Courseiva
Architecture →hardMultiple Choice

CCNP Architecture Practice Question

A network engineer is deploying a Cisco Wireless LAN Controller (WLC) in a large campus with 500 access points. The engineer must ensure that the WLC can handle the expected client load and that APs can join the controller securely. Which protocol does the AP use to discover and join the WLC, and what is the default secure management protocol for the WLC GUI?

⚠ Common exam trap

Test-takers frequently confuse the secure transport protocol (DTLS) with the discovery and join protocol (CAPWAP), or assuming HTTP is the default for WLC management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CAPWAP for AP join; HTTPS for WLC GUI

Access points use CAPWAP to discover and join a WLC, establishing both control and data tunnels. The control channel is secured with DTLS, while the data channel may also be encrypted. The WLC GUI is accessed via HTTPS by default, ensuring secure management. This pairing is standard for Cisco wireless deployments and satisfies the need for secure AP join and management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    LWAPP for AP join; HTTP for WLC GUI

    Why it's wrong here

    LWAPP is the legacy protocol replaced by CAPWAP in modern Cisco WLC deployments. HTTP is not the default secure management protocol; HTTPS is used. Using LWAPP would not be supported on current controllers and does not provide the required security, making this option incorrect.

  • ✗

    DTLS for AP join; HTTPS for WLC GUI

    Why it's wrong here

    DTLS is used within CAPWAP to secure the control channel, but it is not the discovery or join protocol itself. APs first use CAPWAP discovery to find the WLC. Stating DTLS as the join protocol misrepresents the process, so this option is not correct.

  • ✗

    CAPWAP for AP join; HTTP for WLC GUI

    Why it's wrong here

    While CAPWAP is correct for AP join, HTTP is not the default secure management protocol. The WLC GUI defaults to HTTPS to protect credentials and configuration. Using HTTP would expose sensitive management traffic, violating the security requirement in the scenario.

  • ✓

    CAPWAP for AP join; HTTPS for WLC GUI

    Why this is correct

    Access points use CAPWAP (Control and Provisioning of Wireless Access Points) to discover and join a WLC, encapsulating control and data traffic. The WLC GUI is accessed via HTTPS by default, providing secure management. This combination meets the requirement for secure AP join and management in a large campus deployment.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.