350-401 Infrastructure Practice Question
A network administrator is configuring a Cisco wireless LAN controller (WLC) to support a new employee SSID. The SSID must use WPA2-Enterprise with 802.1X authentication against an external RADIUS server. The administrator has already configured the RADIUS server on the WLC. Which additional step is required to complete the configuration?
⚠ Common exam trap
The trap here is adding Layer 3 Web Policy in addition to 802.1X, which would cause double authentication and is not required for WPA2-Enterprise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to None.
For WPA2-Enterprise with 802.1X, the WLAN must use Layer 2 Security set to WPA2 with 802.1X, which leverages the configured RADIUS server for authentication. Layer 3 Security should remain None to avoid additional web authentication. This setup ensures that clients authenticate via 802.1X and receive AES encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to None.
Why this is correct
For WPA2-Enterprise with 802.1X, the WLAN's Layer 2 Security must be set to WPA2 with 802.1X. Layer 3 Security should be set to None because 802.1X handles authentication at Layer 2. This configuration enables the WLC to use the RADIUS server for authentication.
- ✗
Create a new WLAN and set the Layer 2 Security to WPA2 with PSK, and set the Layer 3 Security to Web Policy.
Why it's wrong here
WPA2 with PSK uses a pre-shared key, not 802.1X authentication. Web Policy is a Layer 3 authentication method that redirects users to a web portal. This combination does not meet the requirement for WPA2-Enterprise with 802.1X against a RADIUS server.
- ✗
Create a new WLAN and set the Layer 2 Security to None, and set the Layer 3 Security to Web Policy with RADIUS authentication.
Why it's wrong here
Setting Layer 2 Security to None disables wireless encryption, which is not secure. Web Policy with RADIUS authentication is a Layer 3 method that does not provide WPA2-Enterprise encryption. This configuration would not meet the WPA2-Enterprise requirement.
- ✗
Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to Web Policy.
Why it's wrong here
While Layer 2 Security is correctly set to WPA2 with 802.1X, adding Layer 3 Web Policy would force an additional web authentication step after 802.1X. This is unnecessary and can cause double authentication. For pure WPA2-Enterprise, Layer 3 Security should be None.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.