Courseiva
Switching and Network AccessmediumMultiple ChoiceObjective-mapped

CCNA Switching and Network Access Practice Question

Exhibit

WLAN Corp uses WPA2-Enterprise
WLAN Guest uses WPA2-PSK
AP joined to WLC successfully
Recent event: AAA server unreachable

Exhibit: Users report that they can see the corporate SSID but fail authentication immediately after entering credentials. Guest wireless works on the same access point. Which issue is most likely?

⚠ Common exam trap

Be careful not to confuse visibility and connectivity issues with authentication problems. The SSID is visible, so focus on authentication-related configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The RADIUS or AAA server is unreachable for the enterprise WLAN

When clients can see the SSID and associate at Layer 2 but fail right after entering credentials, a broken 802.1X or RADIUS path is a common cause. RF coverage is clearly not the main problem because the SSID is visible and guest service works.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The AP is using the wrong channel width

    Why it's wrong here

    Channel width controls how much spectrum an AP uses for data transmission; a mismatched width would cause poor throughput or coverage. However, it does not affect the authentication process, and clients can still associate with the SSID regardless of the channel width as long as the signal is present. The inability to authenticate on a visible SSID is an 802.1X/AAA failure, not an RF-level parameter issue.

    When this WOULD be correct

    In a scenario where users are experiencing poor performance or intermittent connectivity issues on a specific SSID, a question might ask about the impact of channel width on wireless communication. If the question specifies that users can connect but experience slow speeds, then this option could be correct.

  • The RADIUS or AAA server is unreachable for the enterprise WLAN

    Why this is correct

    WPA2-Enterprise requires the AP to forward EAP frames from the client to a RADIUS/AAA server for authentication. If that server is unreachable, clients can still discover the SSID and associate at Layer 2, but the 802.1X exchange times out because no Access-Request ever receives a response. The guest WLAN is unaffected because it does not depend on AAA, isolating the fault to the enterprise WLAN's backend.

  • The corporate SSID has a mismatched RADIUS shared secret

    Why it's wrong here

    A mismatched RADIUS shared secret would also break enterprise authentication, but it would not make the server unreachable; the AP would still see the server at the network layer, and authentication attempts would produce an Access-Reject or silently dropped packets instead of a timeout. Since the guest SSID is operational on the same AP, the AP has connectivity, and the more fundamental failure is the AAA server's availability. This answer is wrong because the problem is an outage, not a configuration inconsistency in the shared-secret credentials.

    When this WOULD be correct

    If the question were about a scenario where users are trying to connect to a guest network that requires a PSK, and they report that they can connect but are unable to authenticate, then the expiration of the guest PSK would be the correct answer.

  • The SSID must be configured as hidden

    Why it's wrong here

    If an SSID is configured as hidden, the AP stops including the SSID in its beacons, so it disappears from normal client scan results. But the corporate SSID is already visible to users, which means it is broadcasting normally; hiding it would only prevent discovery. This option is wrong because it addresses visibility, not the authentication process, and changing the SSID broadcast status would not solve an 802.1X/AAA unreachability issue.

    When this WOULD be correct

    In a different scenario where users are unable to see the corporate SSID at all, a question might ask about visibility issues related to SSID configuration. If the question specified that users could not connect because the SSID was hidden, then this option would be correct.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

The RADIUS or AAA server is unreachable for the enterprise WLANCorrect answer

Why this is correct

WPA2-Enterprise requires the AP to forward EAP frames from the client to a RADIUS/AAA server for authentication. If that server is unreachable, clients can still discover the SSID and associate at Layer 2, but the 802.1X exchange times out because no Access-Request ever receives a response. The guest WLAN is unaffected because it does not depend on AAA, isolating the fault to the enterprise WLAN's backend.

The AP is using the wrong channel widthWrong answer — click to see why

Why this is wrong here

The AP using the wrong channel width would not cause immediate authentication failures; it typically affects connectivity or performance rather than authentication processes. Since the guest wireless works, the channel width is likely not the issue.

★ When this WOULD be the correct answer

In a scenario where users are experiencing poor performance or intermittent connectivity issues on a specific SSID, a question might ask about the impact of channel width on wireless communication. If the question specifies that users can connect but experience slow speeds, then this option could be correct.

Why candidates choose this

Candidates may confuse channel width with overall wireless performance issues, leading them to believe that it could impact authentication. This misunderstanding can make the option seem plausible, especially if they are not fully aware of how authentication processes work.

The corporate SSID has a mismatched RADIUS shared secretWrong answer — click to see why

Why this is wrong here

A mismatched RADIUS shared secret would cause authentication failures, but guest wireless works on the same access point, indicating the AP itself is functional; the more likely cause is that the RADIUS server is completely unreachable, not just a shared secret mismatch.

★ When this WOULD be the correct answer

If the question were about a scenario where users are trying to connect to a guest network that requires a PSK, and they report that they can connect but are unable to authenticate, then the expiration of the guest PSK would be the correct answer.

Why candidates choose this

Candidates may choose this option because they recognize that authentication issues can arise from credential problems, and they might mistakenly associate the inability to authenticate with an expired PSK, especially if they have experience with guest networks.

The SSID must be configured as hiddenWrong answer — click to see why

Why this is wrong here

Configuring the SSID as hidden would not cause immediate authentication failures; users would simply not see the SSID unless they manually entered it. The issue described involves users seeing the SSID but failing authentication, indicating a problem beyond SSID visibility.

★ When this WOULD be the correct answer

In a different scenario where users are unable to see the corporate SSID at all, a question might ask about visibility issues related to SSID configuration. If the question specified that users could not connect because the SSID was hidden, then this option would be correct.

Why candidates choose this

Candidates might choose this option due to a misunderstanding of SSID visibility and authentication processes, thinking that if users can see the SSID, it must be configured correctly, and thus they might overlook other potential issues like authentication mechanisms.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,389 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.