Courseiva
Network Infrastructure and ConnectivityhardDrag & DropObjective-mapped

CCNA Network Infrastructure and Connectivity Practice Question

Drag and drop the following steps into the correct order to configure a WLAN for WPA3-Enterprise on a Cisco WLC and sequence a wireless client association process.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

⚠ Common exam trap

Do not confuse the order of 802.1X authentication and DHCP. In WPA3-Enterprise, the client must authenticate before obtaining an IP address. Also, remember that a WLAN must be created before it can be enabled, and it must be enabled before clients can associate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create WLAN with WPA3-Enterprise security, enable WLAN, client associates, 802.1X authentication, DHCP IP assignment

The configuration creates the WLAN with WPA3-Enterprise security, enables it, then the client associates and completes 802.1X authentication before getting an IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create WLAN with WPA3-Enterprise security, enable WLAN, client associates, 802.1X authentication, DHCP IP assignment

    Why this is correct

    On a Cisco WLC, the WLAN must be created and its security parameters (including WPA3-Enterprise) defined before the SSID can be enabled. Once enabled, the WLC broadcasts the SSID and accepts association requests, but the client port remains unauthorized until 802.1X/EAP authentication succeeds. Only after successful authentication does the WLC allow DHCP traffic, enabling the client to request an IP address. This order ensures that the client is authenticated and authorized before receiving any network resources.

  • Create WLAN with WPA3-Enterprise security, enable WLAN, client associates, DHCP IP assignment, 802.1X authentication

    Why it's wrong here

    This sequence incorrectly places DHCP IP assignment before 802.1X authentication. In an 802.1X-secured WLAN, the client's port is blocked by the WLC until the EAP exchange completes, so DHCP discovers and requests cannot reach the network. The client must first authenticate successfully to transition the port to the authorized state; only then can it obtain an IP address via DHCP. Therefore, swapping authentication and DHCP is fundamentally incorrect.

  • Enable WLAN, create WLAN with WPA3-Enterprise security, client associates, 802.1X authentication, DHCP IP assignment

    Why it's wrong here

    A Cisco WLC has no WLAN object to enable until the WLAN is created and configured; enabling a nonexistent WLAN is not a valid operation. The enable toggle is a separate administrative action that makes a previously created WLAN operational and starts broadcasting its SSID. Trying to enable first, before creating the WLAN, is impossible and would fail at the WLC interface. The correct sequence always begins with creating the WLAN, then enabling it, and only then can clients associate.

  • Create WLAN with WPA3-Enterprise security, client associates, enable WLAN, 802.1X authentication, DHCP IP assignment

    Why it's wrong here

    A WLAN that is not enabled is not advertised and cannot accept client associations, as the WLC does not process probes or association requests on a disabled SSID. The enable command must be issued before any client can discover and associate to the WLAN. This sequence shows a client associating while the WLAN is still disabled, which is not possible in operational practice. The WLAN must be enabled immediately after creation and before any client traffic is allowed.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Create WLAN with WPA3-Enterprise security, enable WLAN, client associates, 802.1X authentication, DHCP IP assignmentCorrect answer

Why this is correct

On a Cisco WLC, the WLAN must be created and its security parameters (including WPA3-Enterprise) defined before the SSID can be enabled. Once enabled, the WLC broadcasts the SSID and accepts association requests, but the client port remains unauthorized until 802.1X/EAP authentication succeeds. Only after successful authentication does the WLC allow DHCP traffic, enabling the client to request an IP address. This order ensures that the client is authenticated and authorized before receiving any network resources.

Create WLAN with WPA3-Enterprise security, enable WLAN, client associates, DHCP IP assignment, 802.1X authenticationWrong answer — click to see why

Why this is wrong here

The order of DHCP and 802.1X is reversed; 802.1X authentication must complete before DHCP.

Why candidates choose this

Candidates might think DHCP is needed for the client to communicate with the authentication server, but in 802.1X, the client uses EAP over wireless before getting an IP.

Enable WLAN, create WLAN with WPA3-Enterprise security, client associates, 802.1X authentication, DHCP IP assignmentWrong answer — click to see why

Why this is wrong here

The creation step must precede the enable step; enabling a non-existent WLAN is not possible.

Why candidates choose this

Candidates might think enabling is a separate step that can be done first, but the WLAN must exist in the configuration first.

Create WLAN with WPA3-Enterprise security, client associates, enable WLAN, 802.1X authentication, DHCP IP assignmentWrong answer — click to see why

Why this is wrong here

The enable step must occur before client association; a disabled WLAN does not broadcast or accept associations.

Why candidates choose this

Candidates might think client association can happen before enabling, but the WLAN must be active for clients to see and connect to it.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.