Topic 08 Practice Test 1 covers Wireless Architectures, Infrastructure, and Device Management for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 2.6–2.8. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
Aster’s campus APs serve local clients while a Catalyst 9800 centrally controls them. Which AP mode is the normal client-serving campus mode? Choose ONE.
- Local mode
- Monitor mode
- Bridge mode
- Sniffer mode
Correct Answer: A
Correct Answer
Answer A is correct because Local mode is the standard client-serving mode for centrally managed campus APs, with the controller providing control and policy functions. At Aster, local AP mode evidence is checked directly. The Local mode choice at Aster therefore meets the required outcome. At Aster, the local AP mode state is observable afterward.
Incorrect Answers
Answer B is incorrect because Monitor mode dedicates the AP primarily to RF monitoring and security/scanning functions rather than normal client service. At Aster, local AP mode evidence is checked directly. The Monitor mode choice at Aster therefore misses the required outcome. At Aster, the local AP mode state is observable afterward.
Answer D is incorrect because Sniffer mode captures 802.11 frames on a selected channel and forwards them to an analyzer instead of functioning as a normal production AP. At Aster, local AP mode evidence is checked directly. The Sniffer mode choice at Aster therefore misses the required outcome. At Aster, the local AP mode state is observable afterward.
Answer C is incorrect because Bridge mode is used for wireless bridging/mesh-style connectivity and is not the ordinary campus client-serving mode requested. At Aster, local AP mode evidence is checked directly. The Bridge mode choice at Aster therefore misses the required outcome. At Aster, the local AP mode state is observable afterward.
Question 2
Cobalt’s small branch must keep local wireless client traffic on the branch LAN if the WAN to the controller is interrupted. Which AP architecture is designed for this requirement? Choose ONE.
- Local mode with central switching only
- Monitor mode
- Sniffer mode
- FlexConnect with local switching
Correct Answer: D
Correct Answer
Answer D is correct because FlexConnect supports remote-site deployments and can locally switch client traffic according to policy, reducing dependence on the WAN data path to a central controller. At Cobalt, FlexConnect evidence is checked directly. The FlexConnect with choice at Cobalt therefore meets the required outcome. At Cobalt, the FlexConnect state is observable afterward.
Incorrect Answers
Answer A is incorrect because Local mode with central switching sends client data through the controller path and does not provide the requested branch-local switching behavior. At Cobalt, FlexConnect evidence is checked directly. The Local mode choice at Cobalt therefore misses the required outcome. At Cobalt, the FlexConnect state is observable afterward.
Answer B is incorrect because Monitor mode is intended for RF/security observation and is not a client-serving branch architecture for local data forwarding. At Cobalt, FlexConnect evidence is checked directly. The Monitor mode choice at Cobalt therefore misses the required outcome. At Cobalt, the FlexConnect state is observable afterward.
Answer C is incorrect because Sniffer mode captures wireless frames for analysis and does not provide normal user connectivity or branch-local client switching. At Cobalt, FlexConnect evidence is checked directly. The Sniffer mode choice at Cobalt therefore misses the required outcome. At Cobalt, the FlexConnect state is observable afterward.
Question 3
Ember is documenting a centrally switched WLAN. Which statement best distinguishes CAPWAP control from the client data path? Choose ONE.
- CAPWAP replaces 802.1Q on every switch trunk
- CAPWAP is only a Layer 2 loop-prevention protocol
- CAPWAP provides AP-controller control and can carry centrally switched client data tunnels
- CAPWAP is the RADIUS authentication method used by clients
Correct Answer: C
Correct Answer
Answer C is correct because CAPWAP establishes AP-to-controller control communication and, in centrally switched designs, is also used to tunnel client data toward the controller. At Ember, CAPWAP path evidence is checked directly. The CAPWAP provides choice at Ember therefore meets the required outcome. At Ember, the CAPWAP path state is observable afterward.
Incorrect Answers
Answer B is incorrect because Loop prevention at Layer 2 is handled by spanning-tree mechanisms, not CAPWAP. At Ember, CAPWAP path evidence is checked directly. The CAPWAP is choice at Ember therefore misses the required outcome. At Ember, the CAPWAP path state is observable afterward.
Answer A is incorrect because CAPWAP does not replace Ethernet VLAN tagging on wired trunks; the wired network can still use 802.1Q where VLAN transport is required. At Ember, CAPWAP path evidence is checked directly. The CAPWAP replaces choice at Ember therefore misses the required outcome. At Ember, the CAPWAP path state is observable afterward.
Answer D is incorrect because RADIUS may support AAA for client authentication, but CAPWAP is the AP-controller tunneling/control mechanism rather than the client’s authentication protocol. At Ember, CAPWAP path evidence is checked directly. The CAPWAP is choice at Ember therefore misses the required outcome. At Ember, the CAPWAP path state is observable afterward.
Question 4
Granite needs a dedicated AP to scan channels for rogues and interference without serving normal clients. Which AP mode should be selected? Choose ONE.
- FlexConnect local switching
- Monitor mode
- Bridge mode
- Local mode
Correct Answer: B
Correct Answer
Answer B is correct because Monitor mode dedicates the AP to RF monitoring/scanning functions such as rogue detection and spectrum/security observation instead of ordinary client service. At Granite, monitor mode evidence is checked directly. The Monitor mode choice at Granite therefore meets the required outcome. At Granite, the monitor mode state is observable afterward.
Incorrect Answers
Answer D is incorrect because Local mode is primarily a client-serving mode and therefore does not match an AP intentionally dedicated to continuous monitoring. At Granite, monitor mode evidence is checked directly. The Local mode choice at Granite therefore misses the required outcome. At Granite, the monitor mode state is observable afterward.
Answer A is incorrect because FlexConnect local switching is for remote-site client service with local data forwarding, not for a sensor-only RF monitoring role. At Granite, monitor mode evidence is checked directly. The FlexConnect local choice at Granite therefore misses the required outcome. At Granite, the monitor mode state is observable afterward.
Answer C is incorrect because Bridge mode focuses on wireless backhaul/bridging use cases rather than continuous non-client-serving RF monitoring. At Granite, monitor mode evidence is checked directly. The Bridge mode choice at Granite therefore misses the required outcome. At Granite, the monitor mode state is observable afterward.
Question 5
Ion needs to capture raw 802.11 traffic on a chosen channel and forward the capture to a remote packet analyzer. Which AP mode fits? Choose ONE.
- Local mode
- Sniffer mode
- Monitor mode only
- FlexConnect
Correct Answer: B
Correct Answer
Answer B is correct because Sniffer mode captures wireless frames on a configured channel and forwards the encapsulated traffic to a remote analyzer for detailed packet inspection. At Ion, sniffer mode evidence is checked directly. The Sniffer mode choice at Ion therefore meets the required outcome. At Ion, the sniffer mode state is observable afterward.
Incorrect Answers
Answer A is incorrect because Local mode is intended for production client access rather than dedicating the AP to remote packet capture. At Ion, sniffer mode evidence is checked directly. The Local mode choice at Ion therefore misses the required outcome. At Ion, the sniffer mode state is observable afterward.
Answer C is incorrect because Monitor mode performs RF/security observation, but the explicit remote packet-capture workflow described is the sniffer function. At Ion, sniffer mode evidence is checked directly. The Monitor mode choice at Ion therefore misses the required outcome. At Ion, the sniffer mode state is observable afterward.
Answer D is incorrect because FlexConnect is a remote-site client-serving architecture and does not describe an AP dedicated to forwarding packet captures to an analyzer. At Ion, sniffer mode evidence is checked directly. The FlexConnect choice at Ion therefore misses the required outcome. At Ion, the sniffer mode state is observable afterward.
Question 6
Keystone must connect two locations wirelessly where the APs provide backhaul between wired segments. Which AP role is most appropriate? Choose ONE.
- Local mode only
- Sniffer mode
- Bridge/mesh mode
- Monitor mode
Correct Answer: C
Correct Answer
Answer C is correct because Bridge or mesh modes support wireless backhaul between network segments and are appropriate when APs form a wireless infrastructure link. At Keystone, wireless bridge evidence is checked directly. The Bridge/mesh mode choice at Keystone therefore meets the required outcome. At Keystone, the wireless bridge state is observable afterward.
Incorrect Answers
Answer B is incorrect because Sniffer mode is for packet capture and analysis, not for providing a production wireless backhaul between Ethernet segments. At Keystone, wireless bridge evidence is checked directly. The Sniffer mode choice at Keystone therefore misses the required outcome. At Keystone, the wireless bridge state is observable afterward.
Answer D is incorrect because Monitor mode observes RF conditions and does not provide the normal bridge path required between the two wired sites. At Keystone, wireless bridge evidence is checked directly. The Monitor mode choice at Keystone therefore misses the required outcome. At Keystone, the wireless bridge state is observable afterward.
Answer A is incorrect because Local client-serving mode is not the specialized role used when the APs themselves provide the inter-site wireless bridge/backhaul. At Keystone, wireless bridge evidence is checked directly. The Local mode choice at Keystone therefore misses the required outcome. At Keystone, the wireless bridge state is observable afterward.
Question 7
Mesa adds a new AP to a Catalyst 9800 deployment. Which device provides centralized WLAN configuration and policy for joined APs? Choose ONE.
- NTP server
- DHCP client on the user’s laptop
- Layer 2 access switch only
- Wireless LAN controller
Correct Answer: D
Correct Answer
Answer D is correct because The wireless LAN controller centrally defines WLANs, profiles, tags, and AP policy; an AP must establish the controller relationship to receive and operate under that centralized configuration. At Mesa, controller join evidence is checked directly. The Wireless LAN choice at Mesa therefore meets the required outcome. At Mesa, the controller join state is observable afterward.
Incorrect Answers
Answer C is incorrect because The access switch provides Ethernet/PoE/VLAN connectivity but does not replace the controller’s centralized wireless policy and WLAN-management role. At Mesa, controller join evidence is checked directly. The Layer 2 choice at Mesa therefore misses the required outcome. At Mesa, the controller join state is observable afterward.
Answer B is incorrect because A client DHCP process assigns endpoint addressing after association and cannot provide AP configuration or centralized wireless policy. At Mesa, controller join evidence is checked directly. The DHCP client choice at Mesa therefore misses the required outcome. At Mesa, the controller join state is observable afterward.
Answer A is incorrect because NTP can synchronize time, but it is not the infrastructure component that joins, manages, and distributes WLAN policy to APs. At Mesa, controller join evidence is checked directly. The NTP server choice at Mesa therefore misses the required outcome. At Mesa, the controller join state is observable afterward.
Question 8
Orchid connects a ceiling AP to an access switch and wants one cable to carry Ethernet plus electrical power. Which switch capability is required? Choose ONE.
- Power over Ethernet (PoE)
- Root Guard
- SPAN
- LACP
Correct Answer: A
Correct Answer
Answer A is correct because PoE supplies electrical power over the Ethernet cabling while the same link carries network traffic, which is the standard single-cable AP deployment model. At Orchid, PoE uplink evidence is checked directly. The Power over choice at Orchid therefore meets the required outcome. At Orchid, the PoE uplink state is observable afterward.
Incorrect Answers
Answer D is incorrect because LACP negotiates link aggregation and does not deliver electrical power to an attached AP. At Orchid, PoE uplink evidence is checked directly. The LACP choice at Orchid therefore misses the required outcome. At Orchid, the PoE uplink state is observable afterward.
Answer C is incorrect because SPAN mirrors switch traffic for analysis and is unrelated to powering the AP. At Orchid, PoE uplink evidence is checked directly. The SPAN choice at Orchid therefore misses the required outcome. At Orchid, the PoE uplink state is observable afterward.
Answer B is incorrect because Root Guard is a spanning-tree protection feature and does not provide power or physical Ethernet service to an access point. At Orchid, PoE uplink evidence is checked directly. The Root Guard choice at Orchid therefore misses the required outcome. At Orchid, the PoE uplink state is observable afterward.
Question 9
Quartz uses centrally switched client traffic on a Catalyst 9800. The controller uplink must deliver the client VLAN to the wired network. What wired-network concept remains important? Choose ONE.
- Disable the WLAN’s policy mapping
- Convert every AP uplink to a routed port with the client subnet
- Ensure the required client VLAN is available on the appropriate controller/wired switching path
- Put all clients into the AP management VLAN
Correct Answer: C
Correct Answer
Answer C is correct because Centrally switched client traffic emerges through the controller-side wired network, so the intended client VLAN must be available and correctly transported on that infrastructure path. At Quartz, client VLAN path evidence is checked directly. The Ensure the choice at Quartz therefore meets the required outcome. At Quartz, the client VLAN path state is observable afterward.
Incorrect Answers
Answer B is incorrect because AP uplinks do not each need to become routed ports for a centrally switched client subnet; doing so would not fix the controller-side VLAN transport requirement. At Quartz, client VLAN path evidence is checked directly. The Convert every choice at Quartz therefore misses the required outcome. At Quartz, the client VLAN path state is observable afterward.
Answer A is incorrect because Removing WLAN-to-policy mapping would prevent the controller from applying the intended client policy and would worsen, not solve, the connectivity problem. At Quartz, client VLAN path evidence is checked directly. The Disable the choice at Quartz therefore misses the required outcome. At Quartz, the client VLAN path state is observable afterward.
Answer D is incorrect because Placing user clients into the AP management VLAN collapses management and client segmentation and is not the normal fix for a missing client-VLAN path. At Quartz, client VLAN path evidence is checked directly. The Put all choice at Quartz therefore misses the required outcome. At Quartz, the client VLAN path state is observable afterward.
Question 10
Summit’s Catalyst 9800 design needs to map a WLAN profile to the policy profile that defines client network behavior. Which object performs that association? Choose ONE.
- Site tag
- AP join profile only
- RF tag
- Policy tag
Correct Answer: D
Correct Answer
Answer D is correct because A policy tag maps WLAN profiles to policy profiles and determines which WLAN/policy combinations are deployed to APs assigned that tag. At Summit, policy tag evidence is checked directly. The Policy tag choice at Summit therefore meets the required outcome. At Summit, the policy tag state is observable afterward.
Incorrect Answers
Answer A is incorrect because A site tag controls site-related AP behavior such as FlexConnect/local-mode characteristics but does not itself create the WLAN-to-policy-profile mapping. At Summit, policy tag evidence is checked directly. The Site tag choice at Summit therefore misses the required outcome. At Summit, the policy tag state is observable afterward.
Answer C is incorrect because An RF tag groups RF profiles and radio-related settings; it does not map a WLAN profile to a client policy profile. At Summit, policy tag evidence is checked directly. The RF tag choice at Summit therefore misses the required outcome. At Summit, the policy tag state is observable afterward.
Answer B is incorrect because AP join profiles contain AP-level join/management settings and do not replace the policy-tag mapping between WLAN and policy profiles. At Summit, policy tag evidence is checked directly. The AP join choice at Summit therefore misses the required outcome. At Summit, the policy tag state is observable afterward.
Question 11
Aster loses IP connectivity to a switch after a bad management change but has physical access in the wiring closet. Which management method is most appropriate for recovery? Choose ONE.
- SSH
- HTTPS
- TACACS+ over the production network
- Console access
Correct Answer: D
Correct Answer
Answer D is correct because Console access is out-of-band with respect to the device’s IP forwarding path and is therefore suitable when remote IP management is unavailable. At Aster, console recovery evidence is checked directly. The Console access choice at Aster therefore meets the required outcome. At Aster, the console recovery state is observable afterward.
Incorrect Answers
Answer A is incorrect because SSH requires working IP connectivity to the device, so it cannot be the first recovery method when no management address is reachable. At Aster, console recovery evidence is checked directly. The SSH choice at Aster therefore misses the required outcome. At Aster, the console recovery state is observable afterward.
Answer B is incorrect because HTTPS also depends on IP connectivity and the web-management service, which are unavailable in the stated failure. At Aster, console recovery evidence is checked directly. The HTTPS choice at Aster therefore misses the required outcome. At Aster, the console recovery state is observable afterward.
Answer C is incorrect because Remote TACACS+ authentication depends on network reachability to both the device and AAA server and is less suitable than local console recovery in this outage. At Aster, console recovery evidence is checked directly. The TACACS+ over choice at Aster therefore misses the required outcome. At Aster, the console recovery state is observable afterward.
Question 12
Cobalt requires encrypted command-line management of a network device across the IP network. Which protocol should be preferred? Choose ONE.
- SSH
- HTTP
- Telnet
- TFTP
Correct Answer: A
Correct Answer
Answer A is correct because SSH provides encrypted remote terminal access and is the preferred IP-based CLI management protocol when confidentiality and integrity matter. At Cobalt, SSH management evidence is checked directly. The SSH choice at Cobalt therefore meets the required outcome. At Cobalt, the SSH management state is observable afterward.
Incorrect Answers
Answer C is incorrect because Telnet sends its session data without encryption and is therefore inappropriate when the management path must protect credentials and commands. At Cobalt, SSH management evidence is checked directly. The Telnet choice at Cobalt therefore misses the required outcome. At Cobalt, the SSH management state is observable afterward.
Answer B is incorrect because HTTP can support web management but plain HTTP is unencrypted and is not an encrypted terminal protocol. At Cobalt, SSH management evidence is checked directly. The HTTP choice at Cobalt therefore misses the required outcome. At Cobalt, the SSH management state is observable afterward.
Answer D is incorrect because TFTP is a simple file-transfer protocol and does not provide interactive encrypted CLI administration. At Cobalt, SSH management evidence is checked directly. The TFTP choice at Cobalt therefore misses the required outcome. At Cobalt, the SSH management state is observable afterward.
Question 13
Ember’s legacy switch is managed with Telnet. What is the principal security weakness compared with SSH? Choose ONE.
- Telnet does not encrypt the management session
- Telnet requires a wireless controller
- Telnet automatically disables AAA
- Telnet cannot use TCP
Correct Answer: A
Correct Answer
Answer A is correct because Telnet transmits session content without encryption, so credentials and commands can be exposed to anyone able to observe the traffic path. At Ember, Telnet exposure evidence is checked directly. The Telnet does choice at Ember therefore meets the required outcome. At Ember, the Telnet exposure state is observable afterward.
Incorrect Answers
Answer D is incorrect because Telnet does use TCP, so lack of a transport-layer connection is not the reason the session is insecure. At Ember, Telnet exposure evidence is checked directly. The Telnet cannot choice at Ember therefore misses the required outcome. At Ember, the Telnet exposure state is observable afterward.
Answer B is incorrect because Telnet is a general IP terminal protocol and does not depend on wireless-controller infrastructure. At Ember, Telnet exposure evidence is checked directly. The Telnet requires choice at Ember therefore misses the required outcome. At Ember, the Telnet exposure state is observable afterward.
Answer C is incorrect because Using Telnet does not inherently disable AAA; the weakness described is confidentiality of the session, not automatic removal of authentication controls. At Ember, Telnet exposure evidence is checked directly. The Telnet automatically choice at Ember therefore misses the required outcome. At Ember, the Telnet exposure state is observable afterward.
Question 14
Granite wants browser-based device management but requires encryption in transit. Which protocol should be enabled rather than plain HTTP? Choose ONE.
- HTTP
- Telnet
- HTTPS
- CDP
Correct Answer: C
Correct Answer
Answer C is correct because HTTPS protects browser-based management with TLS, providing encrypted transport for the administrative web session. At Granite, HTTPS management evidence is checked directly. The HTTPS choice at Granite therefore meets the required outcome. At Granite, the HTTPS management state is observable afterward.
Incorrect Answers
Answer A is incorrect because Plain HTTP does not encrypt the management exchange and therefore does not meet the requirement to protect credentials and configuration data in transit. At Granite, HTTPS management evidence is checked directly. The HTTP choice at Granite therefore misses the required outcome. At Granite, the HTTPS management state is observable afterward.
Answer B is incorrect because Telnet is an interactive terminal protocol and is also unencrypted, so it is not a secure replacement for a web-management interface. At Granite, HTTPS management evidence is checked directly. The Telnet choice at Granite therefore misses the required outcome. At Granite, the HTTPS management state is observable afterward.
Answer D is incorrect because CDP is a neighbor discovery protocol and does not provide an administrative web interface. At Granite, HTTPS management evidence is checked directly. The CDP choice at Granite therefore misses the required outcome. At Granite, the HTTPS management state is observable afterward.
Question 15
Ion wants centralized administrator AAA with granular command authorization and accounting for network-device CLI access. Which protocol is generally the strongest fit? Choose ONE.
- CAPWAP
- RADIUS only
- TACACS+
- LLDP
Correct Answer: C
Correct Answer
Answer C is correct because TACACS+ is widely used for network-device administration and supports centralized authentication, authorization, and accounting with granular command-authorization capabilities. At Ion, TACACS admin evidence is checked directly. The TACACS+ choice at Ion therefore meets the required outcome. At Ion, the TACACS admin state is observable afterward.
Incorrect Answers
Answer B is incorrect because RADIUS is strongly associated with network access such as 802.1X and VPN authentication; although it provides AAA, it is less commonly chosen when per-command device-administration control is the core requirement. At Ion, TACACS admin evidence is checked directly. The RADIUS only choice at Ion therefore misses the required outcome. At Ion, the TACACS admin state is observable afterward.
Answer D is incorrect because LLDP advertises neighbor information and has no role in centralized administrator authentication or command accounting. At Ion, TACACS admin evidence is checked directly. The LLDP choice at Ion therefore misses the required outcome. At Ion, the TACACS admin state is observable afterward.
Answer A is incorrect because CAPWAP manages AP-controller communication and does not provide administrator AAA for network-device CLI sessions. At Ion, TACACS admin evidence is checked directly. The CAPWAP choice at Ion therefore misses the required outcome. At Ion, the TACACS admin state is observable afterward.
Question 16
Keystone is deploying 802.1X for employee access and needs a centralized AAA protocol commonly used between the network access device and identity server. Which protocol fits? Choose ONE.
- RADIUS
- TFTP
- LACP
- CDP
Correct Answer: A
Correct Answer
Answer A is correct because RADIUS is commonly used for centralized network-access AAA, including enterprise wireless and 802.1X authentication between access devices/controllers and identity services. At Keystone, RADIUS access evidence is checked directly. The RADIUS choice at Keystone therefore meets the required outcome. At Keystone, the RADIUS access state is observable afterward.
Incorrect Answers
Answer D is incorrect because CDP discovers adjacent Cisco devices and does not carry user network-access authentication transactions. At Keystone, RADIUS access evidence is checked directly. The CDP choice at Keystone therefore misses the required outcome. At Keystone, the RADIUS access state is observable afterward.
Answer C is incorrect because LACP negotiates link aggregation and has no AAA function. At Keystone, RADIUS access evidence is checked directly. The LACP choice at Keystone therefore misses the required outcome. At Keystone, the RADIUS access state is observable afterward.
Answer B is incorrect because TFTP transfers files without the network-access authentication and authorization functions required in this scenario. At Keystone, RADIUS access evidence is checked directly. The TFTP choice at Keystone therefore misses the required outcome. At Keystone, the RADIUS access state is observable afterward.
Question 17
Mesa adopts a cloud-managed network platform so administrators can configure distributed devices from a vendor-hosted management plane. Which device-management model is this? Choose ONE.
- Spanning-tree management
- CDP-based management
- Console-only management
- Cloud-managed networking
Correct Answer: D
Correct Answer
Answer D is correct because Cloud-managed networking centralizes configuration and monitoring in a cloud-hosted management platform while distributed network devices connect to that service. At Mesa, cloud management evidence is checked directly. The Cloud-managed networking choice at Mesa therefore meets the required outcome. At Mesa, the cloud management state is observable afterward.
Incorrect Answers
Answer C is incorrect because Console access is local and device-specific; it cannot provide the centralized remote orchestration described across many branches. At Mesa, cloud management evidence is checked directly. The Console-only management choice at Mesa therefore misses the required outcome. At Mesa, the cloud management state is observable afterward.
Answer B is incorrect because CDP supplies local neighbor discovery information and is not a cloud management/control platform. At Mesa, cloud management evidence is checked directly. The CDP-based management choice at Mesa therefore misses the required outcome. At Mesa, the cloud management state is observable afterward.
Answer A is incorrect because Spanning tree controls Layer 2 loop-free topology and does not provide a centralized configuration service. At Mesa, cloud management evidence is checked directly. The Spanning-tree management choice at Mesa therefore misses the required outcome. At Mesa, the cloud management state is observable afterward.
Question 18
Orchid’s device administrators authenticate centrally but each role should be permitted a different command set. Which AAA function decides what an already authenticated user is allowed to do? Choose ONE.
- Accounting
- Authorization
- Authentication
- Discovery
Correct Answer: B
Correct Answer
Answer B is correct because Authorization determines which services, commands, or privilege levels an authenticated identity is permitted to use. At Orchid, AAA authorization evidence is checked directly. The Authorization choice at Orchid therefore meets the required outcome. At Orchid, the AAA authorization state is observable afterward.
Incorrect Answers
Answer C is incorrect because Authentication verifies who the user is; it precedes the permission decision but does not itself define the allowed command set. At Orchid, AAA authorization evidence is checked directly. The Authentication choice at Orchid therefore misses the required outcome. At Orchid, the AAA authorization state is observable afterward.
Answer A is incorrect because Accounting records activity such as session or command events; it provides audit evidence rather than the permission decision. At Orchid, AAA authorization evidence is checked directly. The Accounting choice at Orchid therefore misses the required outcome. At Orchid, the AAA authorization state is observable afterward.
Answer D is incorrect because Discovery is not one of the AAA functions and does not determine administrative privileges. At Orchid, AAA authorization evidence is checked directly. The Discovery choice at Orchid therefore misses the required outcome. At Orchid, the AAA authorization state is observable afterward.
Question 19
Quartz wants an audit trail showing which administrator logged in and which commands were executed. Which AAA function provides this record? Choose ONE.
- ARP inspection
- Authorization
- Accounting
- Authentication
Correct Answer: C
Correct Answer
Answer C is correct because Accounting records AAA activity such as session starts/stops and, where supported, command events, providing the audit trail required by compliance. At Quartz, AAA accounting evidence is checked directly. The Accounting choice at Quartz therefore meets the required outcome. At Quartz, the AAA accounting state is observable afterward.
Incorrect Answers
Answer D is incorrect because Authentication proves identity but does not by itself create the detailed activity record requested. At Quartz, AAA accounting evidence is checked directly. The Authentication choice at Quartz therefore misses the required outcome. At Quartz, the AAA accounting state is observable afterward.
Answer B is incorrect because Authorization decides what the authenticated user may do, but the audit requirement is specifically about recording what occurred. At Quartz, AAA accounting evidence is checked directly. The Authorization choice at Quartz therefore misses the required outcome. At Quartz, the AAA accounting state is observable afterward.
Answer A is incorrect because Dynamic ARP inspection validates ARP messages at Layer 2 and is unrelated to administrative AAA logging. At Quartz, AAA accounting evidence is checked directly. The ARP inspection choice at Quartz therefore misses the required outcome. At Quartz, the AAA accounting state is observable afterward.
Question 20
Summit compares a console cable with SSH for network-device management. Which distinction is correct? Choose ONE.
- SSH works without an IP address but console requires DNS
- Console is always encrypted across the production LAN; SSH is not
- Console access does not require the device’s IP management path; SSH does
- Both methods require the wireless controller
Correct Answer: C
Correct Answer
Answer C is correct because Console management reaches the device through a local/terminal-server serial path and does not depend on the device’s IP management interface, whereas SSH requires IP connectivity. At Summit, console versus SSH evidence is checked directly. The Console access choice at Summit therefore meets the required outcome. At Summit, the console versus SSH state is observable afterward.
Incorrect Answers
Answer A is incorrect because SSH is an IP protocol and cannot operate to a device with no reachable IP path; DNS is optional name resolution rather than a requirement for local console access. At Summit, console versus SSH evidence is checked directly. The SSH works choice at Summit therefore misses the required outcome. At Summit, the console versus SSH state is observable afterward.
Answer B is incorrect because Console traffic is not inherently a production-LAN encrypted session, while SSH is specifically designed to encrypt remote terminal communication. At Summit, console versus SSH evidence is checked directly. The Console is choice at Summit therefore misses the required outcome. At Summit, the console versus SSH state is observable afterward.
Answer D is incorrect because Neither ordinary console access nor SSH requires a wireless LAN controller to manage a router or switch. At Summit, console versus SSH evidence is checked directly. The Both methods choice at Summit therefore misses the required outcome. At Summit, the console versus SSH state is observable afterward.