Cisco CCNA 200-301 Wireless Architectures, Infrastructure, and Device Management Practice Test 2

 

Topic 08 Practice Test 2 covers Wireless Architectures, Infrastructure, and Device Management for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 2.6–2.8. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.

Question 1

Beacon converts an AP from monitor mode back to its normal client-serving role at headquarters. Which mode should the AP use? Choose ONE.

  1. Monitor mode
  2. Local mode
  3. Sniffer mode
  4. Bridge mode

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Local mode is the standard client-serving mode for centrally managed campus APs, with the controller providing control and policy functions. At Beacon, local AP mode troubleshooting uses this evidence. The Local mode path at Beacon therefore meets the stated constraint. At Beacon, the local AP mode state is observable afterward.

Incorrect Answers

 

Answer A is incorrect because Monitor mode dedicates the AP primarily to RF monitoring and security/scanning functions rather than normal client service. At Beacon, local AP mode troubleshooting uses this evidence. The Monitor mode path at Beacon therefore misses the stated constraint. At Beacon, the local AP mode state is observable afterward.

Answer C is incorrect because Sniffer mode captures 802.11 frames on a selected channel and forwards them to an analyzer instead of functioning as a normal production AP. At Beacon, local AP mode troubleshooting uses this evidence. The Sniffer mode path at Beacon therefore misses the stated constraint. At Beacon, the local AP mode state is observable afterward.

Answer D is incorrect because Bridge mode is used for wireless bridging/mesh-style connectivity and is not the ordinary campus client-serving mode requested. At Beacon, local AP mode troubleshooting uses this evidence. The Bridge mode path at Beacon therefore misses the stated constraint. At Beacon, the local AP mode state is observable afterward.

 

Question 2

Delta’s remote-office AP is centrally managed but should locally switch client data instead of tunneling all traffic to headquarters. Which mode best fits? Choose ONE.

  1. FlexConnect with local switching
  2. Monitor mode
  3. Local mode with central switching only
  4. Sniffer mode

Correct Answer: A

Correct Answer

 

 

Answer A is correct because FlexConnect supports remote-site deployments and can locally switch client traffic according to policy, reducing dependence on the WAN data path to a central controller. At Delta, FlexConnect troubleshooting uses this evidence. The FlexConnect with path at Delta therefore meets the stated constraint. At Delta, the FlexConnect state is observable afterward.

Incorrect Answers

 

Answer C is incorrect because Local mode with central switching sends client data through the controller path and does not provide the requested branch-local switching behavior. At Delta, FlexConnect troubleshooting uses this evidence. The Local mode path at Delta therefore misses the stated constraint. At Delta, the FlexConnect state is observable afterward.

Answer B is incorrect because Monitor mode is intended for RF/security observation and is not a client-serving branch architecture for local data forwarding. At Delta, FlexConnect troubleshooting uses this evidence. The Monitor mode path at Delta therefore misses the stated constraint. At Delta, the FlexConnect state is observable afterward.

Answer D is incorrect because Sniffer mode captures wireless frames for analysis and does not provide normal user connectivity or branch-local client switching. At Delta, FlexConnect troubleshooting uses this evidence. The Sniffer mode path at Delta therefore misses the stated constraint. At Delta, the FlexConnect state is observable afterward.

 

Question 3

Falcon troubleshoots a local-mode AP: control connectivity to the controller is essential, and centrally switched client traffic is also tunneled toward the controller. Which protocol relationship is being described? Choose ONE.

  1. CAPWAP replaces 802.1Q on every switch trunk
  2. CAPWAP provides AP-controller control and can carry centrally switched client data tunnels
  3. CAPWAP is the RADIUS authentication method used by clients
  4. CAPWAP is only a Layer 2 loop-prevention protocol

Correct Answer: B

Correct Answer

 

 

Answer B is correct because CAPWAP establishes AP-to-controller control communication and, in centrally switched designs, is also used to tunnel client data toward the controller. At Falcon, CAPWAP path troubleshooting uses this evidence. The CAPWAP provides path at Falcon therefore meets the stated constraint. At Falcon, the CAPWAP path state is observable afterward.

Incorrect Answers

 

Answer D is incorrect because Loop prevention at Layer 2 is handled by spanning-tree mechanisms, not CAPWAP. At Falcon, CAPWAP path troubleshooting uses this evidence. The CAPWAP is path at Falcon therefore misses the stated constraint. At Falcon, the CAPWAP path state is observable afterward.

Answer A is incorrect because CAPWAP does not replace Ethernet VLAN tagging on wired trunks; the wired network can still use 802.1Q where VLAN transport is required. At Falcon, CAPWAP path troubleshooting uses this evidence. The CAPWAP replaces path at Falcon therefore misses the stated constraint. At Falcon, the CAPWAP path state is observable afterward.

Answer C is incorrect because RADIUS may support AAA for client authentication, but CAPWAP is the AP-controller tunneling/control mechanism rather than the client’s authentication protocol. At Falcon, CAPWAP path troubleshooting uses this evidence. The CAPWAP is path at Falcon therefore misses the stated constraint. At Falcon, the CAPWAP path state is observable afterward.

 

Question 4

Harbor sees an AP that intentionally does not advertise production WLANs and instead continuously monitors RF activity. Which mode most likely explains this behavior? Choose ONE.

  1. Local mode
  2. Monitor mode
  3. FlexConnect local switching
  4. Bridge mode

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Monitor mode dedicates the AP to RF monitoring/scanning functions such as rogue detection and spectrum/security observation instead of ordinary client service. At Harbor, monitor mode troubleshooting uses this evidence. The Monitor mode path at Harbor therefore meets the stated constraint. At Harbor, the monitor mode state is observable afterward.

Incorrect Answers

 

Answer A is incorrect because Local mode is primarily a client-serving mode and therefore does not match an AP intentionally dedicated to continuous monitoring. At Harbor, monitor mode troubleshooting uses this evidence. The Local mode path at Harbor therefore misses the stated constraint. At Harbor, the monitor mode state is observable afterward.

Answer C is incorrect because FlexConnect local switching is for remote-site client service with local data forwarding, not for a sensor-only RF monitoring role. At Harbor, monitor mode troubleshooting uses this evidence. The FlexConnect local path at Harbor therefore misses the stated constraint. At Harbor, the monitor mode state is observable afterward.

Answer D is incorrect because Bridge mode focuses on wireless backhaul/bridging use cases rather than continuous non-client-serving RF monitoring. At Harbor, monitor mode troubleshooting uses this evidence. The Bridge mode path at Harbor therefore misses the stated constraint. At Harbor, the monitor mode state is observable afterward.

 

Question 5

Juniper’s AP stops serving clients after it is configured to send wireless frame captures to an analysis workstation. Which specialized mode is it using? Choose ONE.

  1. FlexConnect
  2. Local mode
  3. Sniffer mode
  4. Monitor mode only

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Sniffer mode captures wireless frames on a configured channel and forwards the encapsulated traffic to a remote analyzer for detailed packet inspection. At Juniper, sniffer mode troubleshooting uses this evidence. The Sniffer mode path at Juniper therefore meets the stated constraint. At Juniper, the sniffer mode state is observable afterward.

Incorrect Answers

 

Answer B is incorrect because Local mode is intended for production client access rather than dedicating the AP to remote packet capture. At Juniper, sniffer mode troubleshooting uses this evidence. The Local mode path at Juniper therefore misses the stated constraint. At Juniper, the sniffer mode state is observable afterward.

Answer D is incorrect because Monitor mode performs RF/security observation, but the explicit remote packet-capture workflow described is the sniffer function. At Juniper, sniffer mode troubleshooting uses this evidence. The Monitor mode path at Juniper therefore misses the stated constraint. At Juniper, the sniffer mode state is observable afterward.

Answer A is incorrect because FlexConnect is a remote-site client-serving architecture and does not describe an AP dedicated to forwarding packet captures to an analyzer. At Juniper, sniffer mode troubleshooting uses this evidence. The FlexConnect path at Juniper therefore misses the stated constraint. At Juniper, the sniffer mode state is observable afterward.

 

Question 6

Lumen’s outdoor AP pair is being used to bridge Ethernet networks across a wireless link rather than only serving endpoint clients. Which mode best describes the requirement? Choose ONE.

  1. Local mode only
  2. Bridge/mesh mode
  3. Monitor mode
  4. Sniffer mode

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Bridge or mesh modes support wireless backhaul between network segments and are appropriate when APs form a wireless infrastructure link. At Lumen, wireless bridge troubleshooting uses this evidence. The Bridge/mesh mode path at Lumen therefore meets the stated constraint. At Lumen, the wireless bridge state is observable afterward.

Incorrect Answers

 

Answer D is incorrect because Sniffer mode is for packet capture and analysis, not for providing a production wireless backhaul between Ethernet segments. At Lumen, wireless bridge troubleshooting uses this evidence. The Sniffer mode path at Lumen therefore misses the stated constraint. At Lumen, the wireless bridge state is observable afterward.

Answer C is incorrect because Monitor mode observes RF conditions and does not provide the normal bridge path required between the two wired sites. At Lumen, wireless bridge troubleshooting uses this evidence. The Monitor mode path at Lumen therefore misses the stated constraint. At Lumen, the wireless bridge state is observable afterward.

Answer A is incorrect because Local client-serving mode is not the specialized role used when the APs themselves provide the inter-site wireless bridge/backhaul. At Lumen, wireless bridge troubleshooting uses this evidence. The Local mode path at Lumen therefore misses the stated constraint. At Lumen, the wireless bridge state is observable afterward.

 

Question 7

Northstar’s AP has power and IP reachability but has not joined its central management system, so it does not receive the enterprise WLAN configuration. Which infrastructure component is missing from the control relationship? Choose ONE.

  1. NTP server
  2. DHCP client on the user’s laptop
  3. Layer 2 access switch only
  4. Wireless LAN controller

Correct Answer: D

Correct Answer

 

 

Answer D is correct because The wireless LAN controller centrally defines WLANs, profiles, tags, and AP policy; an AP must establish the controller relationship to receive and operate under that centralized configuration. At Northstar, controller join troubleshooting uses this evidence. The Wireless LAN path at Northstar therefore meets the stated constraint. At Northstar, the controller join state is observable afterward.

Incorrect Answers

 

Answer C is incorrect because The access switch provides Ethernet/PoE/VLAN connectivity but does not replace the controller’s centralized wireless policy and WLAN-management role. At Northstar, controller join troubleshooting uses this evidence. The Layer 2 path at Northstar therefore misses the stated constraint. At Northstar, the controller join state is observable afterward.

Answer B is incorrect because A client DHCP process assigns endpoint addressing after association and cannot provide AP configuration or centralized wireless policy. At Northstar, controller join troubleshooting uses this evidence. The DHCP client path at Northstar therefore misses the stated constraint. At Northstar, the controller join state is observable afterward.

Answer A is incorrect because NTP can synchronize time, but it is not the infrastructure component that joins, manages, and distributes WLAN policy to APs. At Northstar, controller join troubleshooting uses this evidence. The NTP server path at Northstar therefore misses the stated constraint. At Northstar, the controller join state is observable afterward.

 

Question 8

Pioneer’s AP loses power when moved to a switchport that has Ethernet link capability but no power sourcing. Which physical-infrastructure feature should be checked? Choose ONE.

  1. Power over Ethernet (PoE)
  2. SPAN
  3. LACP
  4. Root Guard

Correct Answer: A

Correct Answer

 

 

Answer A is correct because PoE supplies electrical power over the Ethernet cabling while the same link carries network traffic, which is the standard single-cable AP deployment model. At Pioneer, PoE uplink troubleshooting uses this evidence. The Power over path at Pioneer therefore meets the stated constraint. At Pioneer, the PoE uplink state is observable afterward.

Incorrect Answers

 

Answer C is incorrect because LACP negotiates link aggregation and does not deliver electrical power to an attached AP. At Pioneer, PoE uplink troubleshooting uses this evidence. The LACP path at Pioneer therefore misses the stated constraint. At Pioneer, the PoE uplink state is observable afterward.

Answer B is incorrect because SPAN mirrors switch traffic for analysis and is unrelated to powering the AP. At Pioneer, PoE uplink troubleshooting uses this evidence. The SPAN path at Pioneer therefore misses the stated constraint. At Pioneer, the PoE uplink state is observable afterward.

Answer D is incorrect because Root Guard is a spanning-tree protection feature and does not provide power or physical Ethernet service to an access point. At Pioneer, PoE uplink troubleshooting uses this evidence. The Root Guard path at Pioneer therefore misses the stated constraint. At Pioneer, the PoE uplink state is observable afterward.

 

Question 9

Redwood’s clients associate successfully but cannot reach their wired VLAN because the controller-facing switching path does not carry that VLAN. Which infrastructure area should be corrected? Choose ONE.

  1. Put all clients into the AP management VLAN
  2. Disable the WLAN’s policy mapping
  3. Convert every AP uplink to a routed port with the client subnet
  4. Ensure the required client VLAN is available on the appropriate controller/wired switching path

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Centrally switched client traffic emerges through the controller-side wired network, so the intended client VLAN must be available and correctly transported on that infrastructure path. At Redwood, client VLAN path troubleshooting uses this evidence. The Ensure the path at Redwood therefore meets the stated constraint. At Redwood, the client VLAN path state is observable afterward.

Incorrect Answers

 

Answer C is incorrect because AP uplinks do not each need to become routed ports for a centrally switched client subnet; doing so would not fix the controller-side VLAN transport requirement. At Redwood, client VLAN path troubleshooting uses this evidence. The Convert every path at Redwood therefore misses the stated constraint. At Redwood, the client VLAN path state is observable afterward.

Answer B is incorrect because Removing WLAN-to-policy mapping would prevent the controller from applying the intended client policy and would worsen, not solve, the connectivity problem. At Redwood, client VLAN path troubleshooting uses this evidence. The Disable the path at Redwood therefore misses the stated constraint. At Redwood, the client VLAN path state is observable afterward.

Answer A is incorrect because Placing user clients into the AP management VLAN collapses management and client segmentation and is not the normal fix for a missing client-VLAN path. At Redwood, client VLAN path troubleshooting uses this evidence. The Put all path at Redwood therefore misses the stated constraint. At Redwood, the client VLAN path state is observable afterward.

 

Question 10

Tundra has a WLAN profile and a correct policy profile, but the AP does not receive the intended pairing. Which Catalyst 9800 configuration object should be reviewed? Choose ONE.

  1. Site tag
  2. RF tag
  3. AP join profile only
  4. Policy tag

Correct Answer: D

Correct Answer

 

 

Answer D is correct because A policy tag maps WLAN profiles to policy profiles and determines which WLAN/policy combinations are deployed to APs assigned that tag. At Tundra, policy tag troubleshooting uses this evidence. The Policy tag path at Tundra therefore meets the stated constraint. At Tundra, the policy tag state is observable afterward.

Incorrect Answers

 

Answer A is incorrect because A site tag controls site-related AP behavior such as FlexConnect/local-mode characteristics but does not itself create the WLAN-to-policy-profile mapping. At Tundra, policy tag troubleshooting uses this evidence. The Site tag path at Tundra therefore misses the stated constraint. At Tundra, the policy tag state is observable afterward.

Answer B is incorrect because An RF tag groups RF profiles and radio-related settings; it does not map a WLAN profile to a client policy profile. At Tundra, policy tag troubleshooting uses this evidence. The RF tag path at Tundra therefore misses the stated constraint. At Tundra, the policy tag state is observable afterward.

Answer C is incorrect because AP join profiles contain AP-level join/management settings and do not replace the policy-tag mapping between WLAN and policy profiles. At Tundra, policy tag troubleshooting uses this evidence. The AP join path at Tundra therefore misses the stated constraint. At Tundra, the policy tag state is observable afterward.

 

Question 11

Beacon needs to repair a router before any management IP interface is reachable. Which access method avoids dependence on the IP network? Choose ONE.

  1. HTTPS
  2. Console access
  3. SSH
  4. TACACS+ over the production network

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Console access is out-of-band with respect to the device’s IP forwarding path and is therefore suitable when remote IP management is unavailable. At Beacon, console recovery troubleshooting uses this evidence. The Console access path at Beacon therefore meets the stated constraint. At Beacon, the console recovery state is observable afterward.

Incorrect Answers

 

Answer C is incorrect because SSH requires working IP connectivity to the device, so it cannot be the first recovery method when no management address is reachable. At Beacon, console recovery troubleshooting uses this evidence. The SSH path at Beacon therefore misses the stated constraint. At Beacon, the console recovery state is observable afterward.

Answer A is incorrect because HTTPS also depends on IP connectivity and the web-management service, which are unavailable in the stated failure. At Beacon, console recovery troubleshooting uses this evidence. The HTTPS path at Beacon therefore misses the stated constraint. At Beacon, the console recovery state is observable afterward.

Answer D is incorrect because Remote TACACS+ authentication depends on network reachability to both the device and AAA server and is less suitable than local console recovery in this outage. At Beacon, console recovery troubleshooting uses this evidence. The TACACS+ over path at Beacon therefore misses the stated constraint. At Beacon, the console recovery state is observable afterward.

 

Question 12

Delta finds administrators using Telnet to manage switches across an untrusted operations network. Which replacement provides confidentiality and server authentication capabilities? Choose ONE.

  1. HTTP
  2. SSH
  3. TFTP
  4. Telnet

Correct Answer: B

Correct Answer

 

 

Answer B is correct because SSH provides encrypted remote terminal access and is the preferred IP-based CLI management protocol when confidentiality and integrity matter. At Delta, SSH management troubleshooting uses this evidence. The SSH path at Delta therefore meets the stated constraint. At Delta, the SSH management state is observable afterward.

Incorrect Answers

 

Answer D is incorrect because Telnet sends its session data without encryption and is therefore inappropriate when the management path must protect credentials and commands. At Delta, SSH management troubleshooting uses this evidence. The Telnet path at Delta therefore misses the stated constraint. At Delta, the SSH management state is observable afterward.

Answer A is incorrect because HTTP can support web management but plain HTTP is unencrypted and is not an encrypted terminal protocol. At Delta, SSH management troubleshooting uses this evidence. The HTTP path at Delta therefore misses the stated constraint. At Delta, the SSH management state is observable afterward.

Answer C is incorrect because TFTP is a simple file-transfer protocol and does not provide interactive encrypted CLI administration. At Delta, SSH management troubleshooting uses this evidence. The TFTP path at Delta therefore misses the stated constraint. At Delta, the SSH management state is observable afterward.

 

Question 13

Falcon captures a Telnet management session and can read usernames, passwords, and commands. Which property of Telnet explains the exposure? Choose ONE.

  1. Telnet cannot use TCP
  2. Telnet requires a wireless controller
  3. Telnet automatically disables AAA
  4. Telnet does not encrypt the management session

Correct Answer: D

Correct Answer

 

 

Answer D is correct because Telnet transmits session content without encryption, so credentials and commands can be exposed to anyone able to observe the traffic path. At Falcon, Telnet exposure troubleshooting uses this evidence. The Telnet does path at Falcon therefore meets the stated constraint. At Falcon, the Telnet exposure state is observable afterward.

Incorrect Answers

 

Answer A is incorrect because Telnet does use TCP, so lack of a transport-layer connection is not the reason the session is insecure. At Falcon, Telnet exposure troubleshooting uses this evidence. The Telnet cannot path at Falcon therefore misses the stated constraint. At Falcon, the Telnet exposure state is observable afterward.

Answer B is incorrect because Telnet is a general IP terminal protocol and does not depend on wireless-controller infrastructure. At Falcon, Telnet exposure troubleshooting uses this evidence. The Telnet requires path at Falcon therefore misses the stated constraint. At Falcon, the Telnet exposure state is observable afterward.

Answer C is incorrect because Using Telnet does not inherently disable AAA; the weakness described is confidentiality of the session, not automatic removal of authentication controls. At Falcon, Telnet exposure troubleshooting uses this evidence. The Telnet automatically path at Falcon therefore misses the stated constraint. At Falcon, the Telnet exposure state is observable afterward.

 

Question 14

Harbor’s security scan flags a switch web interface because administrator credentials traverse the network without TLS. Which management protocol should replace it? Choose ONE.

  1. CDP
  2. HTTP
  3. Telnet
  4. HTTPS

Correct Answer: D

Correct Answer

 

 

Answer D is correct because HTTPS protects browser-based management with TLS, providing encrypted transport for the administrative web session. At Harbor, HTTPS management troubleshooting uses this evidence. The HTTPS path at Harbor therefore meets the stated constraint. At Harbor, the HTTPS management state is observable afterward.

Incorrect Answers

 

Answer B is incorrect because Plain HTTP does not encrypt the management exchange and therefore does not meet the requirement to protect credentials and configuration data in transit. At Harbor, HTTPS management troubleshooting uses this evidence. The HTTP path at Harbor therefore misses the stated constraint. At Harbor, the HTTPS management state is observable afterward.

Answer C is incorrect because Telnet is an interactive terminal protocol and is also unencrypted, so it is not a secure replacement for a web-management interface. At Harbor, HTTPS management troubleshooting uses this evidence. The Telnet path at Harbor therefore misses the stated constraint. At Harbor, the HTTPS management state is observable afterward.

Answer A is incorrect because CDP is a neighbor discovery protocol and does not provide an administrative web interface. At Harbor, HTTPS management troubleshooting uses this evidence. The CDP path at Harbor therefore misses the stated constraint. At Harbor, the HTTPS management state is observable afterward.

 

Question 15

Juniper must distinguish network-device administration from user network access and wants per-command authorization records. Which AAA protocol is commonly selected for the device-admin use case? Choose ONE.

  1. TACACS+
  2. CAPWAP
  3. LLDP
  4. RADIUS only

Correct Answer: A

Correct Answer

 

 

Answer A is correct because TACACS+ is widely used for network-device administration and supports centralized authentication, authorization, and accounting with granular command-authorization capabilities. At Juniper, TACACS admin troubleshooting uses this evidence. The TACACS+ path at Juniper therefore meets the stated constraint. At Juniper, the TACACS admin state is observable afterward.

Incorrect Answers

 

Answer D is incorrect because RADIUS is strongly associated with network access such as 802.1X and VPN authentication; although it provides AAA, it is less commonly chosen when per-command device-administration control is the core requirement. At Juniper, TACACS admin troubleshooting uses this evidence. The RADIUS only path at Juniper therefore misses the stated constraint. At Juniper, the TACACS admin state is observable afterward.

Answer C is incorrect because LLDP advertises neighbor information and has no role in centralized administrator authentication or command accounting. At Juniper, TACACS admin troubleshooting uses this evidence. The LLDP path at Juniper therefore misses the stated constraint. At Juniper, the TACACS admin state is observable afterward.

Answer B is incorrect because CAPWAP manages AP-controller communication and does not provide administrator AAA for network-device CLI sessions. At Juniper, TACACS admin troubleshooting uses this evidence. The CAPWAP path at Juniper therefore misses the stated constraint. At Juniper, the TACACS admin state is observable afterward.

 

Question 16

Lumen’s WLAN authenticates enterprise users against an identity service. Which AAA protocol is typically used for this network-access authentication flow? Choose ONE.

  1. RADIUS
  2. TFTP
  3. LACP
  4. CDP

Correct Answer: A

Correct Answer

 

 

Answer A is correct because RADIUS is commonly used for centralized network-access AAA, including enterprise wireless and 802.1X authentication between access devices/controllers and identity services. At Lumen, RADIUS access troubleshooting uses this evidence. The RADIUS path at Lumen therefore meets the stated constraint. At Lumen, the RADIUS access state is observable afterward.

Incorrect Answers

 

Answer D is incorrect because CDP discovers adjacent Cisco devices and does not carry user network-access authentication transactions. At Lumen, RADIUS access troubleshooting uses this evidence. The CDP path at Lumen therefore misses the stated constraint. At Lumen, the RADIUS access state is observable afterward.

Answer C is incorrect because LACP negotiates link aggregation and has no AAA function. At Lumen, RADIUS access troubleshooting uses this evidence. The LACP path at Lumen therefore misses the stated constraint. At Lumen, the RADIUS access state is observable afterward.

Answer B is incorrect because TFTP transfers files without the network-access authentication and authorization functions required in this scenario. At Lumen, RADIUS access troubleshooting uses this evidence. The TFTP path at Lumen therefore misses the stated constraint. At Lumen, the RADIUS access state is observable afterward.

 

Question 17

Northstar’s branches no longer host an on-premises controller for day-to-day configuration; devices are orchestrated through a cloud service. Which management approach is being used? Choose ONE.

  1. CDP-based management
  2. Console-only management
  3. Cloud-managed networking
  4. Spanning-tree management

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Cloud-managed networking centralizes configuration and monitoring in a cloud-hosted management platform while distributed network devices connect to that service. At Northstar, cloud management troubleshooting uses this evidence. The Cloud-managed networking path at Northstar therefore meets the stated constraint. At Northstar, the cloud management state is observable afterward.

Incorrect Answers

 

Answer B is incorrect because Console access is local and device-specific; it cannot provide the centralized remote orchestration described across many branches. At Northstar, cloud management troubleshooting uses this evidence. The Console-only management path at Northstar therefore misses the stated constraint. At Northstar, the cloud management state is observable afterward.

Answer A is incorrect because CDP supplies local neighbor discovery information and is not a cloud management/control platform. At Northstar, cloud management troubleshooting uses this evidence. The CDP-based management path at Northstar therefore misses the stated constraint. At Northstar, the cloud management state is observable afterward.

Answer D is incorrect because Spanning tree controls Layer 2 loop-free topology and does not provide a centralized configuration service. At Northstar, cloud management troubleshooting uses this evidence. The Spanning-tree management path at Northstar therefore misses the stated constraint. At Northstar, the cloud management state is observable afterward.

 

Question 18

Pioneer confirms an engineer’s identity successfully, but the device then denies a privileged command based on the engineer’s assigned role. Which AAA phase made that decision? Choose ONE.

  1. Discovery
  2. Accounting
  3. Authorization
  4. Authentication

Correct Answer: C

Correct Answer

 

 

Answer C is correct because Authorization determines which services, commands, or privilege levels an authenticated identity is permitted to use. At Pioneer, AAA authorization troubleshooting uses this evidence. The Authorization path at Pioneer therefore meets the stated constraint. At Pioneer, the AAA authorization state is observable afterward.

Incorrect Answers

 

Answer D is incorrect because Authentication verifies who the user is; it precedes the permission decision but does not itself define the allowed command set. At Pioneer, AAA authorization troubleshooting uses this evidence. The Authentication path at Pioneer therefore misses the stated constraint. At Pioneer, the AAA authorization state is observable afterward.

Answer B is incorrect because Accounting records activity such as session or command events; it provides audit evidence rather than the permission decision. At Pioneer, AAA authorization troubleshooting uses this evidence. The Accounting path at Pioneer therefore misses the stated constraint. At Pioneer, the AAA authorization state is observable afterward.

Answer A is incorrect because Discovery is not one of the AAA functions and does not determine administrative privileges. At Pioneer, AAA authorization troubleshooting uses this evidence. The Discovery path at Pioneer therefore misses the stated constraint. At Pioneer, the AAA authorization state is observable afterward.

 

Question 19

Redwood already has centralized login and command authorization, but compliance also requires session and command records. Which AAA component should be enabled? Choose ONE.

  1. Authentication
  2. Accounting
  3. Authorization
  4. ARP inspection

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Accounting records AAA activity such as session starts/stops and, where supported, command events, providing the audit trail required by compliance. At Redwood, AAA accounting troubleshooting uses this evidence. The Accounting path at Redwood therefore meets the stated constraint. At Redwood, the AAA accounting state is observable afterward.

Incorrect Answers

 

Answer A is incorrect because Authentication proves identity but does not by itself create the detailed activity record requested. At Redwood, AAA accounting troubleshooting uses this evidence. The Authentication path at Redwood therefore misses the stated constraint. At Redwood, the AAA accounting state is observable afterward.

Answer C is incorrect because Authorization decides what the authenticated user may do, but the audit requirement is specifically about recording what occurred. At Redwood, AAA accounting troubleshooting uses this evidence. The Authorization path at Redwood therefore misses the stated constraint. At Redwood, the AAA accounting state is observable afterward.

Answer D is incorrect because Dynamic ARP inspection validates ARP messages at Layer 2 and is unrelated to administrative AAA logging. At Redwood, AAA accounting troubleshooting uses this evidence. The ARP inspection path at Redwood therefore misses the stated constraint. At Redwood, the AAA accounting state is observable afterward.

 

Question 20

Tundra can reach a switch only through the console server after its management VLAN fails. Why does console access still work while SSH does not? Choose ONE.

  1. Console access does not require the device’s IP management path; SSH does
  2. Console is always encrypted across the production LAN; SSH is not
  3. SSH works without an IP address but console requires DNS
  4. Both methods require the wireless controller

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Console management reaches the device through a local/terminal-server serial path and does not depend on the device’s IP management interface, whereas SSH requires IP connectivity. At Tundra, console versus SSH troubleshooting uses this evidence. The Console access path at Tundra therefore meets the stated constraint. At Tundra, the console versus SSH state is observable afterward.

Incorrect Answers

 

Answer C is incorrect because SSH is an IP protocol and cannot operate to a device with no reachable IP path; DNS is optional name resolution rather than a requirement for local console access. At Tundra, console versus SSH troubleshooting uses this evidence. The SSH works path at Tundra therefore misses the stated constraint. At Tundra, the console versus SSH state is observable afterward.

Answer B is incorrect because Console traffic is not inherently a production-LAN encrypted session, while SSH is specifically designed to encrypt remote terminal communication. At Tundra, console versus SSH troubleshooting uses this evidence. The Console is path at Tundra therefore misses the stated constraint. At Tundra, the console versus SSH state is observable afterward.

Answer D is incorrect because Neither ordinary console access nor SSH requires a wireless LAN controller to manage a router or switch. At Tundra, console versus SSH troubleshooting uses this evidence. The Both methods path at Tundra therefore misses the stated constraint. At Tundra, the console versus SSH state is observable afterward.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!