CCNA Switching and Network Access Practice Question
Which two statements accurately describe CAPWAP in a controller-based WLAN context?
⚠ Common exam trap
Be careful not to confuse encapsulation with encryption or assume CAPWAP is limited to a specific IP version.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It is associated with communication between lightweight APs and the wireless LAN controller.
CAPWAP (Control and Provisioning of Wireless Access Points) is the protocol used between lightweight access points (LAPs) and the wireless LAN controller (WLC) in controller-based WLAN architectures. Options C, D, and E are incorrect: CAPWAP is not an SSID; it is a control and data tunneling protocol, not a security standard like WPA2/WPA3; and it supports both IPv4 and IPv6, not just IPv4 ACL filtering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It is associated with communication between lightweight APs and the wireless LAN controller.
Why this is correct
CAPWAP (Control And Provisioning of Wireless Access Points) is the IETF standard protocol that creates a tunnel between lightweight access points (LAPs) and the wireless LAN controller (WLC). It carries both control plane messages (configuration, authentication) and data plane traffic (client packets) over UDP ports 5246 and 5247. This makes it the key communication channel in split-MAC architecture, not just an optional feature.
- ✓
It is relevant in controller-based WLAN designs.
Why this is correct
In controller-based WLAN designs, CAPWAP is the foundational protocol because it implements the split-MAC architecture, where the controller handles management and coordination while the AP handles real-time frame transmission. The WLC uses CAPWAP to push configuration, push firmware, and forward client data, which enables centralized policies, seamless roaming, and RF management. Without CAPWAP, the entire controller-based model would not function, as the AP would have no standard mechanism to communicate with the controller.
- ✗
It is the same thing as a client SSID.
Why it's wrong here
An SSID (Service Set Identifier) is the human-readable name of a wireless network that clients scan for and select to connect, typically broadcast in beacon frames. CAPWAP is a backend protocol that only operates on the wired network between an AP and a controller, invisible to wireless clients. Confusing them mixes the client-facing characteristic of a WLAN with the control-plane tunneling mechanism used behind the scenes, and they have no functional equivalence.
When this WOULD be correct
If the exam question asked about the various components and configurations of a wireless network, including client-side settings, then stating that CAPWAP is the same as a client SSID could be correct in a context where the question is misleadingly phrased or focuses on user-facing aspects of WLAN.
- ✗
It is a replacement for WPA2 and WPA3.
Why it's wrong here
CAPWAP is a tunneling protocol, not an encryption or authentication standard, so it cannot replace WPA2 or WPA3. WPA2 and WPA3 secure the wireless link by using AES-CCMP or AES-GCMP encryption and handshake-based authentication between the client and the AP. CAPWAP, in contrast, operates behind the AP layer, not between the client and AP, and it carries encrypted payloads rather than providing the encryption itself.
When this WOULD be correct
In a question that asks about security protocols in WLANs, specifically focusing on their roles in authentication and encryption, this option would be correct if it stated that CAPWAP is a replacement for a specific legacy protocol that manages access point communication, but not for WPA2 or WPA3.
- ✗
It is used only for IPv4 ACL filtering.
Why it's wrong here
CAPWAP is a Layer 3 protocol that encapsulates AP-controller traffic using UDP/IP, which has no connection to IPv4 ACL filtering. Access control lists (ACLs) are a separate security mechanism that permits or denies packets based on source/destination addresses, ports, or protocols, and they are configured on routers, switches, or WLCs. CAPWAP does not filter traffic; it simply provides a tunnel for control and data messages, so calling it an ACL tool is incorrect.
When this WOULD be correct
If the exam question were to ask about the specific functionalities of CAPWAP in relation to network security features, and if it were framed in a context where CAPWAP was described as a protocol that includes ACL filtering capabilities, then option E could be considered correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓It is associated with communication between lightweight APs and the wireless LAN controller.Correct answer▾
Why this is correct
CAPWAP (Control And Provisioning of Wireless Access Points) is the IETF standard protocol that creates a tunnel between lightweight access points (LAPs) and the wireless LAN controller (WLC). It carries both control plane messages (configuration, authentication) and data plane traffic (client packets) over UDP ports 5246 and 5247. This makes it the key communication channel in split-MAC architecture, not just an optional feature.
✗It is the same thing as a client SSID.Wrong answer — click to see why▾
Why this is wrong here
CAPWAP is a protocol for AP-controller communication, not a client SSID. An SSID is the network name broadcast by APs for client association, while CAPWAP operates between APs and the controller, not between clients and the network.
★ When this WOULD be the correct answer
If the exam question asked about the various components and configurations of a wireless network, including client-side settings, then stating that CAPWAP is the same as a client SSID could be correct in a context where the question is misleadingly phrased or focuses on user-facing aspects of WLAN.
Why candidates choose this
Students might confuse CAPWAP with SSID because both are associated with WLANs, but they serve entirely different purposes. The acronym similarity (both start with 'C' and 'S' sounds) can lead to this misconception.
✗It is a replacement for WPA2 and WPA3.Wrong answer — click to see why▾
Why this is wrong here
CAPWAP is not a security standard; it is a control and provisioning protocol. WPA2 and WPA3 are encryption and authentication standards for securing wireless client traffic. CAPWAP can tunnel traffic but does not replace these security protocols.
★ When this WOULD be the correct answer
In a question that asks about security protocols in WLANs, specifically focusing on their roles in authentication and encryption, this option would be correct if it stated that CAPWAP is a replacement for a specific legacy protocol that manages access point communication, but not for WPA2 or WPA3.
Why candidates choose this
Since CAPWAP is used in secure WLAN deployments, some may mistakenly think it provides security functions. However, security is handled by separate protocols like WPA2/3, 802.1X, or VPNs.
✗It is used only for IPv4 ACL filtering.Wrong answer — click to see why▾
Why this is wrong here
CAPWAP is not limited to IPv4 ACL filtering; it is a general-purpose protocol for managing APs and tunneling traffic. ACL filtering is a separate feature configured on the WLC or AP, not a function of CAPWAP itself.
★ When this WOULD be the correct answer
If the exam question were to ask about the specific functionalities of CAPWAP in relation to network security features, and if it were framed in a context where CAPWAP was described as a protocol that includes ACL filtering capabilities, then option E could be considered correct.
Why candidates choose this
Because CAPWAP can carry control and data traffic, and ACLs are often applied to filter traffic on WLCs, students might incorrectly associate CAPWAP with ACL filtering. However, CAPWAP is the transport mechanism, not the filtering method.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Visual reference
Go deeper
Related to this question
Learn chapter
Root Guard, Loop Guard, and BPDU Guard in Rapid PVST+
Key term
ACL
An Access Control List is a set of rules that determines who or what can access specific network resources or data.
Key term
LAN
Local Area Network — a network confined to a single physical location such as an office, building, or campus.
About these practice questions
This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.