CCNP Architecture Practice Question
A network engineer is deploying a Cisco Wireless LAN Controller (WLC) in a centralized deployment mode. The engineer needs to ensure that guest traffic is isolated from internal traffic and that guests can only access the internet. Which feature should be configured on the WLC to meet these requirements?
⚠ Common exam trap
The trap here is thinking that Peer-to-Peer Blocking provides complete guest isolation, when it only prevents wireless clients from talking to each other.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a separate WLAN with a guest SSID and map it to a dynamic interface with a dedicated VLAN.
The most effective way to isolate guest traffic is to create a separate WLAN with a guest SSID and assign it to a dynamic interface with a dedicated VLAN. This segregates guest traffic at Layer 2 and allows Layer 3 restrictions via ACLs or firewall rules. Peer-to-Peer Blocking only prevents client-to-client communication, and using the management interface is insecure. DHCP relay is unrelated to isolation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the guest WLAN to use the management interface.
Why it's wrong here
Using the management interface for guest traffic is a security risk because it mixes guest traffic with management traffic. The management interface is used for WLC administration and should not carry user data. This would not provide isolation from internal traffic and could expose the WLC to attacks.
- ✗
Enable DHCP relay on the management interface.
Why it's wrong here
DHCP relay is used to forward DHCP requests from clients to a DHCP server. It does not provide traffic isolation or restrict guest access to the internet. While necessary for IP address assignment, it does not meet the requirement for isolating guest traffic from internal networks.
- ✓
Configure a separate WLAN with a guest SSID and map it to a dynamic interface with a dedicated VLAN.
Why this is correct
Creating a separate WLAN for guests and mapping it to a dynamic interface with its own VLAN isolates guest traffic from internal networks. The dynamic interface can be configured with an ACL or firewall rules to restrict guests to internet-only access. This approach ensures that guest traffic is segregated at Layer 2 and can be controlled at Layer 3.
- ✗
Enable Peer-to-Peer Blocking on the guest WLAN.
Why it's wrong here
Peer-to-Peer Blocking prevents wireless clients on the same WLAN from communicating directly with each other. While it enhances guest isolation, it does not isolate guest traffic from internal wired networks or restrict guests to internet-only access. It is a complementary feature but not sufficient for the scenario.
Visual reference
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.