CCNP Architecture Practice Question
A network administrator is configuring a Cisco Wireless LAN Controller (WLC) for a new office. The office has a mix of corporate laptops and guest devices. The administrator wants to ensure that guest devices can only access the Internet and are isolated from the corporate network. Which WLC feature should be configured to achieve this?
⚠ Common exam trap
The trap here is thinking that dynamic VLAN assignment alone provides guest isolation, when actually a separate WLAN with a dedicated interface and ACL is needed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Guest WLAN with a dedicated interface and ACL
To isolate guest traffic, the administrator should create a separate guest WLAN and map it to a dedicated interface, such as a DMZ VLAN. Then, an ACL can be applied to that WLAN to restrict traffic to only Internet-bound destinations. This prevents guests from accessing corporate resources. Other options like dynamic VLAN or FlexConnect do not inherently provide the required isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FlexConnect local switching
Why it's wrong here
FlexConnect local switching allows traffic to be switched locally at the AP, which can be useful for branch offices. However, it does not automatically provide guest isolation. Without proper VLAN and ACL configuration, guests could still access corporate resources. It is not a specific guest isolation feature.
- ✓
Guest WLAN with a dedicated interface and ACL
Why this is correct
Creating a separate guest WLAN mapped to a dedicated interface (e.g., a DMZ VLAN) and applying an ACL that permits only Internet-bound traffic is the standard method for guest isolation. This ensures guest devices cannot reach corporate subnets. The WLC supports this through interface mapping and ACLs applied to the WLAN.
- ✗
Dynamic VLAN assignment
Why it's wrong here
Dynamic VLAN assignment places clients into specific VLANs based on authentication. While it can separate guest traffic into a different VLAN, it does not inherently enforce isolation from the corporate network. Additional ACLs or firewall rules would be needed. It is not the specific feature designed for guest isolation.
- ✗
Access Control Lists (ACLs) on the WLC
Why it's wrong here
ACLs on the WLC can filter traffic, but they are not the primary mechanism for guest isolation. They can be used to restrict certain traffic, but a more appropriate feature is a dedicated guest WLAN with interface mapping. ACLs alone would require complex rules and might not provide the necessary isolation from corporate resources.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.