Courseiva
Architecture →mediumMultiple Choice

CCNP Architecture Practice Question

A network administrator is configuring a Cisco wireless controller for a branch office. The design requires that guest clients be isolated from corporate clients while still using the same physical access points. Which Cisco wireless architecture feature should be used to separate the traffic?

⚠ Common exam trap

The trap here is treating Peer-to-Peer Blocking or interface groups as security segmentation tools, when they do not isolate traffic between different WLANs or VLANs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a separate WLAN with a guest VLAN and enforce ACLs or a firewall between the guest and corporate subnets.

Guest isolation in a Cisco wireless deployment is achieved by placing guest clients on a dedicated WLAN and VLAN, then enforcing separation at Layer 3 with ACLs or a firewall. Peer-to-Peer Blocking only stops client-to-client traffic within a WLAN, interface groups are for dynamic interface mapping, and FlexConnect local switching addresses traffic forwarding rather than segmentation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Peer-to-Peer Blocking on the guest WLAN.

    Why it's wrong here

    Peer-to-Peer Blocking prevents wireless clients on the same WLAN from communicating directly with each other. It does not isolate guest clients from corporate clients on a different WLAN or VLAN. While useful for guest privacy, it does not provide the inter-WLAN separation required in this scenario, making this option insufficient.

  • ✗

    Configure separate WLANs mapped to different VLANs and apply an interface group.

    Why it's wrong here

    Separate WLANs with different VLANs do separate traffic at Layer 2, but an interface group is used to map a WLAN to multiple dynamic interfaces for load balancing or mobility, not for guest isolation. Simply applying an interface group does not inherently enforce isolation between guest and corporate clients, so this option does not fully meet the requirement.

  • ✗

    Configure the access points in local mode and use FlexConnect local switching for all WLANs.

    Why it's wrong here

    FlexConnect local switching changes where traffic is switched, but it does not by itself isolate guest from corporate clients. If both WLANs are locally switched on the same VLAN, isolation is not achieved. Local mode versus FlexConnect is about traffic path, not security segmentation, so this option does not meet the isolation requirement.

  • ✓

    Use a separate WLAN with a guest VLAN and enforce ACLs or a firewall between the guest and corporate subnets.

    Why this is correct

    Creating a dedicated guest WLAN mapped to a separate VLAN, combined with ACLs or firewall rules between the guest and corporate subnets, provides clear Layer 2 and Layer 3 separation. This approach isolates guest traffic while allowing shared physical access points. It directly satisfies the requirement to separate guest and corporate clients, making it the correct design choice.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.