Question 1,608 of 1,389
CCNA Switching and Network Access Practice Question
A host on a guest WLAN can browse the Internet but cannot reach internal corporate resources, while employees on another SSID can. Which statement best explains why that can be a correct design outcome?
⚠ Common exam trap
A frequent exam trap is to interpret guest WLAN isolation as a misconfiguration, rather than an intentional policy enforcement. Candidates may also incorrectly attribute the restriction to technical limitations like routing being inherently disabled or SSIDs triggering firewall rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Because guest and employee WLANs can intentionally have different trust levels and access policies.
Guest wireless networks are intentionally isolated from corporate resources through separate trust levels and access policies. Option B is incorrect because guest WLANs can use IP routing, but routing policies restrict which destinations are reachable. Option C is incorrect because inter-VLAN routing is not inherently disabled; it is a design choice to restrict routing between VLANs. Option D is incorrect because SSIDs themselves do not trigger firewall rules; it is the VLAN or group assignment that determines the applied policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Because guest and employee WLANs can intentionally have different trust levels and access policies.
Why this is correct
Guest and employee WLANs are intentionally configured with different trust levels and access policies. A guest WLAN is typically placed in a less-trusted network zone, with ACLs that permit only outbound internet traffic while blocking access to internal corporate resources. This design is a deliberate security choice, not a technical limitation, because the organization wants visitors to have basic connectivity without exposing sensitive assets.
- ✗
Because guest WLANs cannot use IP routing at all.
Why it's wrong here
This statement is incorrect because guest WLANs absolutely use IP routing to reach the internet. The guest traffic is forwarded by the access point or wireless controller to a router or firewall, which then routes it out through the WAN interface. The guest network simply has firewall policies or ACLs that restrict its destination, but the routing process itself is fully functional.
When this WOULD be correct
In a scenario where a question asks about the technical limitations of guest WLANs in a highly restricted network environment, stating that guest WLANs cannot use IP routing might be correct if the context specifies a configuration that disables routing for security reasons. This would clarify that routing is not permitted for guests.
- ✗
Because the guest WLAN is assigned to a different VLAN that uses a different IP subnet, and inter-VLAN routing is inherently disabled for security reasons.
Why it's wrong here
This option is wrong because inter-VLAN routing is not inherently disabled for security reasons; it is a standard function of Layer 3 switches and routers. Even if the guest WLAN is on a separate VLAN with a different IP subnet, inter-VLAN routing is still needed to reach the internet gateway unless the gateway is on the same subnet. Security is enforced through ACLs and firewall rules tied to the VLAN interface, not by globally disabling inter-VLAN routing.
When this WOULD be correct
In a different exam scenario where the question states that employees are using static IP addresses and predefined host files for name resolution, it could be correct to say that they do not need DHCP or DNS services.
- ✗
Because the guest WLAN uses a different SSID that automatically triggers firewall rules that only permit HTTP/HTTPS traffic.
Why it's wrong here
An SSID does not automatically trigger firewall rules; rather, the SSID is mapped to a specific VLAN or dynamic interface, and the security policies applied to that interface determine permitted traffic. These policies typically allow more than just HTTP/HTTPS, such as DNS and DHCP, so the statement oversimplifies how guest WLAN restrictions are implemented. The configuration is manual, not automatic, and depends on the network administrator's design.
When this WOULD be correct
In a question that asks about how different SSIDs can influence routing decisions in a complex network with multiple routing protocols, one could argue that SSIDs can impact BGP policy if the question specifies that SSIDs are tied to different routing policies in a multi-tenant environment.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓Because guest and employee WLANs can intentionally have different trust levels and access policies.Correct answer▾
Why this is correct
Guest and employee WLANs are intentionally configured with different trust levels and access policies. A guest WLAN is typically placed in a less-trusted network zone, with ACLs that permit only outbound internet traffic while blocking access to internal corporate resources. This design is a deliberate security choice, not a technical limitation, because the organization wants visitors to have basic connectivity without exposing sensitive assets.
✗Because guest WLANs cannot use IP routing at all.Wrong answer — click to see why▾
Why this is wrong here
This option is incorrect because guest WLANs can indeed use IP routing; the issue here is related to access policies rather than routing capabilities. Guest networks often restrict access to internal resources intentionally, which is not a limitation of IP routing.
★ When this WOULD be the correct answer
In a scenario where a question asks about the technical limitations of guest WLANs in a highly restricted network environment, stating that guest WLANs cannot use IP routing might be correct if the context specifies a configuration that disables routing for security reasons. This would clarify that routing is not permitted for guests.
Why candidates choose this
Candidates may find this option tempting due to a common misconception that guest networks are entirely isolated and incapable of routing, leading them to overlook the nuances of access policies and network design.
✗Because the guest WLAN is assigned to a different VLAN that uses a different IP subnet, and inter-VLAN routing is inherently disabled for security reasons.Wrong answer — click to see why▾
Why this is wrong here
Inter-VLAN routing is not inherently disabled; it is a configurable policy choice, not a fixed characteristic.
★ When this WOULD be the correct answer
In a different exam scenario where the question states that employees are using static IP addresses and predefined host files for name resolution, it could be correct to say that they do not need DHCP or DNS services.
Why candidates choose this
Candidates may choose this option due to a misunderstanding of network configurations, mistakenly believing that a lack of DHCP or DNS is a valid reason for employees to access internal resources without those services.
✗Because the guest WLAN uses a different SSID that automatically triggers firewall rules that only permit HTTP/HTTPS traffic.Wrong answer — click to see why▾
Why this is wrong here
SSIDs themselves do not trigger firewall rules; the mapping to a VLAN or user group determines the policy applied.
★ When this WOULD be the correct answer
In a question that asks about how different SSIDs can influence routing decisions in a complex network with multiple routing protocols, one could argue that SSIDs can impact BGP policy if the question specifies that SSIDs are tied to different routing policies in a multi-tenant environment.
Why candidates choose this
Candidates may be tempted by this option due to a misunderstanding of how networking protocols interact, confusing SSID configurations with routing policies, leading them to think that SSIDs could influence BGP settings.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: May 17, 2026
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.