Courseiva
Network Infrastructure and ConnectivityhardMultiple ChoiceObjective-mapped

CCNA Network Infrastructure and Connectivity Practice Question

A network administrator has recently upgraded the corporate wireless LAN to support 802.11ax (Wi-Fi 6) and is using WPA3-Enterprise with a central WLC. Several users with new 802.11ax laptops report that they can connect to the SSID, but after a few minutes their connections drop and then re-establish, while legacy 802.11ac clients work without issues. Which action will resolve this problem?

⚠ Common exam trap

Cisco often tests the misconception that Wi-Fi 6 issues are caused by physical layer features like OFDMA or channel width, when the actual problem is a mandatory security configuration mismatch (PMF) between WPA3 and the WLC.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Protected Management Frames (PMF) as Required on the WLAN.

WPA3-Enterprise requires Protected Management Frames (PMF) to be set to 'Required' on the WLC. When PMF is not enabled or set to 'Optional', 802.11ax clients using WPA3 may experience intermittent disconnects because management frame protection is mandatory for WPA3 operation. Legacy 802.11ac clients using WPA2 do not require PMF, so they remain unaffected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Downgrade the WLAN security to WPA2-Enterprise for backward compatibility.

    Why it's wrong here

    Downgrading to WPA2-Enterprise does not resolve the underlying PMF misconfiguration; while WPA2 allows optional PMF, WPA3 and 802.11ax mandate PMF as a hard requirement. The reported drops stem from management frame protection negotiation failing during association, not from WPA3 protocol incompatibility. Moreover, WPA2-Enterprise omits SAE and weakens the security posture, making it an inappropriate workaround that masks rather than fixes the root cause.

  • Enable Protected Management Frames (PMF) as Required on the WLAN.

    Why this is correct

    Setting Protected Management Frames (PMF) to Required enforces 802.11w on the WLAN, ensuring all management frames are encrypted and integrity-protected. WPA3 and 802.11ax clients expect PMF mandatory during robust security network association (RSNA); if the AP advertises PMF as not required or disabled, clients may disassociate immediately after authentication. Requiring PMF eliminates negotiation mismatches and prevents unprotected robust management frames from triggering disconnections.

  • Disable OFDMA and MU-MIMO on the WLC for the affected APs.

    Why it's wrong here

    OFDMA and MU-MIMO are channel-access and spatial multiplexing techniques that boost throughput in dense 802.11ax environments; they have no role in authentication, key management, or management frame protection. Disabling these features would not alter PMF negotiation or change how the WLAN advertises its security capabilities. The reported disconnections occur at the protocol level immediately after connecting, not from PHY-layer contention or scheduling, so this action is irrelevant.

  • Adjust the 5 GHz channel width from 80 MHz to 40 MHz to avoid interference.

    Why it's wrong here

    Reducing the 5 GHz channel width from 80 MHz to 40 MHz narrows the occupied spectrum and can improve SNR by avoiding overlapping channels, but it does not influence the management frame exchange or PMF capability negotiation that is failing. The symptom pattern—clients dropping right after association rather than suffering persistent throughput loss or RSSI fluctuation—points to a logical security parameter mismatch, not RF interference. Without changing the PMF policy, clients will still be disconnected regardless of channel geometry.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Enable Protected Management Frames (PMF) as Required on the WLAN.Correct answer

Why this is correct

Setting Protected Management Frames (PMF) to Required enforces 802.11w on the WLAN, ensuring all management frames are encrypted and integrity-protected. WPA3 and 802.11ax clients expect PMF mandatory during robust security network association (RSNA); if the AP advertises PMF as not required or disabled, clients may disassociate immediately after authentication. Requiring PMF eliminates negotiation mismatches and prevents unprotected robust management frames from triggering disconnections.

Downgrade the WLAN security to WPA2-Enterprise for backward compatibility.Wrong answer — click to see why

Why this is wrong here

Downgrading to WPA2 is a common workaround when WPA3-related features aren't correctly configured, but it's not the correct solution for PMF-related disconnections.

Disable OFDMA and MU-MIMO on the WLC for the affected APs.Wrong answer — click to see why

Why this is wrong here

Disabling Wi-Fi 6 features does not resolve authentication or management frame protection issues; this misconception stems from blaming new features for instability.

Adjust the 5 GHz channel width from 80 MHz to 40 MHz to avoid interference.Wrong answer — click to see why

Why this is wrong here

Changing channel width addresses co-channel interference and throughput, not authentication or management frame protection issues.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 1,389 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.