Network Access

400 questions

Question 1Question

Which two statements accurately describe Rapid PVST+ port roles and operational port states? (Select two.)

Select all that apply

Show answer & explanation

Answer: An Alternate port maintains a backup path to the root bridge and remains in the Discarding state.; Rapid PVST+ reduces the legacy 802.1D Disabled, Blocking, and Listening states into a single Discarding state.

Answer

An Alternate port maintains a backup path to the root bridge and remains in the Discarding state, and Rapid PVST+ reduces the legacy 802.1D Disabled, Blocking, and Listening states into a single Discarding state.
Rapid PVST+ (802.1w) optimizes Spanning Tree by consolidating the 802.1D Disabled, Blocking, and Listening states into a single Discarding state. Under this model, an Alternate port provides a backup path to the root bridge and stays in the Discarding state during normal operation.

Step-by-Step Solution

1
Identify the port states supported by Rapid PVST+ (802.1w).
Rapid PVST+ consolidates legacy 802.1D port states (Disabled, Blocking, Listening) into a single Discarding state.
This reduces operational complexity and improves convergence time.
2
Analyze the function and state of an Alternate port role in Rapid PVST+.
An Alternate port offers an alternate path to the root bridge and remains discarded (not forwarding traffic) unless the primary root port loses connectivity.
Alternate ports provide rapid failover without needing to undergo standard convergence delays.

Key Concept

Rapid PVST+ Port Roles and Port States
Question 2Question

A network administrator is deploying a Cisco Lightweight Access Point (AP) connected to a Layer 2 switch port configured as an 802.1Q trunk. The AP is intended to exchange CAPWAP control messages with the Wireless LAN Controller (WLC) management interface over the native VLAN while carrying client traffic on tagged VLANs. Switch syslogs immediately report a 'Native VLAN mismatch' notification on the interface, and the AP fails to join the controller. Which condition explains why management access between the AP and the WLC is failing?

Show answer & explanation

Answer: Untagged CAPWAP discovery and management packets sent by the AP arrive on a mismatched native VLAN at the switch, placing management traffic into an unintended VLAN segment.

Answer

Untagged CAPWAP discovery and management packets sent by the AP arrive on a mismatched native VLAN at the switch, placing management traffic into an unintended VLAN segment.
Cisco Lightweight Access Points transmit their initial CAPWAP discovery and management control traffic as untagged frames by default. When connected to an 802.1Q trunk port, these untagged frames are mapped directly to the switch port's native VLAN. A native VLAN mismatch causes the switch to place the AP's management frames into an incorrect VLAN segment, preventing IP communication with the Wireless LAN Controller (WLC) management interface.

Step-by-Step Solution

1
Identify the transmission mode of AP management and CAPWAP control traffic on an 802.1Q trunk port.
By default, Cisco Lightweight Access Points transmit CAPWAP management packets as untagged frames.
The AP relies on the native VLAN of the connected switchport to process untagged management traffic.
2
Analyze the impact of a Native VLAN mismatch on untagged frames.
When a switch port's native VLAN does not match the configured subnet or opposing link expectation, untagged packets are forwarded onto the incorrect VLAN.
Layer 2 switches assign incoming untagged frames to the port's configured native VLAN.
3
Determine the effect on WLC management access and CAPWAP tunnel establishment.
Because the AP management frames enter the wrong VLAN/IP subnet, IP routing to the WLC management IP fails and the CAPWAP state machine cannot complete.
CAPWAP discovery and join requests require bidirectional IP connectivity between the AP management IP and the WLC management interface IP.

Key Concept

AP and WLC Management Access over 802.1Q Native VLANs
Question 3Question

Match each Cisco AP and Wireless LAN Controller (WLC) connection type to its corresponding switchport configuration requirement.

Click a left item, then click its matching right item

Items

Cisco AP operating in Local Mode
Cisco AP operating in FlexConnect Mode with local switching
Cisco WLC Management Interface physical connection
Cisco WLC Service Port physical connection

Matches

Show answer & explanation

Answer

Local Mode AP matches Access port assigned to the dedicated AP management VLAN; FlexConnect Mode AP matches 802.1Q trunk port carrying tagged VLANs for local client traffic and a native VLAN for AP management; WLC Management Interface matches 802.1Q trunk port carrying tagged traffic for dynamic interfaces and controller management; WLC Service Port matches Access port isolated for out-of-band controller administration without 802.1Q VLAN tagging.
Each connection type matches its mandatory physical switch port requirement based on whether the link supports single VLAN access, 802.1Q trunking, or isolated out-of-band management.

Step-by-Step Solution

1
Analyze AP traffic modes to determine switchport configuration requirements.
Local mode APs send all client traffic inside CAPWAP tunnels to the WLC, requiring only a single-VLAN access port. FlexConnect APs with local switching forward client frames locally, requiring an 802.1Q trunk port with a native VLAN for CAPWAP management.
Understanding AP deployment modes determines whether single-VLAN access or multi-VLAN trunking is required at the access layer switch.
2
Analyze WLC interface physical connection requirements.
The main WLC distribution system port connects to an 802.1Q trunk port to multiplex controller management and dynamic VLANs. The physical service port connects to an access port dedicated to out-of-band management.
Controller architecture separates in-band multi-VLAN trunking from out-of-band isolated access management.

Key Concept

Switchport Configuration for AP and WLC Management Access Connections
Question 4Question

Match each Cisco Access Point (AP) mode to its primary operational behavior.

Click a left item, then click its matching right item

Items

Local Mode
FlexConnect Mode
Sniffer Mode
Monitor Mode

Matches

Show answer & explanation

Answer

Local Mode matches default central CAPWAP switching to the WLC; FlexConnect Mode matches branch local traffic switching during normal operation or WAN outage; Sniffer Mode matches capturing over-the-air wireless frames for analysis; Monitor Mode matches functioning strictly as a security sensor without servicing client connections.
Each Cisco AP mode serves a specific operational purpose: Local mode centrally tunnels client data to the controller via CAPWAP, FlexConnect supports local switching for branch offices, Sniffer mode redirects raw 802.11 frames to a network analyzer, and Monitor mode acts purely as a non-client-serving security sensor.

Step-by-Step Solution

1
Identify the role of Local Mode.
Local Mode is the default operational state for Cisco lightweight APs where client data is tunneled back to the central WLC.
Lightweight AP architectures rely on centralized traffic control by default.
2
Identify the role of FlexConnect Mode.
FlexConnect Mode handles remote branch office deployments.
It allows local traffic switching at the access layer without sending all traffic over the WAN back to the central controller.
3
Identify the role of Sniffer Mode.
Sniffer Mode collects packet captures on a configured channel.
It acts as a remote wireless probe for troubleshooting and packet analysis.
4
Identify the role of Monitor Mode.
Monitor Mode performs continuous threat analysis and location services.
The radio refrains from serving client connections so it can constantly cycle through channels to detect rogues and intrusion attempts.

Key Concept

Cisco Wireless Access Point Modes and Operational Behaviors
Question 5Question

A network administrator is configuring out-of-band management access for a Cisco Wireless LAN Controller (WLC). The administrator connects the WLC Service Port to an isolated management network while connecting the WLC Management Interface to an 802.1Q trunk port on the distribution switch. Which operational characteristic uniquely applies to the Service Port on a Cisco WLC?

Show answer & explanation

Answer: It operates strictly out-of-band, supports only untagged traffic, and maintains a dedicated default gateway separate from the main controller routing table.

Answer

The Service Port operates strictly out-of-band, supports only untagged traffic, and maintains a dedicated default gateway separate from the main controller routing table.
The Cisco WLC Service Port provides dedicated out-of-band management capability. It is completely isolated from the controller's data plane, does not support 802.1Q VLAN tagging (untagged traffic only), and maintains its own independent default gateway settings separate from the controller's main routing table.

Step-by-Step Solution

1
Identify the primary role and architecture of the WLC Service Port.
The Service Port is a dedicated, physical, out-of-band management interface isolated from client and AP CAPWAP traffic.
Out-of-band management ports provide access for administrative GUI/CLI tasks even during main network or controller interface outages.
2
Evaluate framing and encapsulation requirements for the Service Port.
The Service Port only accepts untagged Ethernet frames (802.1Q tagging is not supported).
It connects to an access port on an isolated management network switch.
3
Analyze routing behavior for out-of-band traffic vs in-band traffic.
The Service Port uses a separate, independent default gateway configuration specifically defined for service port management traffic.
Traffic arriving on the Service Port must route back out through its own gateway rather than using the controller's main system routing table.

Key Concept

Cisco WLC Service Port vs Management Interface characteristics
Estimated Time:1m 30s
Question 6Question

Which Cisco Access Point (AP) mode operates by dedicating its radios to capturing wireless traffic and forwarding all raw 802.11 frames over a CAPWAP tunnel to a specified IP address for analysis by packet analyzer software such as Wireshark?

Show answer & explanation

Answer: Sniffer mode

Answer

Sniffer mode dedicatedly captures raw 802.11 frames on a specified channel and sends them via a CAPWAP tunnel to a designated workstation running network analysis software.
In Sniffer mode, the lightweight access point dedicates its radio to a specific channel, captures all 802.11 wireless traffic, and encapsulates those frames into CAPWAP packets sent to a destination server running a network protocol analyzer.

Step-by-Step Solution

1
Identify the AP mode configured specifically for remote packet capturing.
Sniffer mode allows an engineer to remotely capture wireless frames on a target channel without being physically present with a wireless packet capture card.
When an AP is placed in Sniffer mode, it stops serving clients and redirects all received radio traffic to a specified IP destination for decode and troubleshooting.

Key Concept

Cisco Lightweight AP Operational Modes
Estimated Time:45s
Question 7Question

A network administrator is deploying Cisco Lightweight Access Points (APs) operating in Local mode across an enterprise network. The APs must establish CAPWAP tunnels back to a central Wireless LAN Controller (WLC) whose Management interface resides on VLAN 10. The switch ports connected to the APs are configured as access ports assigned to VLAN 20, where an infrastructure DHCP server provides IP addressing along with DHCP Option 43. A junior engineer proposes reconfiguring all AP switch ports as 802.1Q trunk ports with PortFast enabled.

Which statement accurately evaluates this switchport configuration recommendation for Local mode AP access?

Show answer & explanation

Answer: Local mode APs transmit and receive management traffic as untagged frames, making access ports in the AP management VLAN standard; configuring 802.1Q trunks is unnecessary unless FlexConnect mode with local VLAN mapping is used.

Answer

Local mode APs transmit and receive management traffic as untagged frames, making access ports in the AP management VLAN standard; configuring 802.1Q trunks is unnecessary unless FlexConnect mode with local VLAN mapping is used.
In Cisco centralized wireless architecture, an AP in Local mode tunnels all wireless client traffic to the Wireless LAN Controller using CAPWAP. The AP itself only needs a single IP address on an untagged access port (or untagged native VLAN) within its management VLAN to establish communication with the WLC. Configuring an 802.1Q trunk on the AP switch port is unnecessary for Local mode APs and is primarily used when deploying APs in FlexConnect mode with local VLAN switching.

Step-by-Step Solution

1
Analyze the operational mode of the Cisco Lightweight Access Point.
The AP operates in Local mode, which means all user traffic is encapsulated within CAPWAP data tunnels and sent directly to the Wireless LAN Controller (WLC).
Local mode APs do not switch wireless client traffic locally onto the switch.
2
Determine the interface and VLAN requirement for the AP switch connection.
The AP only requires a single Layer 3 IP address to establish a CAPWAP control and data tunnel to the WLC Management interface.
Because all wireless SSID traffic is tunneled to the WLC, multiple VLAN tags do not pass over the physical switch link connected to a Local mode AP.
3
Evaluate the necessity of 802.1Q trunking vs access ports.
An access port assigned to the AP management VLAN (VLAN 20) is sufficient and recommended. 802.1Q trunks are typically only required when APs are operating in FlexConnect mode with local traffic switching across multiple VLANs.
Configuring trunks for Local mode APs adds unnecessary complexity and potential misconfigurations.

Key Concept

Lightweight AP and WLC Management Interconnects (Local vs FlexConnect AP Modes)
Question 8Question

A network engineer needs to configure a static IEEE 802.1Q trunk link on Cisco switch interface GigabitEthernet0/1, disable Dynamic Trunking Protocol (DTP) negotiation, and configure VLAN 99 as the untagged native VLAN. Place the following CLI configuration commands in the correct logical execution sequence from first to last.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct execution order is: interface GigabitEthernet0/1, switchport trunk encapsulation dot1q, switchport mode trunk, switchport nonegotiate, and switchport trunk native vlan 99.
The CLI commands follow strict Cisco IOS configuration order dependencies. First, access the interface mode with 'interface GigabitEthernet0/1'. Second, set encapsulation using 'switchport trunk encapsulation dot1q'. Third, enable static trunking with 'switchport mode trunk'. Fourth, disable DTP frames using 'switchport nonegotiate' (which fails if the port is in dynamic DTP mode). Finally, assign untagged traffic processing using 'switchport trunk native vlan 99'.

Step-by-Step Solution

1
Enter interface configuration mode
Context changes to Switch(config-if)# for GigabitEthernet0/1
CLI commands affecting a specific port require entering that interface context first.
2
Set trunk encapsulation to IEEE 802.1Q
Interface protocol encapsulation set to dot1q
Cisco IOS platforms supporting both ISL and 802.1Q require explicit encapsulation specification before changing mode to trunk.
3
Configure operational mode to static trunk
Interface changes state to unconditional trunking mode
Establishes trunk operational state.
4
Disable Dynamic Trunking Protocol negotiation
DTP frame transmission is stopped on the interface
The 'switchport nonegotiate' command is rejected by Cisco IOS if the interface remains in dynamic auto or dynamic desirable mode.
5
Modify the native VLAN identifier
VLAN 99 becomes the untagged VLAN for IEEE 802.1Q traffic
Applies non-default native VLAN parameter to prevent native VLAN mismatch security issues.

Key Concept

IEEE 802.1Q Trunk Configuration and DTP Suppression Sequence
Estimated Time:1m 30s
Question 9Question

A network administrator configures Cisco STP PortFast globally on an access switch (`spanning-tree portfast default`) to streamline host initialization. To evaluate the impact of this command on switch behavior and topology stability, which TWO statements accurately describe the operational characteristics and benefits of enabling PortFast on an access switch interface?

Select all that apply

Show answer & explanation

Answer: The interface transitions immediately from the Blocking state to the Forwarding state upon link up, completely bypassing the Listening and Learning states.; Link status transitions on the PortFast-enabled port do not generate Topology Change Notifications (TCNs) across the Spanning Tree domain.

Answer

PortFast enables immediate transition from Blocking to Forwarding by skipping Listening and Learning states, and it prevents link flaps on edge ports from generating Topology Change Notifications (TCNs).
Enabling PortFast allows access ports connected to end devices to bypass the classic 802.1D Listening and Learning states (saving 30 seconds of convergence delay) and move straight to Forwarding. Furthermore, PortFast suppresses Topology Change Notification (TCN) generation when the port flaps, preventing unnecessary MAC address table flushing across the switch network.

Step-by-Step Solution

1
Analyze the state transition mechanics of Cisco STP PortFast.
Standard 802.1D STP transitions through Blocking (20s max age) -> Listening (15s forward delay) -> Learning (15s forward delay) -> Forwarding (30-50s total). PortFast bypasses Listening and Learning, bringing the port directly from Blocking to Forwarding instantly upon link establishment.
This direct transition prevents DHCP request timeouts and initial bootup delays for end-user workstations.
2
Evaluate the topology change control mechanisms introduced by PortFast.
Normal STP interfaces generate TCN BPDUs whenever link status changes, instructing the Root Bridge to broadcast a topology change flag that shortens MAC address table aging timers to the forward delay period (15s). PortFast suppresses TCN generation for edge ports.
Preventing TCNs on workstation ports avoids unnecessary MAC table flooding and performance degradation across the entire Spanning Tree domain when end devices power on or off.
3
Verify BPDU processing behavior on PortFast interfaces.
PortFast ports still originate outbound BPDUs and continue to evaluate incoming BPDUs. Receiving a BPDU causes PortFast to be revoked operational status so normal loop prevention mechanics can take over.
PortFast alone does not filter or block BPDUs in either direction.

Key Concept

STP PortFast operational mechanics: Immediate Forwarding state bypass and TCN suppression.
Question 10Question

A network engineer needs to manually configure VLAN 30 named Engineering on a Cisco Catalyst switch and assign interface GigabitEthernet0/1 as an explicit static access port belonging to VLAN 30. Place the Cisco IOS CLI configuration steps in the correct chronological order required to accomplish this configuration starting from Privileged EXEC mode.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence begins with entering global configuration mode ('configure terminal'), creating and naming VLAN 30 ('vlan 30' and 'name Engineering'), navigating to interface configuration mode ('interface gigabitethernet0/1'), enforcing access mode ('switchport mode access'), and assigning the port to VLAN 30 ('switchport access vlan 30').
The CLI hierarchy in Cisco IOS demands starting in Privileged EXEC mode, moving to global configuration mode, defining the VLAN object and its name, entering the target interface configuration context, defining the port mode as access, and lastly binding the port to the intended VLAN ID.

Step-by-Step Solution

1
Execute 'configure terminal' at the Privileged EXEC prompt (Switch#).
Transitions the CLI prompt to global configuration mode (Switch(config)#).
CLI commands for creating VLANs and accessing interfaces require global configuration privileges.
2
Execute 'vlan 30', followed by 'name Engineering' and 'exit'.
Creates VLAN 30 in the VLAN database and assigns the alphanumeric label 'Engineering'.
Defining the VLAN explicitly in global configuration mode ensures proper Layer 2 broadcast domain setup and labeling.
3
Execute 'interface gigabitethernet0/1'.
Transitions the CLI prompt to interface configuration mode (Switch(config-if)#).
Interface parameters can only be altered when inside the specific interface configuration context.
4
Execute 'switchport mode access'.
Statically sets the port mode to access, disabling DTP trunk negotiation.
Best security and operational practices dictate explicit configuration of access ports rather than relying on dynamic negotiation defaults.
5
Execute 'switchport access vlan 30'.
Associates interface GigabitEthernet0/1 with VLAN 30 for untagged frame traffic.
Assigns the access interface to forward untagged traffic on VLAN 30.

Key Concept

Cisco IOS CLI Hierarchy for VLAN Creation and Static Access Port Configuration
Question 11Question

A network engineer deploys lightweight Cisco Access Points (APs) across multiple remote branch offices linked via a wide area network (WAN) to a centralized Wireless LAN Controller (WLC) in the main datacentre. During a unexpected WAN outage, wireless users at Branch 1 lose all network access to local site servers, whereas wireless users at Branch 2 continue accessing local network resources uninterrupted. Which configuration difference regarding AP modes and traffic handling accounts for this behavior during the WAN failure?

Show answer & explanation

Answer: Branch 2 deployed APs in FlexConnect mode with local switching configured for the WLAN, whereas Branch 1 deployed APs in standard Local mode, which relies on CAPWAP data tunnels to centralize all traffic at the WLC.

Answer

Branch 2 deployed APs in FlexConnect mode with local switching configured for the WLAN, whereas Branch 1 deployed APs in standard Local mode, which relies on CAPWAP data tunnels to centralize all traffic at the WLC.
In Cisco wireless architectures, standard Local mode APs encapsulate all user traffic inside CAPWAP data tunnels and route it back to the centralized Wireless LAN Controller (WLC) regardless of destination. If the WAN link connecting a remote branch to the central WLC drops, Local mode APs cannot process or forward client packets. Conversely, FlexConnect APs are designed for remote/branch deployments; when configured for local switching, client data frames are bridged directly onto the local wired network switch port at the branch. This allows local network connectivity to persist even during a WAN link or WLC failure.

Step-by-Step Solution

1
Analyze the operational requirements of AP modes during WAN link failure scenarios.
Identified that Local mode requires active CAPWAP control and data tunnels back to the central WLC for all traffic forwarding.
Standard Local mode APs depend entirely on the WLC to process and switch client data packets.
2
Evaluate the behavior of FlexConnect AP mode when WAN connectivity breaks.
FlexConnect mode allows APs to drop into standalone mode and switch client data packets locally to the access switch on configured local VLANs.
FlexConnect separates the control plane from the data plane, allowing local subnet resources to stay reachable locally when the central WLC is unreachable.
3
Determine why other listed modes (Monitor, Sniffer, Rogue Detector) do not apply.
Specialized AP modes (Monitor, Sniffer, Rogue Detector) do not broadcast SSIDs or handle client traffic.
Only client-serving modes like Local and FlexConnect support active client associations.

Key Concept

Cisco Lightweight AP Modes and FlexConnect Local vs Central Switching
Question 12Question

A network administrator needs to assign interface GigabitEthernet0/4 on a Cisco Catalyst switch to VLAN 25. Which Cisco IOS command must be executed in interface configuration mode to set the active VLAN assignment for this access port?

Show answer & explanation

Answer: switchport access vlan 25

Answer

The command switchport access vlan 25 correctly assigns an access port interface to VLAN 25 in Cisco IOS.
Executing switchport access vlan 25 in interface configuration mode directly sets the VLAN associated with an operational access port. If the specified VLAN does not already exist in the switch VLAN database, Cisco IOS automatically creates it upon executing this command.

Step-by-Step Solution

1
Enter interface configuration mode for the specified port (e.g., interface GigabitEthernet0/4).
The switch prompt changes to Switch(config-if)#.
Port-specific VLAN assignments must be applied within the interface configuration context.
2
Execute switchport access vlan 25.
The port is assigned to transmit untagged traffic for VLAN 25.
The switchport access vlan <vlan-id> command sets the broadcast domain/VLAN for an access interface.

Key Concept

VLAN Configuration and Access Port Setup
Question 13Question

A network administrator is evaluating Rapid PVST+ spanning-tree behavior across a multi-switch enterprise topology containing VLAN 10 and VLAN 20. Switch-A is configured with `spanning-tree vlan 10 priority 4096`, while Switch-B is configured with `spanning-tree vlan 20 priority 8192`. Switch-C connects to both Switch-A and Switch-B via 802.1Q trunk links with default Rapid PVST+ settings. Which two statements correctly describe the resulting Rapid PVST+ bridge operations, port roles, and configuration rules? (Select two choices.)

Select all that apply

Show answer & explanation

Answer: For VLAN 10, Switch-A advertises a total Bridge ID priority value of 4106 in its outbound BPDUs due to the addition of the 12-bit System ID Extension.; On Switch-C, an interface assigned the Alternate port role remains in the Discarding state while receiving superior BPDUs from a designated switch.

Answer

The correct statements are that Switch-A advertises a total priority value of 4106 for VLAN 10 due to the System ID Extension, and an Alternate port on Switch-C remains in the Discarding state while receiving superior BPDUs.
In Rapid PVST+, the Bridge ID priority calculation incorporates the 12-bit System ID Extension, resulting in an advertised priority of 4096+10=41064096 + 10 = 4106 for VLAN 10 on Switch-A. Additionally, an Alternate port provides a backup root path and resides in the Discarding state while continuing to process superior BPDUs from the designated bridge.

Step-by-Step Solution

1
Calculate the total Bridge ID priority advertised by Switch-A for VLAN 10.
Total Priority = Base Priority (4096) + System ID Extension (VLAN 10) = 4106.
Rapid PVST+ dynamically includes the VLAN ID inside the 12-bit System ID Extension field of the 16-bit Bridge Priority structure.
2
Verify Cisco IOS syntax rules for configuring STP bridge priority.
Configuring a value such as 4100 is rejected by Cisco IOS.
STP base priority values must be exact multiples of 4096 (0,4096,8192,,614400, 4096, 8192, \dots, 61440).
3
Determine the state and behavior of an Alternate port in Rapid PVST+.
The Alternate port is placed in the Discarding state.
An Alternate port offers an alternate path to the root bridge but remains blocked (Discarding state) as long as it receives superior BPDUs from another switch.
4
Evaluate the operational mechanics of PortFast on switch links.
PortFast transitions ports directly to Forwarding, not Learning, and does not disable BPDU traffic.
PortFast is intended exclusively for single-host end devices to skip STP listening/learning phases. Applying it to trunk links connecting switches threatens network stability.

Key Concept

Rapid PVST+ Bridge ID Structure, Port Roles, and Port States
Question 14Question

A network technician is configuring administration settings for a Cisco Wireless LAN Controller (WLC). Which two statements correctly describe the features and capabilities of the WLC Service Port and Management Interface? (Select two.)

Select all that apply

Show answer & explanation

Answer: The Service Port is dedicated to out-of-band management and traffic on this port is kept isolated from wireless client data network paths.; The Management Interface operates in-band to handle administrative SSH/HTTPS access as well as CAPWAP control communications with Access Points.

Answer

The Service Port provides dedicated out-of-band management isolated from client data paths, while the Management Interface handles in-band administration and CAPWAP tunnel traffic across routed networks.
The correct options accurately identify that the Service Port is used for isolated, out-of-band management access, whereas the Management Interface handles in-band administrative access (such as HTTPS and SSH) alongside CAPWAP control messaging across routed infrastructure.

Step-by-Step Solution

1
Identify the primary role and connectivity model of the WLC Service Port.
Recognize that the Service Port is a physical interface reserved for out-of-band management, initial setup, and emergency recovery, operating separately from client data.
Out-of-band interfaces isolate network management from general data plane congestion or failures.
2
Identify the primary function of the WLC Management Interface.
Recognize that the Management Interface is the default in-band interface used for CAPWAP management protocols between APs and WLC, as well as in-band Web/SSH administration.
In-band interfaces allow centralized administration and AP control traffic to traverse routed enterprise networks.

Key Concept

Distinction between out-of-band (Service Port) and in-band (Management Interface) management access connections on Cisco Wireless LAN Controllers.
Question 15Question

A network administrator deploys Cisco Lightweight Access Points (APs) in FlexConnect mode at a remote branch office. Which two statements correctly describe the characteristics of FlexConnect mode when connected to the Cisco Wireless LAN Controller (WLC)? (Select two.)

Select all that apply

Show answer & explanation

Answer: Wireless client data traffic can be switched locally on the branch access switch rather than tunneled back to the WLC.; Control plane traffic and central management functions are maintained over a CAPWAP tunnel with the central WLC.

Answer

FlexConnect mode allows wireless client data traffic to be switched locally on the local branch network while maintaining control plane management via a CAPWAP tunnel to the central Wireless LAN Controller.
FlexConnect mode provides remote branch offices with operational flexibility by enabling local switching of user data traffic directly onto the local LAN. At the same time, it relies on a CAPWAP control tunnel back to the central WLC for control plane tasks, configuration updates, and management oversight.

Step-by-Step Solution

1
Identify the primary purpose of FlexConnect mode in Cisco wireless architecture.
FlexConnect is designed for branch office deployments connected over WAN links to a centralized controller.
It optimizes WAN bandwidth by permitting local switching of user traffic at the branch.
2
Analyze how data traffic and control traffic are handled in FlexConnect mode.
User data traffic can be switched locally onto the branch switch, while control and management traffic travel over the CAPWAP tunnel to the WLC.
This split-MAC capability avoids sending branch-to-branch or branch-to-internet user traffic back to the central WLC.

Key Concept

Cisco FlexConnect AP Mode Operational Characteristics
Estimated Time:1m 0s
Question 16Question

An enterprise deploys Cisco lightweight Access Points (APs) configured in FlexConnect mode at a remote branch location connected via a WAN link to a centralized Wireless LAN Controller (WLC). The branch supports two SSIDs: an Enterprise WLAN configured for local switching with 802.1X (EAP) using FlexConnect Local Authentication, and a Guest WLAN configured for central switching and central authentication. If the WAN connection between the branch APs and the centralized WLC fails, causing the APs to transition to standalone mode, which statement correctly describes the resulting wireless client behavior?

Show answer & explanation

Answer: Clients on the Enterprise WLAN can successfully authenticate and maintain local data switching, while clients attempting to connect to the Guest WLAN are unable to authenticate or pass traffic.

Answer

Clients on the Enterprise WLAN can successfully authenticate and maintain local data switching, while clients attempting to connect to the Guest WLAN are unable to authenticate or pass traffic.
In Cisco wireless architectures, FlexConnect APs in standalone mode maintain functionality for WLANs configured for local switching and local authentication. Because the Enterprise WLAN uses local switching and FlexConnect Local Authentication, clients on this SSID can continue to authenticate and forward traffic directly onto the local branch network. Conversely, WLANs configured for central switching rely on the CAPWAP data tunnel to the WLC; when WAN connectivity to the controller is lost, centrally switched WLANs like the Guest WLAN become completely disabled.

Step-by-Step Solution

1
Analyze AP mode and controller connectivity state.
The lightweight APs are operating in FlexConnect mode and lose their CAPWAP connection to the centralized WLC, placing them in standalone mode.
FlexConnect APs are specifically designed for branch office deployments where WAN link loss to the WLC may occur.
2
Evaluate the behavior of the Enterprise WLAN.
Because the Enterprise WLAN is configured for local switching and FlexConnect Local Authentication, the AP handles 802.1X authentication and switches user traffic locally to the branch VLAN without requiring active WLC communication.
FlexConnect Local Authentication enables the AP or local RADIUS/FlexConnect Group to process authentication requests locally during WAN outages.
3
Evaluate the behavior of the Guest WLAN.
Because the Guest WLAN relies on central switching (CAPWAP data tunnel to WLC) and central authentication, it becomes completely non-functional when the CAPWAP tunnel is down.
Centrally switched traffic must traverse the CAPWAP data tunnel back to the WLC, which is impossible when WAN connectivity to the controller is disconnected.

Key Concept

Cisco FlexConnect AP Standalone Mode Operations and Local vs. Central Switching
Question 17Question

Place the steps of IEEE 802.1Q frame processing in sequential order, starting from when a host sends traffic on VLAN 20 until it is delivered to a host on another switch across an 802.1Q trunk link.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The sequence starts when the ingress switch receives an untagged frame from a host on a VLAN 20 access port, inserts a 4-byte 802.1Q tag into the frame header, transmits the tagged frame over the trunk link, the egress switch reads the VLAN ID from the tag, removes the 802.1Q header, and delivers the untagged frame out the access port to the destination host.
When a frame traverses an IEEE 802.1Q trunk link, the ingress switch inserts a 4-byte tag into the frame header to identify the originating VLAN (unless it is the native VLAN). The frame travels across the physical trunk link carrying this tag. Upon reaching the remote switch, the egress switch inspects the tag to determine the VLAN association, strips the 4-byte tag header, and delivers the original untagged Ethernet frame to the destination device connected to an access port in that VLAN.

Step-by-Step Solution

1
Receive untagged frame at ingress switch.
The ingress switch accepts the standard frame from the host on a port configured as an access port in VLAN 20.
Host end devices transmit standard untagged Ethernet frames.
2
Encapsulate frame with 802.1Q tag.
The switch inserts a 4-byte 802.1Q header between the Source MAC address and Length/Type fields.
IEEE 802.1Q tagging allows multiplexing multiple VLANs over a single interswitch trunk.
3
Send frame across trunk link.
The tagged frame is transmitted over the trunk interface toward the neighboring switch.
The tag remains intact during transmission across the trunk.
4
Process tag at egress switch.
The egress switch receives the frame and reads the 12-bit VLAN ID (VID) field in the 802.1Q header.
The receiving switch uses the VLAN ID to associate the frame with internal VLAN 20.
5
Decapsulate (strip) 802.1Q header.
The 4-byte 802.1Q tag is removed from the frame header.
End-user devices do not expect 802.1Q tags on access port connections.
6
Forward untagged frame to destination host.
The frame is sent out the matching VLAN 20 access port to the end device.
This completes the end-to-end Layer 2 delivery across switches.

Key Concept

IEEE 802.1Q Frame Encapsulation, Tagging, and Decapsulation Mechanics
Question 18Question

A network administrator is connecting two Cisco Catalyst switches via a multi-link bundle using Link Aggregation Control Protocol (LACP). Which two conditions or configuration settings are required for the EtherChannel bundle to form and operate correctly? (Select two.)

Select all that apply

Show answer & explanation

Answer: At least one of the switches must have its physical member interfaces configured in LACP active mode.; All physical member interfaces in the bundle must be configured with identical speed, duplex, and VLAN settings.

Answer

The EtherChannel bundle successfully forms when at least one side is configured in LACP active mode and all member interfaces share matching operational parameters such as speed, duplex, and VLAN configurations.
For an LACP EtherChannel to form, at least one endpoint must actively send LACP packets (active mode), allowing negotiation when paired with an active or passive remote interface. Additionally, all bundled physical interfaces must have identical speed, duplex, switchport mode, native VLAN, and allowed VLAN attributes.

Step-by-Step Solution

1
Analyze LACP negotiation modes
LACP modes must be compatible (active-active or active-passive). Matching passive-passive modes will fail to initiate negotiation.
Passive mode only responds to LACP packets received; if neither end initiates, no negotiation occurs.
2
Evaluate member interface attribute requirements
All member links must match speed, duplex, trunking status, allowed VLANs, and native VLAN.
EtherChannel treats bundled physical links as a single logical interface, requiring identical physical and Layer 2 properties.

Key Concept

LACP Mode Compatibility and Prerequisite Interface Matching for EtherChannel
Question 19Question

A network technician is configuring a new Wireless LAN on a Cisco Wireless LAN Controller (WLC) using the web interface. The technician has created the WLAN profile, assigned the SSID, and selected the interface mapping under the General tab. However, access points are not broadcasting the new network and wireless clients cannot connect. Which checkbox under the WLANs > Edit 'General' tab must be selected to make the WLAN active and operational?

Show answer & explanation

Answer: Status

Answer

The Status checkbox must be selected under the General tab to administratively enable the WLAN.
Newly created WLANs on a Cisco WLC are disabled by default. Under the General tab of the WLANs > Edit configuration page, checking the Status box (Enabled) is required to administratively activate the WLAN so that assigned Access Points can broadcast the SSID and process client association requests.

Step-by-Step Solution

1
Navigate to the WLANs menu in the Cisco WLC GUI and click on the newly created WLAN ID.
The WLANs > Edit configuration screen appears showing the General tab.
This menu contains basic identity and status controls for the specific WLAN.
2
Locate the Status field on the General tab page.
The Status checkbox is unchecked by default upon WLAN creation.
Cisco WLC creates WLANs in an administratively disabled state to prevent broadcasting incomplete network settings.
3
Check the Status box to set it to Enabled and click Apply.
The WLAN state changes to Enabled and Access Points begin broadcasting the SSID.
Enabling Status activates the WLAN operational state across all assigned APs.

Key Concept

WLAN Administrative Enablement via WLC GUI
Question 20Question

Which two statements accurately describe the operational characteristics of port roles and port states in Cisco Rapid PVST+ (802.1w)?

Select all that apply

Show answer & explanation

Answer: An Alternate port provides an alternate path toward the Root Bridge and remains in the Discarding state under normal operation.; Rapid PVST+ consolidates the legacy 802.1D Listening, Blocking, and Disabled states into a single Discarding state.

Answer

The statement that an Alternate port serves as a backup path in the Discarding state and the statement that Rapid PVST+ merges Listening, Blocking, and Disabled states into a single Discarding state are both correct.
Rapid PVST+ streamlines STP operation by using only three states: Discarding, Learning, and Forwarding. The Discarding state merges the old 802.1D Disabled, Blocking, and Listening states. An Alternate port is a designated backup path toward the Root Bridge that remains in the Discarding state while receiving BPDUs from other switches.

Step-by-Step Solution

1
Analyze Rapid PVST+ port states
Rapid PVST+ (802.1w) reduces port states to Discarding, Learning, and Forwarding.
Legacy 802.1D states of Disabled, Blocking, and Listening are combined into the Discarding state in 802.1w.
2
Analyze Rapid PVST+ port roles
An Alternate port is a backup path to the Root Bridge that stays in Discarding state until the primary Root Port fails.
Alternate ports receive superior BPDUs from neighboring switches but are blocked from forwarding frame traffic to maintain a loop-free topology.
3
Evaluate distractor regarding PortFast
PortFast is designed only for end-host (edge) access ports, not switch-to-switch trunks.
Configuring PortFast on trunks can lead to transient or persistent Layer 2 switching loops.
4
Evaluate distractor regarding bridge priority configuration
Bridge priority values must be assigned in multiples of 4096.
The 16-bit Bridge ID consists of a 4-bit priority field (increments of 4096) and a 12-bit System ID Extension carrying the VLAN ID.

Key Concept

Rapid PVST+ Port Roles, States, and Priority Configuration
Page 1 / 20Next