Topic 19 Practice Test 1 covers Wireless Security and WPA2 PSK WLANs for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 5.9–5.10. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.
Question 1
A small branch employee WLAN has a documented requirement to identify the older TKIP-associated WPA security generation. Which technology or concept should be selected? Choose ONE.
- WPA2/WPA3 Enterprise with 802.1X
- WPA with TKIP
- WPA2 with AES/CCMP
- Protected Management Frames (PMF)
Correct Answer: B
Correct Answer
Answer B is correct because The evidence at a small branch employee WLAN points to WPA with TKIP. It represents the older WPA generation that commonly uses TKIP and provides weaker legacy protection. That capability supports the requirement to identify the older TKIP-associated WPA security generation.
Incorrect Answers
Answer C is incorrect because This option uses WPA2 with AES/CCMP for configuring a CCNA-scope WPA2 WLAN that requires modern encryption rather than TKIP. At a small branch employee WLAN, the required function belongs to WPA with TKIP. The mechanism does not match.
Answer D is incorrect because Using Protected Management Frames (PMF), the design protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. For a small branch employee WLAN, the missing function is to identify the older TKIP-associated WPA security generation; WPA with TKIP supplies it.
Answer A is incorrect because WPA2/WPA3 Enterprise with 802.1X uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. At a small branch employee WLAN, it does not provide the requirement to identify the older TKIP-associated WPA security generation. WPA with TKIP does.
Question 2
A clinic staff SSID has a documented requirement to protect the WLAN with WPA2 using AES/CCMP. Which mechanism should the engineer use? Choose ONE.
- WPA2 with AES/CCMP
- WPA3-Personal with SAE
- WPA2 Personal using a pre-shared key (PSK)
- Create or edit the WLAN profile
Correct Answer: A
Correct Answer
Answer A is correct because WPA2 with AES/CCMP is appropriate for a clinic staff SSID. Its typical use is configuring a CCNA-scope WPA2 WLAN that requires modern encryption rather than TKIP. It uses WPA2 protection with AES-based CCMP for confidentiality and integrity. Both clues point to this option.
Incorrect Answers
Answer B is incorrect because Using WPA3-Personal with SAE, the design uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. For a clinic staff SSID, the missing function is to protect the WLAN with WPA2 using AES/CCMP; WPA2 with AES/CCMP supplies it.
Answer C is incorrect because This option uses WPA2 Personal using a pre-shared key (PSK) for building the objective-required WPA2 PSK WLAN for a small environment that intentionally uses one shared secret. At a clinic staff SSID, the required function belongs to WPA2 with AES/CCMP. The mechanism does not match.
Answer D is incorrect because Create or edit the WLAN profile defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. That can be valid elsewhere, but a clinic staff SSID needs to protect the WLAN with WPA2 using AES/CCMP. WPA2 with AES/CCMP matches that objective.
Question 3
A warehouse handheld WLAN has a documented requirement to use modern personal WLAN authentication based on SAE. Which technology or concept should be selected? Choose ONE.
- WPA3-Personal with SAE
- WPA2/AES Layer 2 security policy
- WPA2/WPA3 Enterprise with 802.1X
- Protected Management Frames (PMF)
Correct Answer: A
Correct Answer
Answer A is correct because WPA3-Personal with SAE fits a warehouse handheld WLAN: it uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. That behavior matches the requirement to use modern personal WLAN authentication based on SAE. Other choices perform different roles.
Incorrect Answers
Answer D is incorrect because Protected Management Frames (PMF) protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. That can be valid elsewhere, but a warehouse handheld WLAN needs to use modern personal WLAN authentication based on SAE. WPA3-Personal with SAE matches that objective.
Answer C is incorrect because WPA2/WPA3 Enterprise with 802.1X is intended for requiring unique user or device authentication and centrally controlled enterprise credentials. The scenario at a warehouse handheld WLAN instead requires a mechanism to use modern personal WLAN authentication based on SAE. That is the role of WPA3-Personal with SAE.
Answer B is incorrect because WPA2/AES Layer 2 security policy selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. That can be valid elsewhere, but a warehouse handheld WLAN needs to use modern personal WLAN authentication based on SAE. WPA3-Personal with SAE matches that objective.
Question 4
A training-room wireless network has a documented requirement to protect management frames from forged deauthentication or disassociation. Which mechanism should the engineer use? Choose ONE.
- Create or edit the WLAN profile
- Enter the pre-shared key in the WLAN security settings
- Protected Management Frames (PMF)
- WPA2 Personal using a pre-shared key (PSK)
Correct Answer: C
Correct Answer
Answer C is correct because For a training-room wireless network, the requirement is to protect management frames from forged deauthentication or disassociation. Protected Management Frames (PMF) provides that function. It matches the evidence. Encryption of user data alone does not authenticate all protected management frames.
Incorrect Answers
Answer D is incorrect because For a training-room wireless network, WPA2 Personal using a pre-shared key (PSK) solves the wrong problem. It authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. The scenario needs to protect management frames from forged deauthentication or disassociation, which points to Protected Management Frames (PMF).
Answer A is incorrect because This option uses Create or edit the WLAN profile for starting a controller GUI workflow for a new SSID before selecting its Layer 2 security settings. At a training-room wireless network, the required function belongs to Protected Management Frames (PMF). The mechanism does not match.
Answer B is incorrect because This option uses Enter the pre-shared key in the WLAN security settings for completing the WPA2-PSK credential portion of a controller GUI WLAN configuration. At a training-room wireless network, the required function belongs to Protected Management Frames (PMF). The mechanism does not match.
Question 5
A retail back-office SSID has a documented requirement to authenticate a small WLAN with one shared passphrase. Which technology or concept should be selected? Choose ONE.
- Enable the WLAN after applying its configuration
- WPA2 Personal using a pre-shared key (PSK)
- WPA2/WPA3 Enterprise with 802.1X
- WPA2/AES Layer 2 security policy
Correct Answer: B
Correct Answer
Answer B is correct because The evidence at a retail back-office SSID points to WPA2 Personal using a pre-shared key (PSK). It authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. That capability supports the requirement to authenticate a small WLAN with one shared passphrase.
Incorrect Answers
Answer C is incorrect because Using WPA2/WPA3 Enterprise with 802.1X, the design uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. For a retail back-office SSID, the missing function is to authenticate a small WLAN with one shared passphrase; WPA2 Personal using a pre-shared key (PSK) supplies it.
Answer D is incorrect because This option uses WPA2/AES Layer 2 security policy for ensuring the WLAN is actually protected by WPA2/AES rather than remaining open or using legacy TKIP. At a retail back-office SSID, the required function belongs to WPA2 Personal using a pre-shared key (PSK). The mechanism does not match.
Answer A is incorrect because Enable the WLAN after applying its configuration allows the configured WLAN to begin servicing clients after its profile and security settings are complete. At a retail back-office SSID, it does not provide the requirement to authenticate a small WLAN with one shared passphrase. WPA2 Personal using a pre-shared key (PSK) does.
Question 6
A temporary project-office WLAN has a documented requirement to use individual enterprise credentials backed by AAA. Which mechanism should the engineer use? Choose ONE.
- WPA2/WPA3 transition mode
- Enter the pre-shared key in the WLAN security settings
- Create or edit the WLAN profile
- WPA2/WPA3 Enterprise with 802.1X
Correct Answer: D
Correct Answer
Answer D is correct because WPA2/WPA3 Enterprise with 802.1X fits a temporary project-office WLAN: it uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. That behavior matches the requirement to use individual enterprise credentials backed by AAA. Other choices perform different roles.
Incorrect Answers
Answer C is incorrect because For a temporary project-office WLAN, Create or edit the WLAN profile solves the wrong problem. It defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. The scenario needs to use individual enterprise credentials backed by AAA, which points to WPA2/WPA3 Enterprise with 802.1X.
Answer B is incorrect because For a temporary project-office WLAN, Enter the pre-shared key in the WLAN security settings solves the wrong problem. It configures the shared secret that WPA2 Personal clients must possess to authenticate. The scenario needs to use individual enterprise credentials backed by AAA, which points to WPA2/WPA3 Enterprise with 802.1X.
Answer A is incorrect because WPA2/WPA3 transition mode allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. At a temporary project-office WLAN, it does not provide the requirement to use individual enterprise credentials backed by AAA. WPA2/WPA3 Enterprise with 802.1X does.
Question 7
A small hotel staff network has a documented requirement to define the WLAN identity before adding security settings. Which technology or concept should be selected? Choose ONE.
- WPA2/AES Layer 2 security policy
- Enable the WLAN after applying its configuration
- WPA with TKIP
- Create or edit the WLAN profile
Correct Answer: D
Correct Answer
Answer D is correct because The evidence at a small hotel staff network points to Create or edit the WLAN profile. It defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. That capability supports the requirement to define the WLAN identity before adding security settings.
Incorrect Answers
Answer A is incorrect because For a small hotel staff network, WPA2/AES Layer 2 security policy solves the wrong problem. It selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. The scenario needs to define the WLAN identity before adding security settings, which points to Create or edit the WLAN profile.
Answer B is incorrect because Enable the WLAN after applying its configuration is intended for making a correctly configured but administratively disabled WLAN available for client association. The scenario at a small hotel staff network instead requires a mechanism to define the WLAN identity before adding security settings. That is the role of Create or edit the WLAN profile.
Answer C is incorrect because WPA with TKIP represents the older WPA generation that commonly uses TKIP and provides weaker legacy protection. At a small hotel staff network, it does not provide the requirement to define the WLAN identity before adding security settings. Create or edit the WLAN profile does.
Question 8
A field engineering SSID has a documented requirement to select WPA2 and AES as the Layer 2 security policy. Which mechanism should the engineer use? Choose ONE.
- WPA2/WPA3 transition mode
- WPA2 with AES/CCMP
- WPA2/AES Layer 2 security policy
- Enter the pre-shared key in the WLAN security settings
Correct Answer: C
Correct Answer
Answer C is correct because The evidence at a field engineering SSID points to WPA2/AES Layer 2 security policy. It selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. That capability supports the requirement to select WPA2 and AES as the Layer 2 security policy.
Incorrect Answers
Answer D is incorrect because Enter the pre-shared key in the WLAN security settings configures the shared secret that WPA2 Personal clients must possess to authenticate. At a field engineering SSID, it does not provide the requirement to select WPA2 and AES as the Layer 2 security policy. WPA2/AES Layer 2 security policy does.
Answer A is incorrect because WPA2/WPA3 transition mode is intended for migrating a mixed client population without forcing every device to support WPA3 on the first day. The scenario at a field engineering SSID instead requires a mechanism to select WPA2 and AES as the Layer 2 security policy. That is the role of WPA2/AES Layer 2 security policy.
Answer B is incorrect because For a field engineering SSID, WPA2 with AES/CCMP solves the wrong problem. It uses WPA2 protection with AES-based CCMP for confidentiality and integrity. The scenario needs to select WPA2 and AES as the Layer 2 security policy, which points to WPA2/AES Layer 2 security policy.
Question 9
A new WPA2-PSK employee WLAN being configured in the controller GUI has two independent requirements. First, it must select WPA2 and AES as the Layer 2 security policy. Second, it must configure the shared authentication secret. Which TWO choices satisfy those requirements? Choose TWO.
- WPA2/AES Layer 2 security policy
- Protected Management Frames (PMF)
- WPA2 with AES/CCMP
- WPA2/WPA3 transition mode
- Enter the pre-shared key in the WLAN security settings
Correct Answers: A, E
Correct Answers
Answer A is correct because WPA2/AES Layer 2 security policy fits a new WPA2-PSK employee WLAN being configured in the controller GUI: it selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. That behavior matches the requirement to select WPA2 and AES as the Layer 2 security policy. Other choices perform different roles.
Answer E is correct because The evidence at a new WPA2-PSK employee WLAN being configured in the controller GUI points to Enter the pre-shared key in the WLAN security settings. It configures the shared secret that WPA2 Personal clients must possess to authenticate. That capability supports the requirement to configure the shared authentication secret.
Incorrect Answers
Answer D is incorrect because WPA2/WPA3 transition mode does not satisfy the paired requirement at a new WPA2-PSK employee WLAN being configured in the controller GUI. It allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. The needed choices are WPA2/AES Layer 2 security policy and Enter the pre-shared key in the WLAN security settings.
Answer C is incorrect because WPA2 with AES/CCMP uses WPA2 protection with AES-based CCMP for confidentiality and integrity. The pair required at a new WPA2-PSK employee WLAN being configured in the controller GUI is WPA2/AES Layer 2 security policy plus Enter the pre-shared key in the WLAN security settings. This option serves another role.
Answer B is incorrect because Protected Management Frames (PMF) is used for protecting wireless management exchanges in a WPA3 deployment from forged disconnect frames. In a new WPA2-PSK employee WLAN being configured in the controller GUI, the required functions come from WPA2/AES Layer 2 security policy and Enter the pre-shared key in the WLAN security settings. It is not one of them.
Question 10
A finance branch wireless network has a documented requirement to make the completed WLAN administratively available to clients. Which mechanism should the engineer use? Choose ONE.
- Enable the WLAN after applying its configuration
- WPA2/WPA3 transition mode
- WPA2 with AES/CCMP
- Protected Management Frames (PMF)
Correct Answer: A
Correct Answer
Answer A is correct because Enable the WLAN after applying its configuration fits a finance branch wireless network: it allows the configured WLAN to begin servicing clients after its profile and security settings are complete. That behavior matches the requirement to make the completed WLAN administratively available to clients. Other choices perform different roles.
Incorrect Answers
Answer B is incorrect because Using WPA2/WPA3 transition mode, the design allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. For a finance branch wireless network, the missing function is to make the completed WLAN administratively available to clients; Enable the WLAN after applying its configuration supplies it.
Answer C is incorrect because WPA2 with AES/CCMP uses WPA2 protection with AES-based CCMP for confidentiality and integrity. At a finance branch wireless network, it does not provide the requirement to make the completed WLAN administratively available to clients. Enable the WLAN after applying its configuration does.
Answer D is incorrect because This option uses Protected Management Frames (PMF) for protecting wireless management exchanges in a WPA3 deployment from forged disconnect frames. At a finance branch wireless network, the required function belongs to Enable the WLAN after applying its configuration. The mechanism does not match.
Question 11
A support-center WLAN has a documented requirement to support WPA2 and WPA3 clients during a staged migration. Which technology or concept should be selected? Choose ONE.
- WPA with TKIP
- WPA3-Personal with SAE
- WPA2 Personal using a pre-shared key (PSK)
- WPA2/WPA3 transition mode
Correct Answer: D
Correct Answer
Answer D is correct because WPA2/WPA3 transition mode fits a support-center WLAN: it allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. That behavior matches the requirement to support WPA2 and WPA3 clients during a staged migration. Other choices perform different roles.
Incorrect Answers
Answer A is incorrect because Using WPA with TKIP, the design represents the older WPA generation that commonly uses TKIP and provides weaker legacy protection. For a support-center WLAN, the missing function is to support WPA2 and WPA3 clients during a staged migration; WPA2/WPA3 transition mode supplies it.
Answer B is incorrect because This option uses WPA3-Personal with SAE for selecting the current personal-mode successor to WPA2-PSK when client support permits WPA3. At a support-center WLAN, the required function belongs to WPA2/WPA3 transition mode. The mechanism does not match.
Answer C is incorrect because WPA2 Personal using a pre-shared key (PSK) authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. At a support-center WLAN, it does not provide the requirement to support WPA2 and WPA3 clients during a staged migration. WPA2/WPA3 transition mode does.
Question 12
During troubleshooting of a conference-room SSID, the missing capability is one that uses WPA2 protection with AES-based CCMP for confidentiality and integrity. Which option best addresses this requirement? Choose ONE.
- WPA3-Personal with SAE
- WPA2 with AES/CCMP
- Create or edit the WLAN profile
- WPA2 Personal using a pre-shared key (PSK)
Correct Answer: B
Correct Answer
Answer B is correct because WPA2 with AES/CCMP is appropriate for a conference-room SSID. Its typical use is configuring a CCNA-scope WPA2 WLAN that requires modern encryption rather than TKIP. It uses WPA2 protection with AES-based CCMP for confidentiality and integrity. Both clues point to this option.
Incorrect Answers
Answer A is incorrect because Using WPA3-Personal with SAE, the design uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. For a conference-room SSID, the missing function is to protect the WLAN with WPA2 using AES/CCMP; WPA2 with AES/CCMP supplies it.
Answer D is incorrect because This option uses WPA2 Personal using a pre-shared key (PSK) for building the objective-required WPA2 PSK WLAN for a small environment that intentionally uses one shared secret. At a conference-room SSID, the required function belongs to WPA2 with AES/CCMP. The mechanism does not match.
Answer C is incorrect because Create or edit the WLAN profile defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. That can be valid elsewhere, but a conference-room SSID needs to protect the WLAN with WPA2 using AES/CCMP. WPA2 with AES/CCMP matches that objective.
Question 13
During troubleshooting of a remote sales-office WLAN, the missing capability is one that uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. Which option provides the required function? Choose ONE.
- WPA2/AES Layer 2 security policy
- WPA3-Personal with SAE
- Protected Management Frames (PMF)
- WPA2/WPA3 Enterprise with 802.1X
Correct Answer: B
Correct Answer
Answer B is correct because WPA3-Personal with SAE fits a remote sales-office WLAN: it uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. That behavior matches the requirement to use modern personal WLAN authentication based on SAE. Other choices perform different roles.
Incorrect Answers
Answer C is incorrect because Protected Management Frames (PMF) protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. That can be valid elsewhere, but a remote sales-office WLAN needs to use modern personal WLAN authentication based on SAE. WPA3-Personal with SAE matches that objective.
Answer D is incorrect because WPA2/WPA3 Enterprise with 802.1X is intended for requiring unique user or device authentication and centrally controlled enterprise credentials. The scenario at a remote sales-office WLAN instead requires a mechanism to use modern personal WLAN authentication based on SAE. That is the role of WPA3-Personal with SAE.
Answer A is incorrect because WPA2/AES Layer 2 security policy selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. That can be valid elsewhere, but a remote sales-office WLAN needs to use modern personal WLAN authentication based on SAE. WPA3-Personal with SAE matches that objective.
Question 14
During troubleshooting of a design studio wireless network, the missing capability is one that authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. Which option best addresses this requirement? Choose ONE.
- WPA2 Personal using a pre-shared key (PSK)
- WPA2/WPA3 Enterprise with 802.1X
- WPA2/AES Layer 2 security policy
- Enable the WLAN after applying its configuration
Correct Answer: A
Correct Answer
Answer A is correct because WPA2 Personal using a pre-shared key (PSK) fits a design studio wireless network: it authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. That behavior matches the requirement to authenticate a small WLAN with one shared passphrase. Other choices perform different roles.
Incorrect Answers
Answer B is incorrect because For a design studio wireless network, WPA2/WPA3 Enterprise with 802.1X solves the wrong problem. It uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. The scenario needs to authenticate a small WLAN with one shared passphrase, which points to WPA2 Personal using a pre-shared key (PSK).
Answer C is incorrect because WPA2/AES Layer 2 security policy is intended for ensuring the WLAN is actually protected by WPA2/AES rather than remaining open or using legacy TKIP. The scenario at a design studio wireless network instead requires a mechanism to authenticate a small WLAN with one shared passphrase. That is the role of WPA2 Personal using a pre-shared key (PSK).
Answer D is incorrect because Enable the WLAN after applying its configuration allows the configured WLAN to begin servicing clients after its profile and security settings are complete. That can be valid elsewhere, but a design studio wireless network needs to authenticate a small WLAN with one shared passphrase. WPA2 Personal using a pre-shared key (PSK) matches that objective.
Question 15
During troubleshooting of a laboratory staff SSID, the missing capability is one that uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. Which option provides the required function? Choose ONE.
- WPA2/WPA3 Enterprise with 802.1X
- WPA2/WPA3 transition mode
- Enter the pre-shared key in the WLAN security settings
- Create or edit the WLAN profile
Correct Answer: A
Correct Answer
Answer A is correct because The evidence at a laboratory staff SSID points to WPA2/WPA3 Enterprise with 802.1X. It uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. That capability supports the requirement to use individual enterprise credentials backed by AAA.
Incorrect Answers
Answer D is incorrect because Using Create or edit the WLAN profile, the design defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. For a laboratory staff SSID, the missing function is to use individual enterprise credentials backed by AAA; WPA2/WPA3 Enterprise with 802.1X supplies it.
Answer C is incorrect because Using Enter the pre-shared key in the WLAN security settings, the design configures the shared secret that WPA2 Personal clients must possess to authenticate. For a laboratory staff SSID, the missing function is to use individual enterprise credentials backed by AAA; WPA2/WPA3 Enterprise with 802.1X supplies it.
Answer B is incorrect because WPA2/WPA3 transition mode allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. That can be valid elsewhere, but a laboratory staff SSID needs to use individual enterprise credentials backed by AAA. WPA2/WPA3 Enterprise with 802.1X matches that objective.
Question 16
During troubleshooting of a municipal branch WLAN, the missing capability is one that protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. Which option best addresses this requirement? Choose ONE.
- Create or edit the WLAN profile
- Enter the pre-shared key in the WLAN security settings
- Protected Management Frames (PMF)
- WPA2 Personal using a pre-shared key (PSK)
Correct Answer: C
Correct Answer
Answer C is correct because For a municipal branch WLAN, the requirement is to protect management frames from forged deauthentication or disassociation. Protected Management Frames (PMF) provides that function. It matches the evidence. Encryption of user data alone does not authenticate all protected management frames.
Incorrect Answers
Answer D is incorrect because For a municipal branch WLAN, WPA2 Personal using a pre-shared key (PSK) solves the wrong problem. It authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. The scenario needs to protect management frames from forged deauthentication or disassociation, which points to Protected Management Frames (PMF).
Answer A is incorrect because This option uses Create or edit the WLAN profile for starting a controller GUI workflow for a new SSID before selecting its Layer 2 security settings. At a municipal branch WLAN, the required function belongs to Protected Management Frames (PMF). The mechanism does not match.
Answer B is incorrect because This option uses Enter the pre-shared key in the WLAN security settings for completing the WPA2-PSK credential portion of a controller GUI WLAN configuration. At a municipal branch WLAN, the required function belongs to Protected Management Frames (PMF). The mechanism does not match.
Question 17
During troubleshooting of a library staff wireless network, the missing capability is one that selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. Which option provides the required function? Choose ONE.
- WPA2 with AES/CCMP
- WPA2/AES Layer 2 security policy
- Enter the pre-shared key in the WLAN security settings
- WPA2/WPA3 transition mode
Correct Answer: B
Correct Answer
Answer B is correct because WPA2/AES Layer 2 security policy fits a library staff wireless network: it selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. That behavior matches the requirement to select WPA2 and AES as the Layer 2 security policy. Other choices perform different roles.
Incorrect Answers
Answer C is incorrect because Enter the pre-shared key in the WLAN security settings configures the shared secret that WPA2 Personal clients must possess to authenticate. That can be valid elsewhere, but a library staff wireless network needs to select WPA2 and AES as the Layer 2 security policy. WPA2/AES Layer 2 security policy matches that objective.
Answer D is incorrect because This option uses WPA2/WPA3 transition mode for migrating a mixed client population without forcing every device to support WPA3 on the first day. At a library staff wireless network, the required function belongs to WPA2/AES Layer 2 security policy. The mechanism does not match.
Answer A is incorrect because Using WPA2 with AES/CCMP, the design uses WPA2 protection with AES-based CCMP for confidentiality and integrity. For a library staff wireless network, the missing function is to select WPA2 and AES as the Layer 2 security policy; WPA2/AES Layer 2 security policy supplies it.
Question 18
A WPA3-Personal WLAN being hardened against password and management-frame attacks has two independent requirements. First, it must use modern personal WLAN authentication based on SAE. Second, it must protect management frames from forged deauthentication or disassociation. Which TWO choices satisfy those requirements? Choose TWO.
- Enable the WLAN after applying its configuration
- WPA2/AES Layer 2 security policy
- WPA2/WPA3 Enterprise with 802.1X
- Protected Management Frames (PMF)
- WPA3-Personal with SAE
Correct Answers: D, E
Correct Answers
Answer E is correct because The evidence at a WPA3-Personal WLAN being hardened against password and management-frame attacks points to WPA3-Personal with SAE. It uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. That capability supports the requirement to use modern personal WLAN authentication based on SAE.
Answer D is correct because Protected Management Frames (PMF) fits a WPA3-Personal WLAN being hardened against password and management-frame attacks: it protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. That behavior matches the requirement to protect management frames from forged deauthentication or disassociation. Other choices perform different roles.
Incorrect Answers
Answer C is incorrect because WPA2/WPA3 Enterprise with 802.1X uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. The pair required at a WPA3-Personal WLAN being hardened against password and management-frame attacks is WPA3-Personal with SAE plus Protected Management Frames (PMF). This option serves another role.
Answer B is incorrect because WPA2/AES Layer 2 security policy is used for ensuring the WLAN is actually protected by WPA2/AES rather than remaining open or using legacy TKIP. In a WPA3-Personal WLAN being hardened against password and management-frame attacks, the required functions come from WPA3-Personal with SAE and Protected Management Frames (PMF). It is not one of them.
Answer A is incorrect because Using Enable the WLAN after applying its configuration, the design allows the configured WLAN to begin servicing clients after its profile and security settings are complete. A WPA3-Personal WLAN being hardened against password and management-frame attacks instead needs both WPA3-Personal with SAE and Protected Management Frames (PMF). This addresses a different mechanism.
Question 19
During troubleshooting of a manufacturing office WLAN, the missing capability is one that allows the configured WLAN to begin servicing clients after its profile and security settings are complete. Which option provides the required function? Choose ONE.
- WPA2/WPA3 transition mode
- WPA2 with AES/CCMP
- Protected Management Frames (PMF)
- Enable the WLAN after applying its configuration
Correct Answer: D
Correct Answer
Answer D is correct because The evidence at a manufacturing office WLAN points to Enable the WLAN after applying its configuration. It allows the configured WLAN to begin servicing clients after its profile and security settings are complete. That capability supports the requirement to make the completed WLAN administratively available to clients.
Incorrect Answers
Answer A is incorrect because For a manufacturing office WLAN, WPA2/WPA3 transition mode solves the wrong problem. It allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. The scenario needs to make the completed WLAN administratively available to clients, which points to Enable the WLAN after applying its configuration.
Answer B is incorrect because WPA2 with AES/CCMP uses WPA2 protection with AES-based CCMP for confidentiality and integrity. That can be valid elsewhere, but a manufacturing office WLAN needs to make the completed WLAN administratively available to clients. Enable the WLAN after applying its configuration matches that objective.
Answer C is incorrect because Protected Management Frames (PMF) is intended for protecting wireless management exchanges in a WPA3 deployment from forged disconnect frames. The scenario at a manufacturing office WLAN instead requires a mechanism to make the completed WLAN administratively available to clients. That is the role of Enable the WLAN after applying its configuration.
Question 20
During troubleshooting of a professional-services branch WLAN, the missing capability is one that allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. Which option best addresses this requirement? Choose ONE.
- WPA3-Personal with SAE
- WPA2 Personal using a pre-shared key (PSK)
- WPA2/WPA3 transition mode
- WPA with TKIP
Correct Answer: C
Correct Answer
Answer C is correct because The evidence at a professional-services branch WLAN points to WPA2/WPA3 transition mode. It allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. That capability supports the requirement to support WPA2 and WPA3 clients during a staged migration.
Incorrect Answers
Answer D is incorrect because For a professional-services branch WLAN, WPA with TKIP solves the wrong problem. It represents the older WPA generation that commonly uses TKIP and provides weaker legacy protection. The scenario needs to support WPA2 and WPA3 clients during a staged migration, which points to WPA2/WPA3 transition mode.
Answer A is incorrect because WPA3-Personal with SAE is intended for selecting the current personal-mode successor to WPA2-PSK when client support permits WPA3. The scenario at a professional-services branch WLAN instead requires a mechanism to support WPA2 and WPA3 clients during a staged migration. That is the role of WPA2/WPA3 transition mode.
Answer B is incorrect because WPA2 Personal using a pre-shared key (PSK) authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. That can be valid elsewhere, but a professional-services branch WLAN needs to support WPA2 and WPA3 clients during a staged migration. WPA2/WPA3 transition mode matches that objective.