Courseiva
Architecture →mediumMultiple Choice

350-401 Architecture Practice Question

A network architect is designing a new branch office that requires a controller-based wireless solution. The branch has a single Cisco Catalyst 9800-CL appliance and needs to support 802.1X authentication with dynamic VLAN assignment for employee SSIDs. Which deployment mode should the architect use for the access points to meet these requirements with minimal configuration on the APs?

⚠ Common exam trap

The trap here is assuming that FlexConnect is always required for branch offices, when local mode is sufficient if WAN survivability is not a requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Local mode with the APs managed by the Catalyst 9800-CL controller

Local mode is the correct choice because it keeps the APs lightweight and relies on the Catalyst 9800-CL controller for all client authentication and VLAN assignment. This centralizes the complex configuration on the controller, reducing AP-side setup. The other modes either add unnecessary complexity for survivability or do not serve client traffic at all.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FlexConnect mode with central switching enabled for the employee SSIDs

    Why it's wrong here

    FlexConnect with central switching still tunnels client traffic to the controller, but FlexConnect is designed for scenarios where the AP can operate in standalone mode if the WAN link fails. It adds complexity because the AP must maintain local configuration for authentication fallback. Since the scenario does not require survivability during WAN outages, FlexConnect is unnecessary and does not provide a simpler configuration than local mode.

  • ✗

    Sniffer mode with the APs capturing 802.11 frames for analysis

    Why it's wrong here

    Sniffer mode allows the AP to capture wireless frames and send them to a packet analyzer, but it does not provide client connectivity. It cannot handle 802.1X authentication or dynamic VLAN assignment because it does not associate clients. This mode is strictly for troubleshooting and analysis, not for production wireless access.

  • ✓

    Local mode with the APs managed by the Catalyst 9800-CL controller

    Why this is correct

    In local mode, the AP establishes a CAPWAP tunnel to the Catalyst 9800-CL and the controller handles all client authentication, including 802.1X and dynamic VLAN assignment. This centralizes configuration and keeps the APs simple, matching the requirement for minimal AP configuration. Local mode is the standard controller-based deployment for branch offices with centralized management.

  • ✗

    Monitor mode with the APs dedicated to spectrum analysis and rogue detection

    Why it's wrong here

    Monitor mode turns the AP into a dedicated sensor for spectrum analysis and rogue detection, and it does not serve client traffic. This mode cannot authenticate users or assign VLANs, so it fails the requirement to support employee SSIDs. Monitor mode is used for security and RF monitoring, not for providing wireless access to clients.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.