Cisco CCNA 200-301 Wireless Security and WPA2 PSK WLANs Practice Test 2

 

Topic 19 Practice Test 2 covers Wireless Security and WPA2 PSK WLANs for Cisco Certified Network Associate 200-301 CCNA and maps to objectives 5.9–5.10. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps. Every option includes focused technical reasoning explaining both the networking concept and its fit to the scenario.

Question 1

A design review for a healthcare branch SSID focuses on this use case: recognizing a legacy wireless security mode that should not be selected when stronger modern security is available. Which option provides the required function? Choose ONE.

  1. WPA2 with AES/CCMP
  2. Protected Management Frames (PMF)
  3. WPA2/WPA3 Enterprise with 802.1X
  4. WPA with TKIP

Correct Answer: D

Correct Answer

 

 

Answer D is correct because WPA with TKIP is appropriate for a healthcare branch SSID. Its typical use is recognizing a legacy wireless security mode that should not be selected when stronger modern security is available. It represents the older WPA generation that commonly uses TKIP and provides weaker legacy protection. Both clues point to this option.

Incorrect Answers

 

Answer A is incorrect because WPA2 with AES/CCMP uses WPA2 protection with AES-based CCMP for confidentiality and integrity. That can be valid elsewhere, but a healthcare branch SSID needs to identify the older TKIP-associated WPA security generation. WPA with TKIP matches that objective.

Answer B is incorrect because Protected Management Frames (PMF) is intended for protecting wireless management exchanges in a WPA3 deployment from forged disconnect frames. The scenario at a healthcare branch SSID instead requires a mechanism to identify the older TKIP-associated WPA security generation. That is the role of WPA with TKIP.

Answer C is incorrect because For a healthcare branch SSID, WPA2/WPA3 Enterprise with 802.1X solves the wrong problem. It uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. The scenario needs to identify the older TKIP-associated WPA security generation, which points to WPA with TKIP.

 

Question 2

A design review for a construction-site office WLAN focuses on this use case: configuring a CCNA-scope WPA2 WLAN that requires modern encryption rather than TKIP. Which option best addresses this requirement? Choose ONE.

  1. WPA2 Personal using a pre-shared key (PSK)
  2. Create or edit the WLAN profile
  3. WPA2 with AES/CCMP
  4. WPA3-Personal with SAE

Correct Answer: C

Correct Answer

 

 

Answer C is correct because For a construction-site office WLAN, the requirement is to protect the WLAN with WPA2 using AES/CCMP. WPA2 with AES/CCMP provides that function. It matches the evidence. WPA/TKIP is the older design, while WPA3 adds newer authentication such as SAE.

Incorrect Answers

 

Answer D is incorrect because WPA3-Personal with SAE is intended for selecting the current personal-mode successor to WPA2-PSK when client support permits WPA3. The scenario at a construction-site office WLAN instead requires a mechanism to protect the WLAN with WPA2 using AES/CCMP. That is the role of WPA2 with AES/CCMP.

Answer A is incorrect because WPA2 Personal using a pre-shared key (PSK) authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. That can be valid elsewhere, but a construction-site office WLAN needs to protect the WLAN with WPA2 using AES/CCMP. WPA2 with AES/CCMP matches that objective.

Answer B is incorrect because Using Create or edit the WLAN profile, the design defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. For a construction-site office WLAN, the missing function is to protect the WLAN with WPA2 using AES/CCMP; WPA2 with AES/CCMP supplies it.

 

Question 3

A design review for a small legal-office wireless network focuses on this use case: selecting the current personal-mode successor to WPA2-PSK when client support permits WPA3. Which option provides the required function? Choose ONE.

  1. WPA2/WPA3 Enterprise with 802.1X
  2. Protected Management Frames (PMF)
  3. WPA3-Personal with SAE
  4. WPA2/AES Layer 2 security policy

Correct Answer: C

Correct Answer

 

 

Answer C is correct because In a small legal-office wireless network, WPA3-Personal with SAE is the closest technical fit. It uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. The observed requirement depends on that specific behavior.

Incorrect Answers

 

Answer B is incorrect because Using Protected Management Frames (PMF), the design protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. For a small legal-office wireless network, the missing function is to use modern personal WLAN authentication based on SAE; WPA3-Personal with SAE supplies it.

Answer A is incorrect because WPA2/WPA3 Enterprise with 802.1X uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. At a small legal-office wireless network, it does not provide the requirement to use modern personal WLAN authentication based on SAE. WPA3-Personal with SAE does.

Answer D is incorrect because Using WPA2/AES Layer 2 security policy, the design selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. For a small legal-office wireless network, the missing function is to use modern personal WLAN authentication based on SAE; WPA3-Personal with SAE supplies it.

 

Question 4

A design review for a customer-service WLAN focuses on this use case: protecting wireless management exchanges in a WPA3 deployment from forged disconnect frames. Which option best addresses this requirement? Choose ONE.

  1. Protected Management Frames (PMF)
  2. WPA2 Personal using a pre-shared key (PSK)
  3. Create or edit the WLAN profile
  4. Enter the pre-shared key in the WLAN security settings

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Protected Management Frames (PMF) fits a customer-service WLAN: it protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. That behavior matches the requirement to protect management frames from forged deauthentication or disassociation. Other choices perform different roles.

Incorrect Answers

 

Answer B is incorrect because This option uses WPA2 Personal using a pre-shared key (PSK) for building the objective-required WPA2 PSK WLAN for a small environment that intentionally uses one shared secret. At a customer-service WLAN, the required function belongs to Protected Management Frames (PMF). The mechanism does not match.

Answer C is incorrect because Create or edit the WLAN profile defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. That can be valid elsewhere, but a customer-service WLAN needs to protect management frames from forged deauthentication or disassociation. Protected Management Frames (PMF) matches that objective.

Answer D is incorrect because Enter the pre-shared key in the WLAN security settings configures the shared secret that WPA2 Personal clients must possess to authenticate. That can be valid elsewhere, but a customer-service WLAN needs to protect management frames from forged deauthentication or disassociation. Protected Management Frames (PMF) matches that objective.

 

Question 5

A design review for a university department SSID focuses on this use case: building the objective-required WPA2 PSK WLAN for a small environment that intentionally uses one shared secret. Which option provides the required function? Choose ONE.

  1. WPA2/WPA3 Enterprise with 802.1X
  2. WPA2/AES Layer 2 security policy
  3. Enable the WLAN after applying its configuration
  4. WPA2 Personal using a pre-shared key (PSK)

Correct Answer: D

Correct Answer

 

 

Answer D is correct because WPA2 Personal using a pre-shared key (PSK) is appropriate for a university department SSID. Its typical use is building the objective-required WPA2 PSK WLAN for a small environment that intentionally uses one shared secret. It authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. Both clues point to this option.

Incorrect Answers

 

Answer A is incorrect because WPA2/WPA3 Enterprise with 802.1X is intended for requiring unique user or device authentication and centrally controlled enterprise credentials. The scenario at a university department SSID instead requires a mechanism to authenticate a small WLAN with one shared passphrase. That is the role of WPA2 Personal using a pre-shared key (PSK).

Answer B is incorrect because WPA2/AES Layer 2 security policy selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. That can be valid elsewhere, but a university department SSID needs to authenticate a small WLAN with one shared passphrase. WPA2 Personal using a pre-shared key (PSK) matches that objective.

Answer C is incorrect because For a university department SSID, Enable the WLAN after applying its configuration solves the wrong problem. It allows the configured WLAN to begin servicing clients after its profile and security settings are complete. The scenario needs to authenticate a small WLAN with one shared passphrase, which points to WPA2 Personal using a pre-shared key (PSK).

 

Question 6

A design review for an engineering branch WLAN focuses on this use case: requiring unique user or device authentication and centrally controlled enterprise credentials. Which option best addresses this requirement? Choose ONE.

  1. Create or edit the WLAN profile
  2. WPA2/WPA3 Enterprise with 802.1X
  3. WPA2/WPA3 transition mode
  4. Enter the pre-shared key in the WLAN security settings

Correct Answer: B

Correct Answer

 

 

Answer B is correct because In an engineering branch WLAN, WPA2/WPA3 Enterprise with 802.1X is the closest technical fit. It uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. The observed requirement depends on that specific behavior.

Incorrect Answers

 

Answer A is incorrect because This option uses Create or edit the WLAN profile for starting a controller GUI workflow for a new SSID before selecting its Layer 2 security settings. At an engineering branch WLAN, the required function belongs to WPA2/WPA3 Enterprise with 802.1X. The mechanism does not match.

Answer D is incorrect because This option uses Enter the pre-shared key in the WLAN security settings for completing the WPA2-PSK credential portion of a controller GUI WLAN configuration. At an engineering branch WLAN, the required function belongs to WPA2/WPA3 Enterprise with 802.1X. The mechanism does not match.

Answer C is incorrect because For an engineering branch WLAN, WPA2/WPA3 transition mode solves the wrong problem. It allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. The scenario needs to use individual enterprise credentials backed by AAA, which points to WPA2/WPA3 Enterprise with 802.1X.

 

Question 7

A design review for a secure records-office SSID focuses on this use case: starting a controller GUI workflow for a new SSID before selecting its Layer 2 security settings. Which option provides the required function? Choose ONE.

  1. WPA with TKIP
  2. Create or edit the WLAN profile
  3. WPA2/AES Layer 2 security policy
  4. Enable the WLAN after applying its configuration

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Create or edit the WLAN profile is appropriate for a secure records-office SSID. Its typical use is starting a controller GUI workflow for a new SSID before selecting its Layer 2 security settings. It defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. Both clues point to this option.

Incorrect Answers

 

Answer C is incorrect because This option uses WPA2/AES Layer 2 security policy for ensuring the WLAN is actually protected by WPA2/AES rather than remaining open or using legacy TKIP. At a secure records-office SSID, the required function belongs to Create or edit the WLAN profile. The mechanism does not match.

Answer D is incorrect because Enable the WLAN after applying its configuration allows the configured WLAN to begin servicing clients after its profile and security settings are complete. At a secure records-office SSID, it does not provide the requirement to define the WLAN identity before adding security settings. Create or edit the WLAN profile does.

Answer A is incorrect because For a secure records-office SSID, WPA with TKIP solves the wrong problem. It represents the older WPA generation that commonly uses TKIP and provides weaker legacy protection. The scenario needs to define the WLAN identity before adding security settings, which points to Create or edit the WLAN profile.

 

Question 8

A design review for a regional retail WLAN focuses on this use case: ensuring the WLAN is actually protected by WPA2/AES rather than remaining open or using legacy TKIP. Which option best addresses this requirement? Choose ONE.

  1. WPA2/AES Layer 2 security policy
  2. Enter the pre-shared key in the WLAN security settings
  3. WPA2/WPA3 transition mode
  4. WPA2 with AES/CCMP

Correct Answer: A

Correct Answer

 

 

Answer A is correct because WPA2/AES Layer 2 security policy is appropriate for a regional retail WLAN. Its typical use is ensuring the WLAN is actually protected by WPA2/AES rather than remaining open or using legacy TKIP. It selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. Both clues point to this option.

Incorrect Answers

 

Answer B is incorrect because For a regional retail WLAN, Enter the pre-shared key in the WLAN security settings solves the wrong problem. It configures the shared secret that WPA2 Personal clients must possess to authenticate. The scenario needs to select WPA2 and AES as the Layer 2 security policy, which points to WPA2/AES Layer 2 security policy.

Answer C is incorrect because WPA2/WPA3 transition mode allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. At a regional retail WLAN, it does not provide the requirement to select WPA2 and AES as the Layer 2 security policy. WPA2/AES Layer 2 security policy does.

Answer D is incorrect because This option uses WPA2 with AES/CCMP for configuring a CCNA-scope WPA2 WLAN that requires modern encryption rather than TKIP. At a regional retail WLAN, the required function belongs to WPA2/AES Layer 2 security policy. The mechanism does not match.

 

Question 9

Engineers reviewing a branch PSK WLAN whose security policy and shared secret are not yet complete need two complementary capabilities: one that selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2, plus another that configures the shared secret that WPA2 Personal clients must possess to authenticate. Select the TWO options that provide those capabilities. Choose TWO.

  1. WPA2/WPA3 transition mode
  2. Enter the pre-shared key in the WLAN security settings
  3. WPA2/AES Layer 2 security policy
  4. Protected Management Frames (PMF)
  5. WPA2 with AES/CCMP

Correct Answers: B, C

Correct Answers

 

 

Answer C is correct because In a branch PSK WLAN whose security policy and shared secret are not yet complete, WPA2/AES Layer 2 security policy is the closest technical fit. It selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. The observed requirement depends on that specific behavior.

Answer B is correct because Enter the pre-shared key in the WLAN security settings is appropriate for a branch PSK WLAN whose security policy and shared secret are not yet complete. Its typical use is completing the WPA2-PSK credential portion of a controller GUI WLAN configuration. It configures the shared secret that WPA2 Personal clients must possess to authenticate. Both clues point to this option.

Incorrect Answers

 

Answer A is incorrect because WPA2/WPA3 transition mode allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. The pair required at a branch PSK WLAN whose security policy and shared secret are not yet complete is WPA2/AES Layer 2 security policy plus Enter the pre-shared key in the WLAN security settings. This option serves another role.

Answer E is incorrect because WPA2 with AES/CCMP is used for configuring a CCNA-scope WPA2 WLAN that requires modern encryption rather than TKIP. In a branch PSK WLAN whose security policy and shared secret are not yet complete, the required functions come from WPA2/AES Layer 2 security policy and Enter the pre-shared key in the WLAN security settings. It is not one of them.

Answer D is incorrect because Using Protected Management Frames (PMF), the design protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. A branch PSK WLAN whose security policy and shared secret are not yet complete instead needs both WPA2/AES Layer 2 security policy and Enter the pre-shared key in the WLAN security settings. This addresses a different mechanism.

 

Question 10

A design review for a corporate classroom SSID focuses on this use case: making a correctly configured but administratively disabled WLAN available for client association. Which option best addresses this requirement? Choose ONE.

  1. WPA2 with AES/CCMP
  2. Protected Management Frames (PMF)
  3. Enable the WLAN after applying its configuration
  4. WPA2/WPA3 transition mode

Correct Answer: C

Correct Answer

 

 

Answer C is correct because In a corporate classroom SSID, Enable the WLAN after applying its configuration is the closest technical fit. It allows the configured WLAN to begin servicing clients after its profile and security settings are complete. The observed requirement depends on that specific behavior.

Incorrect Answers

 

Answer D is incorrect because WPA2/WPA3 transition mode is intended for migrating a mixed client population without forcing every device to support WPA3 on the first day. The scenario at a corporate classroom SSID instead requires a mechanism to make the completed WLAN administratively available to clients. That is the role of Enable the WLAN after applying its configuration.

Answer A is incorrect because For a corporate classroom SSID, WPA2 with AES/CCMP solves the wrong problem. It uses WPA2 protection with AES-based CCMP for confidentiality and integrity. The scenario needs to make the completed WLAN administratively available to clients, which points to Enable the WLAN after applying its configuration.

Answer B is incorrect because Protected Management Frames (PMF) protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. That can be valid elsewhere, but a corporate classroom SSID needs to make the completed WLAN administratively available to clients. Enable the WLAN after applying its configuration matches that objective.

 

Question 11

A design review for an insurance office WLAN focuses on this use case: migrating a mixed client population without forcing every device to support WPA3 on the first day. Which option provides the required function? Choose ONE.

  1. WPA2 Personal using a pre-shared key (PSK)
  2. WPA2/WPA3 transition mode
  3. WPA with TKIP
  4. WPA3-Personal with SAE

Correct Answer: B

Correct Answer

 

 

Answer B is correct because In an insurance office WLAN, WPA2/WPA3 transition mode is the closest technical fit. It allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. The observed requirement depends on that specific behavior.

Incorrect Answers

 

Answer C is incorrect because WPA with TKIP is intended for recognizing a legacy wireless security mode that should not be selected when stronger modern security is available. The scenario at an insurance office WLAN instead requires a mechanism to support WPA2 and WPA3 clients during a staged migration. That is the role of WPA2/WPA3 transition mode.

Answer D is incorrect because WPA3-Personal with SAE uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. That can be valid elsewhere, but an insurance office WLAN needs to support WPA2 and WPA3 clients during a staged migration. WPA2/WPA3 transition mode matches that objective.

Answer A is incorrect because For an insurance office WLAN, WPA2 Personal using a pre-shared key (PSK) solves the wrong problem. It authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. The scenario needs to support WPA2 and WPA3 clients during a staged migration, which points to WPA2/WPA3 transition mode.

 

Question 12

The case involving a media studio SSID turns on a specific distinction: WPA/TKIP is the older design, while WPA3 adds newer authentication such as SAE. Which choice matches the evidence most directly? Choose ONE.

  1. Create or edit the WLAN profile
  2. WPA2 Personal using a pre-shared key (PSK)
  3. WPA3-Personal with SAE
  4. WPA2 with AES/CCMP

Correct Answer: D

Correct Answer

 

 

Answer D is correct because For a media studio SSID, the requirement is to protect the WLAN with WPA2 using AES/CCMP. WPA2 with AES/CCMP provides that function. It matches the evidence. WPA/TKIP is the older design, while WPA3 adds newer authentication such as SAE.

Incorrect Answers

 

Answer C is incorrect because WPA3-Personal with SAE is intended for selecting the current personal-mode successor to WPA2-PSK when client support permits WPA3. The scenario at a media studio SSID instead requires a mechanism to protect the WLAN with WPA2 using AES/CCMP. That is the role of WPA2 with AES/CCMP.

Answer B is incorrect because WPA2 Personal using a pre-shared key (PSK) authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. That can be valid elsewhere, but a media studio SSID needs to protect the WLAN with WPA2 using AES/CCMP. WPA2 with AES/CCMP matches that objective.

Answer A is incorrect because Using Create or edit the WLAN profile, the design defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. For a media studio SSID, the missing function is to protect the WLAN with WPA2 using AES/CCMP; WPA2 with AES/CCMP supplies it.

 

Question 13

The case involving a warehouse supervisor WLAN turns on a specific distinction: WPA2-PSK authenticates from the shared secret without using SAE. Which choice is the best operational match? Choose ONE.

  1. Protected Management Frames (PMF)
  2. WPA2/WPA3 Enterprise with 802.1X
  3. WPA2/AES Layer 2 security policy
  4. WPA3-Personal with SAE

Correct Answer: D

Correct Answer

 

 

Answer D is correct because In a warehouse supervisor WLAN, WPA3-Personal with SAE is the closest technical fit. It uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. The observed requirement depends on that specific behavior.

Incorrect Answers

 

Answer A is incorrect because Using Protected Management Frames (PMF), the design protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. For a warehouse supervisor WLAN, the missing function is to use modern personal WLAN authentication based on SAE; WPA3-Personal with SAE supplies it.

Answer B is incorrect because WPA2/WPA3 Enterprise with 802.1X uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. At a warehouse supervisor WLAN, it does not provide the requirement to use modern personal WLAN authentication based on SAE. WPA3-Personal with SAE does.

Answer C is incorrect because Using WPA2/AES Layer 2 security policy, the design selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. For a warehouse supervisor WLAN, the missing function is to use modern personal WLAN authentication based on SAE; WPA3-Personal with SAE supplies it.

 

Question 14

The case involving a finance training SSID turns on a specific distinction: 802.1X enterprise authentication instead relies on per-user/device credentials through AAA infrastructure. Which choice matches the evidence most directly? Choose ONE.

  1. WPA2/AES Layer 2 security policy
  2. Enable the WLAN after applying its configuration
  3. WPA2 Personal using a pre-shared key (PSK)
  4. WPA2/WPA3 Enterprise with 802.1X

Correct Answer: C

Correct Answer

 

 

Answer C is correct because In a finance training SSID, WPA2 Personal using a pre-shared key (PSK) is the closest technical fit. It authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. The observed requirement depends on that specific behavior.

Incorrect Answers

 

Answer D is incorrect because This option uses WPA2/WPA3 Enterprise with 802.1X for requiring unique user or device authentication and centrally controlled enterprise credentials. At a finance training SSID, the required function belongs to WPA2 Personal using a pre-shared key (PSK). The mechanism does not match.

Answer A is incorrect because WPA2/AES Layer 2 security policy selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. At a finance training SSID, it does not provide the requirement to authenticate a small WLAN with one shared passphrase. WPA2 Personal using a pre-shared key (PSK) does.

Answer B is incorrect because Using Enable the WLAN after applying its configuration, the design allows the configured WLAN to begin servicing clients after its profile and security settings are complete. For a finance training SSID, the missing function is to authenticate a small WLAN with one shared passphrase; WPA2 Personal using a pre-shared key (PSK) supplies it.

 

Question 15

The case involving a field support branch WLAN turns on a specific distinction: a PSK WLAN shares one secret and therefore does not provide individual enterprise identity. Which choice is the best operational match? Choose ONE.

  1. Enter the pre-shared key in the WLAN security settings
  2. Create or edit the WLAN profile
  3. WPA2/WPA3 Enterprise with 802.1X
  4. WPA2/WPA3 transition mode

Correct Answer: C

Correct Answer

 

 

Answer C is correct because WPA2/WPA3 Enterprise with 802.1X is appropriate for a field support branch WLAN. Its typical use is requiring unique user or device authentication and centrally controlled enterprise credentials. It uses enterprise authentication with a RADIUS/AAA-backed identity process instead of one shared passphrase. Both clues point to this option.

Incorrect Answers

 

Answer B is incorrect because Create or edit the WLAN profile is intended for starting a controller GUI workflow for a new SSID before selecting its Layer 2 security settings. The scenario at a field support branch WLAN instead requires a mechanism to use individual enterprise credentials backed by AAA. That is the role of WPA2/WPA3 Enterprise with 802.1X.

Answer A is incorrect because Enter the pre-shared key in the WLAN security settings is intended for completing the WPA2-PSK credential portion of a controller GUI WLAN configuration. The scenario at a field support branch WLAN instead requires a mechanism to use individual enterprise credentials backed by AAA. That is the role of WPA2/WPA3 Enterprise with 802.1X.

Answer D is incorrect because Using WPA2/WPA3 transition mode, the design allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. For a field support branch WLAN, the missing function is to use individual enterprise credentials backed by AAA; WPA2/WPA3 Enterprise with 802.1X supplies it.

 

Question 16

The case involving a medical admin SSID turns on a specific distinction: encryption of user data alone does not authenticate all protected management frames. Which choice matches the evidence most directly? Choose ONE.

  1. Protected Management Frames (PMF)
  2. WPA2 Personal using a pre-shared key (PSK)
  3. Create or edit the WLAN profile
  4. Enter the pre-shared key in the WLAN security settings

Correct Answer: A

Correct Answer

 

 

Answer A is correct because Protected Management Frames (PMF) fits a medical admin SSID: it protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. That behavior matches the requirement to protect management frames from forged deauthentication or disassociation. Other choices perform different roles.

Incorrect Answers

 

Answer B is incorrect because This option uses WPA2 Personal using a pre-shared key (PSK) for building the objective-required WPA2 PSK WLAN for a small environment that intentionally uses one shared secret. At a medical admin SSID, the required function belongs to Protected Management Frames (PMF). The mechanism does not match.

Answer C is incorrect because Create or edit the WLAN profile defines the logical WLAN, including profile name, WLAN ID, SSID, and security configuration on the controller. That can be valid elsewhere, but a medical admin SSID needs to protect management frames from forged deauthentication or disassociation. Protected Management Frames (PMF) matches that objective.

Answer D is incorrect because Enter the pre-shared key in the WLAN security settings configures the shared secret that WPA2 Personal clients must possess to authenticate. That can be valid elsewhere, but a medical admin SSID needs to protect management frames from forged deauthentication or disassociation. Protected Management Frames (PMF) matches that objective.

 

Question 17

The case involving a product-test lab WLAN turns on a specific distinction: entering a PSK without the matching WPA2/AES policy leaves the intended security mode incomplete. Which choice is the best operational match? Choose ONE.

  1. Enter the pre-shared key in the WLAN security settings
  2. WPA2/WPA3 transition mode
  3. WPA2 with AES/CCMP
  4. WPA2/AES Layer 2 security policy

Correct Answer: D

Correct Answer

 

 

Answer D is correct because In a product-test lab WLAN, WPA2/AES Layer 2 security policy is the closest technical fit. It selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. The observed requirement depends on that specific behavior.

Incorrect Answers

 

Answer A is incorrect because Using Enter the pre-shared key in the WLAN security settings, the design configures the shared secret that WPA2 Personal clients must possess to authenticate. For a product-test lab WLAN, the missing function is to select WPA2 and AES as the Layer 2 security policy; WPA2/AES Layer 2 security policy supplies it.

Answer B is incorrect because WPA2/WPA3 transition mode allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. That can be valid elsewhere, but a product-test lab WLAN needs to select WPA2 and AES as the Layer 2 security policy. WPA2/AES Layer 2 security policy matches that objective.

Answer C is incorrect because WPA2 with AES/CCMP is intended for configuring a CCNA-scope WPA2 WLAN that requires modern encryption rather than TKIP. The scenario at a product-test lab WLAN instead requires a mechanism to select WPA2 and AES as the Layer 2 security policy. That is the role of WPA2/AES Layer 2 security policy.

 

Question 18

Engineers reviewing a modern personal SSID that must use SAE and protect management frames need two complementary capabilities: one that uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing, plus another that protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. Select the TWO options that provide those capabilities. Choose TWO.

  1. Protected Management Frames (PMF)
  2. WPA3-Personal with SAE
  3. Enable the WLAN after applying its configuration
  4. WPA2/AES Layer 2 security policy
  5. WPA2/WPA3 Enterprise with 802.1X

Correct Answers: A, B

Correct Answers

 

 

Answer B is correct because WPA3-Personal with SAE is appropriate for a modern personal SSID that must use SAE and protect management frames. Its typical use is selecting the current personal-mode successor to WPA2-PSK when client support permits WPA3. It uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. Both clues point to this option.

Answer A is correct because In a modern personal SSID that must use SAE and protect management frames, Protected Management Frames (PMF) is the closest technical fit. It protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. The observed requirement depends on that specific behavior.

Incorrect Answers

 

Answer E is incorrect because WPA2/WPA3 Enterprise with 802.1X is used for requiring unique user or device authentication and centrally controlled enterprise credentials. In a modern personal SSID that must use SAE and protect management frames, the required functions come from WPA3-Personal with SAE and Protected Management Frames (PMF). It is not one of them.

Answer D is incorrect because Using WPA2/AES Layer 2 security policy, the design selects the WPA2 security policy and AES cipher used to protect the WLAN at Layer 2. A modern personal SSID that must use SAE and protect management frames instead needs both WPA3-Personal with SAE and Protected Management Frames (PMF). This addresses a different mechanism.

Answer C is incorrect because Enable the WLAN after applying its configuration does not satisfy the paired requirement at a modern personal SSID that must use SAE and protect management frames. It allows the configured WLAN to begin servicing clients after its profile and security settings are complete. The needed choices are WPA3-Personal with SAE and Protected Management Frames (PMF).

 

Question 19

The case involving a consulting branch SSID turns on a specific distinction: security parameters can be correct while an administratively disabled WLAN still advertises no usable service. Which choice is the best operational match? Choose ONE.

  1. Protected Management Frames (PMF)
  2. Enable the WLAN after applying its configuration
  3. WPA2/WPA3 transition mode
  4. WPA2 with AES/CCMP

Correct Answer: B

Correct Answer

 

 

Answer B is correct because Enable the WLAN after applying its configuration is appropriate for a consulting branch SSID. Its typical use is making a correctly configured but administratively disabled WLAN available for client association. It allows the configured WLAN to begin servicing clients after its profile and security settings are complete. Both clues point to this option.

Incorrect Answers

 

Answer C is incorrect because This option uses WPA2/WPA3 transition mode for migrating a mixed client population without forcing every device to support WPA3 on the first day. At a consulting branch SSID, the required function belongs to Enable the WLAN after applying its configuration. The mechanism does not match.

Answer D is incorrect because Using WPA2 with AES/CCMP, the design uses WPA2 protection with AES-based CCMP for confidentiality and integrity. For a consulting branch SSID, the missing function is to make the completed WLAN administratively available to clients; Enable the WLAN after applying its configuration supplies it.

Answer A is incorrect because Protected Management Frames (PMF) protects selected 802.11 management frames against spoofed deauthentication and disassociation attacks and is required with WPA3. At a consulting branch SSID, it does not provide the requirement to make the completed WLAN administratively available to clients. Enable the WLAN after applying its configuration does.

 

Question 20

The case involving a small campus office WLAN turns on a specific distinction: a WPA3-only WLAN can strand clients that have no SAE support. Which choice matches the evidence most directly? Choose ONE.

  1. WPA2/WPA3 transition mode
  2. WPA with TKIP
  3. WPA3-Personal with SAE
  4. WPA2 Personal using a pre-shared key (PSK)

Correct Answer: A

Correct Answer

 

 

Answer A is correct because WPA2/WPA3 transition mode is appropriate for a small campus office WLAN. Its typical use is migrating a mixed client population without forcing every device to support WPA3 on the first day. It allows compatible clients to use WPA3 while supporting older clients with WPA2 during a staged migration. Both clues point to this option.

Incorrect Answers

 

Answer B is incorrect because This option uses WPA with TKIP for recognizing a legacy wireless security mode that should not be selected when stronger modern security is available. At a small campus office WLAN, the required function belongs to WPA2/WPA3 transition mode. The mechanism does not match.

Answer C is incorrect because WPA3-Personal with SAE uses Simultaneous Authentication of Equals for password-based personal WLAN authentication and improves resistance to offline password guessing. At a small campus office WLAN, it does not provide the requirement to support WPA2 and WPA3 clients during a staged migration. WPA2/WPA3 transition mode does.

Answer D is incorrect because Using WPA2 Personal using a pre-shared key (PSK), the design authenticates WLAN clients with a shared passphrase rather than individual enterprise credentials. For a small campus office WLAN, the missing function is to support WPA2 and WPA3 clients during a staged migration; WPA2/WPA3 transition mode supplies it.

Leave a Reply

How It Works

img
Step 1. Choose Exam
on ExamLabs
Download IT Exams Questions & Answers
img
Step 2. Open Exam with
Avanset Exam Simulator
Press here to download VCE Exam Simulator that simulates real exam environment
img
Step 3. Study
& Pass
IT Exams Anywhere, Anytime!