Wireless questions on the CCNA cover 802.11 standards (ax/ac/n), WPA3, SSID/BSSID concepts, WLC architecture (FlexConnect, local switching), and client connectivity troubleshooting. These are mostly MCQ and multi-select.
Start Scenario PracticeAn organization uses ISE for wireless LAN authentication via 802.1X with PEAP-MSCHAPv2. Users authenticate against Active Directory. Recently, some users report that after changing their domain password, they cannot connect to the wireless network for about 30 minutes. What is the most likely cause?
Explanation: ISE caches user credentials for efficiency, including the password used during 802.1X authentication. When a user changes their domain password, ISE may still have the old password cached and will attempt to authenticate with it until the cache expires (typically up to 30 minutes). Option A is incorrect because DNS updates are not related to cached passwords; stale DNS records would affect all users, not just those with recent password changes. Option C is incorrect because wireless controllers do not cache passwords for 802.1X; they forward credentials to the RADIUS server (ISE). Option D is incorrect because the RADIUS server (ISE) is the one caching credentials, not the wireless controller.
A network engineer is configuring Cisco ISE for wireless 802.1X authentication. The company wants to use certificate-based authentication for all corporate devices. Which EAP method should be configured?
Explanation: EAP-TLS uses digital certificates for mutual authentication between the client and the server, providing strong security without requiring passwords.
A large enterprise with over 2,000 employees recently experienced a security breach. An attacker gained initial access through a phishing email and then moved laterally across the network to reach a critical database server. The network currently has a flat Layer 2 topology with all devices in a single large VLAN. The company wants to prevent lateral movement in the future while maintaining operational simplicity. They have a Cisco ISE deployment already but it is only used for wireless guest access. The security team is evaluating options. Option A: Deploy 802.1X with dynamic VLAN assignment across all wired ports. This would authenticate users and assign them to different VLANs based on identity. Option B: Implement micro-segmentation using Cisco TrustSec with Security Group Tags (SGTs) on the existing switches and enforce SGT-based policies on the firewalls. This would allow traffic control between groups regardless of IP. Option C: Install a next-generation firewall at the internet edge and enable IPS to block known attack signatures. Option D: Upgrade all access switches to support Private VLANs (PVLANs) and configure promiscuous ports for servers. Which solution BEST addresses the lateral movement problem while leveraging existing infrastructure?
Explanation: Cisco TrustSec with Security Group Tags (SGTs) enables micro-segmentation at Layer 2, allowing traffic control between user groups and servers based on identity rather than IP address. This directly prevents lateral movement by enforcing policies that restrict which endpoints can communicate, even within the same VLAN, and it leverages the existing Cisco ISE deployment for policy management without requiring major topology changes.
An organization wants to provide guest wireless access with a captive portal. Which Cisco ISE portal type should be used?
Explanation: (Self-Registered Guest Portal). This portal enables guests to self-register via a captive portal, creating their own credentials without needing a sponsor. Option A (Sponsored Guest Portal) requires an existing user to sponsor the guest. Option B (Central Web Authentication Portal) is typically used for BYOD or device onboarding, not guest self-registration. Option C (Hotspot Guest Portal) provides simple internet access without any registration or authentication.
A global company uses Cisco Umbrella to enforce security policies across roaming users. Recently, a user reported that they could not access a legitimate business application while connected to a guest Wi-Fi at an airport. The application is categorized as 'Productivity' in Umbrella. Other users outside the office can access it. What is the most likely reason?
Explanation: When the Umbrella roaming client fails to authenticate, the user's DNS requests fall back to the default policy, which may block categories like 'Productivity' that are allowed under the authenticated user's policy. This explains why the user cannot access the application while other users outside the office can, as they are likely authenticated and subject to a permissive policy.
+4 more scenario questions available
Practice all Wireless LAN and WLC ScenariosWireless questions on the CCNA cover 802.11 standards (ax/ac/n), WPA3, SSID/BSSID concepts, WLC architecture (FlexConnect, local switching), and client connectivity troubleshooting. These are mostly MCQ and multi-select. These appear throughout the 350-701 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-701. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-701 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full Wireless LAN and WLC Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →