Courseiva
Infrastructure →mediumMultiple Choice

350-401 Infrastructure Practice Question

A network administrator is configuring a Cisco wireless LAN controller (WLC) to support a new employee SSID. The SSID must use WPA2-Enterprise with 802.1X authentication against an external RADIUS server. The administrator has already configured the RADIUS server on the WLC. Which additional step is required to complete the configuration?

⚠ Common exam trap

The trap here is adding Layer 3 Web Policy in addition to 802.1X, which would cause double authentication and is not required for WPA2-Enterprise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to None.

For WPA2-Enterprise with 802.1X, the WLAN must use Layer 2 Security set to WPA2 with 802.1X, which leverages the configured RADIUS server for authentication. Layer 3 Security should remain None to avoid additional web authentication. This setup ensures that clients authenticate via 802.1X and receive AES encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to None.

    Why this is correct

    For WPA2-Enterprise with 802.1X, the WLAN's Layer 2 Security must be set to WPA2 with 802.1X. Layer 3 Security should be set to None because 802.1X handles authentication at Layer 2. This configuration enables the WLC to use the RADIUS server for authentication.

  • ✗

    Create a new WLAN and set the Layer 2 Security to WPA2 with PSK, and set the Layer 3 Security to Web Policy.

    Why it's wrong here

    WPA2 with PSK uses a pre-shared key, not 802.1X authentication. Web Policy is a Layer 3 authentication method that redirects users to a web portal. This combination does not meet the requirement for WPA2-Enterprise with 802.1X against a RADIUS server.

  • ✗

    Create a new WLAN and set the Layer 2 Security to None, and set the Layer 3 Security to Web Policy with RADIUS authentication.

    Why it's wrong here

    Setting Layer 2 Security to None disables wireless encryption, which is not secure. Web Policy with RADIUS authentication is a Layer 3 method that does not provide WPA2-Enterprise encryption. This configuration would not meet the WPA2-Enterprise requirement.

  • ✗

    Create a new WLAN and set the Layer 2 Security to WPA2 with 802.1X, and set the Layer 3 Security to Web Policy.

    Why it's wrong here

    While Layer 2 Security is correctly set to WPA2 with 802.1X, adding Layer 3 Web Policy would force an additional web authentication step after 802.1X. This is unnecessary and can cause double authentication. For pure WPA2-Enterprise, Layer 3 Security should be None.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.