CCNA Switching and Network Access Practice Question
Exhibit
Laptop status: Associated to CorpWiFi, signal strong AP dashboard: client joined successfully Client shows APIPA address 169.254.22.14
Exhibit: A wireless client can see the SSID and associates successfully, but it never gets network access. Other users on the same SSID work. Which issue is the best fit?
⚠ Common exam trap
Don't confuse association issues with post-association network access problems. Ensure you understand the difference between connecting to the SSID and obtaining network access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The client failed to obtain a valid IP address from DHCP
Successful association means the radio connection is up. If only one client fails to get network access while others work, the most likely issue is a client-specific addressing problem such as not obtaining a valid DHCP lease. Option A is incorrect because channel width affects all clients, not just one. Option C is incorrect because hiding the SSID does not affect network access after association. Option D is incorrect because WPA2 does not block clients due to NTP; NTP is unrelated to client authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The AP is advertising the wrong channel width
Why it's wrong here
Advertising a wrong channel width, such as using 40 MHz in a congested 2.4 GHz band, degrades throughput and increases co-channel interference, but it does not prevent the client from completing DHCP. The client would still associate and receive an IP address; it would simply experience slower speeds or intermittent RF issues, not a total lack of network access.
When this WOULD be correct
In a different scenario where a question involves a client unable to connect to an AP due to interference or performance issues caused by an incorrect channel width setting, this option could be correct. For example, if multiple clients are experiencing poor performance or disconnections due to a misconfigured channel width, this would be a valid answer.
- ✓
The client failed to obtain a valid IP address from DHCP
Why this is correct
The client successfully completes Layer 2 association and authentication, but without a valid DHCP lease it has no IP address, subnet mask, default gateway, or DNS servers. This leaves the client appearing connected to the Wi-Fi network yet unable to reach any external resources, which is the classic symptom of DHCP failure after association.
- ✗
The SSID must be changed from broadcast to hidden
Why it's wrong here
Hiding the SSID by disabling beacon broadcasts only prevents the network name from appearing in passive scans; clients must manually type the SSID to associate. This does not influence DHCP operation, as the client can still associate and request an IP address even with a hidden SSID. The root issue is at Layer 3 addressing, not Layer 2 visibility.
When this WOULD be correct
In a different scenario, if a question describes a situation where a client cannot see the SSID at all, and the network administrator wants to restrict visibility for security reasons, then changing the SSID from broadcast to hidden would be the correct answer.
- ✗
WPA2 automatically blocks clients until NTP is configured
Why it's wrong here
WPA2 is a Layer 2 security mechanism that performs authentication and encryption via a four-way handshake; it has no dependency on NTP for PSK or Enterprise modes. Incorrect NTP settings on the AP might affect certificate validation in some EAP methods, but they do not block a client from obtaining a DHCP address after successful association.
When this WOULD be correct
In a different question, if a client is unable to connect to a network due to time synchronization issues that affect the WPA2 authentication process, then this option could be correct. For instance, if the question specifies that clients are being denied access due to mismatched timestamps, this would validate the answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓The client failed to obtain a valid IP address from DHCPCorrect answer▾
Why this is correct
The client successfully completes Layer 2 association and authentication, but without a valid DHCP lease it has no IP address, subnet mask, default gateway, or DNS servers. This leaves the client appearing connected to the Wi-Fi network yet unable to reach any external resources, which is the classic symptom of DHCP failure after association.
✗The AP is advertising the wrong channel widthWrong answer — click to see why▾
Why this is wrong here
The AP advertising the wrong channel width would affect RF performance and potentially cause connectivity issues for all clients, not just one specific client. Since other users on the same SSID work, this is not the issue.
★ When this WOULD be the correct answer
In a different scenario where a question involves a client unable to connect to an AP due to interference or performance issues caused by an incorrect channel width setting, this option could be correct. For example, if multiple clients are experiencing poor performance or disconnections due to a misconfigured channel width, this would be a valid answer.
Why candidates choose this
Channel width misconfiguration is a common wireless issue, but it typically impacts multiple clients or overall throughput, not a single client's ability to get network access after association.
✗The SSID must be changed from broadcast to hiddenWrong answer — click to see why▾
Why this is wrong here
Changing the SSID from broadcast to hidden would prevent clients from seeing the SSID in scan results, but the client in this scenario already sees and associates successfully. Hiding the SSID does not address the lack of network access after association.
★ When this WOULD be the correct answer
In a different scenario, if a question describes a situation where a client cannot see the SSID at all, and the network administrator wants to restrict visibility for security reasons, then changing the SSID from broadcast to hidden would be the correct answer.
Why candidates choose this
Students may confuse SSID hiding with a security measure that could affect client connectivity, but it only affects visibility, not post-association network access.
✗WPA2 automatically blocks clients until NTP is configuredWrong answer — click to see why▾
Why this is wrong here
WPA2 does not have any mechanism that blocks clients based on NTP configuration. NTP is used for time synchronization and is unrelated to client authentication or DHCP processes.
★ When this WOULD be the correct answer
In a different question, if a client is unable to connect to a network due to time synchronization issues that affect the WPA2 authentication process, then this option could be correct. For instance, if the question specifies that clients are being denied access due to mismatched timestamps, this would validate the answer.
Why candidates choose this
Some students might think that time synchronization is required for authentication protocols like 802.1X, but WPA2-PSK does not require NTP, and even with 802.1X, NTP issues would not cause a client to associate but fail to get an IP address.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Root Guard, Loop Guard, and BPDU Guard in Rapid PVST+
Key term
DHCP
Dynamic Host Configuration Protocol (DHCP) automatically assigns IP addresses and network settings to devices on a network, so they can communicate without manual configuration.
Key term
Network Time Protocol
Network Time Protocol (NTP) is a networking protocol that synchronizes the clocks of computers and devices over a network to a common reference time source, typically Coordinated Universal Time (UTC).
About these practice questions
One of 1,389 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.