easyMultiple Choice
200-201 Practice Question: Monitor for unauthorized wireless access points
A company wants to monitor for unauthorized wireless access points. Which technique should they implement?
⚠ Common exam trap
Cisco often tests the distinction between wired security controls (port security, VLANs, 802.1X) and wireless-specific monitoring (WIPS), trapping candidates who assume that any network security measure can detect unauthorized wireless devices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a Wireless Intrusion Prevention System (WIPS).
A Wireless Intrusion Prevention System (WIPS) is specifically designed to detect, classify, and block unauthorized wireless access points (rogue APs) by continuously monitoring the RF spectrum. Unlike wired-only controls, WIPS can identify rogue devices that are not connected to the wired network, making it the correct choice for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable port security on all switches.
Why it's wrong here
Port security binds MAC addresses to switch ports, detecting wired rogue devices, not radio-frequency rogue APs. It is tempting because it addresses unauthorised network access generally, and would be correct for stopping unknown devices plugging into access ports, but it cannot see wireless frames.
- ✗
Use VLAN segmentation.
Why it's wrong here
VLAN segmentation separates traffic into isolated broadcast domains; it neither discovers nor locates rogue access points. It is tempting because it limits lateral movement from a compromised device, and would be correct for containing an intruder already on the network, but it provides no wireless monitoring capability.
- ✓
Deploy a Wireless Intrusion Prevention System (WIPS).
Why this is correct
A WIPS continuously scans the radio frequency spectrum, matching detected signals against known authorised access point inventories and attack signatures. It identifies rogue or unauthorised access points and can automatically contain them, satisfying the requirement to monitor for unauthorised wireless devices rather than merely detect them.
- ✗
Implement 802.1X authentication.
Why it's wrong here
802.1X authenticates clients joining the wired or wireless network; it does not scan the radio spectrum for rogue access points. It is tempting because it controls wireless access, but detecting unauthorised APs requires wireless intrusion detection or site surveys, not port-based authentication.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.