hierarchy: primary, secondary, and tertiary entries control failover sequence.
AP CLI pre-staging: static entries survive WAN outages for remote-site recovery.
Why B is correct
The Catalyst AP CLI uses capwap ap primary-base, secondary-base, and tertiary-base with controller name and IP to preconfigure the join list. On primary loss during a WAN outage, the AP tries secondary then tertiary automatically. The other syntaxes are not valid AP commands for this purpose.
Why the others are wrong
A. set controller syntax is not the Catalyst AP command for WLC join targets.
C. ap join primary or secondary is not valid AP CLI for persistent controller assignment.
D. capwap ap wlc primary or secondary is malformed and not accepted on Catalyst APs.
350-101 exam tip
Catalyst AP failover trio always starts capwap ap — primary-base, secondary-base, tertiary-base.
10A customer requires wireless clients to maintain uninterrupted voice calls while roaming between access points. Which Cisco wireless feature minimizes roaming delay?
WPA3 SAE
802.11r Fast Transition
RADIUS accounting
AVC profiling
Answer: B
The short version
B — 802.11r Fast Transition cuts roaming key exchange delay. It keeps voice calls seamless across APs.
Key concepts in this question
Fast Transition: pre-negotiated keys enable rapid AP-to-AP handoff.
Voice sensitivity: calls drop with even brief authentication gaps.
Roaming versus security: FT preserves WPA2 or WPA3 security while speeding transitions.
Why B is correct
802.11r Fast Transition caches and pre-distributes keying material so clients roam without full re-authentication. That minimizes handoff delay and packet loss, preserving uninterrupted voice. SAE secures initial joins, while RADIUS accounting and AVC profiling do not accelerate roaming.
Why the others are wrong
A. WPA3 SAE strengthens personal-network authentication, but does not shorten AP roams.
C. RADIUS accounting logs session usage and has no roaming-acceleration role.
D. AVC profiling classifies applications for QoS, but does not reduce handoff time.
350-101 exam tip
Voice plus roaming equals 802.11r FT — fast secure handoff keeps calls alive.