350-401 Architecture Practice Question
A network architect is designing a new branch office that requires a controller-based wireless solution. The branch has a single Cisco Catalyst 9800-CL appliance and needs to support 802.1X authentication with dynamic VLAN assignment for employee SSIDs. Which deployment mode should the architect use for the access points to meet these requirements with minimal configuration on the APs?
⚠ Common exam trap
The trap here is assuming that FlexConnect is always required for branch offices, when local mode is sufficient if WAN survivability is not a requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Local mode with the APs managed by the Catalyst 9800-CL controller
Local mode is the correct choice because it keeps the APs lightweight and relies on the Catalyst 9800-CL controller for all client authentication and VLAN assignment. This centralizes the complex configuration on the controller, reducing AP-side setup. The other modes either add unnecessary complexity for survivability or do not serve client traffic at all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FlexConnect mode with central switching enabled for the employee SSIDs
Why it's wrong here
FlexConnect with central switching still tunnels client traffic to the controller, but FlexConnect is designed for scenarios where the AP can operate in standalone mode if the WAN link fails. It adds complexity because the AP must maintain local configuration for authentication fallback. Since the scenario does not require survivability during WAN outages, FlexConnect is unnecessary and does not provide a simpler configuration than local mode.
- ✗
Sniffer mode with the APs capturing 802.11 frames for analysis
Why it's wrong here
Sniffer mode allows the AP to capture wireless frames and send them to a packet analyzer, but it does not provide client connectivity. It cannot handle 802.1X authentication or dynamic VLAN assignment because it does not associate clients. This mode is strictly for troubleshooting and analysis, not for production wireless access.
- ✓
Local mode with the APs managed by the Catalyst 9800-CL controller
Why this is correct
In local mode, the AP establishes a CAPWAP tunnel to the Catalyst 9800-CL and the controller handles all client authentication, including 802.1X and dynamic VLAN assignment. This centralizes configuration and keeps the APs simple, matching the requirement for minimal AP configuration. Local mode is the standard controller-based deployment for branch offices with centralized management.
- ✗
Monitor mode with the APs dedicated to spectrum analysis and rogue detection
Why it's wrong here
Monitor mode turns the AP into a dedicated sensor for spectrum analysis and rogue detection, and it does not serve client traffic. This mode cannot authenticate users or assign VLANs, so it fails the requirement to support employee SSIDs. Monitor mode is used for security and RF monitoring, not for providing wireless access to clients.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Fundamentals and 802.11 Standards
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.