Courseiva

350-401 · topic practice

Wireless Infrastructure practice questions

Practise ENCOR 350-401 Wireless Infrastructure practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Wireless Infrastructure

What the exam tests

What to know about Wireless Infrastructure

Wireless security questions usually test authentication protocols (WPA2/WPA3), encryption modes, 802.11 standards and troubleshooting clients that cannot connect or associate.

WPA2 vs WPA3 authentication and encryption standards.

802.11 wireless standards, frequency bands and channel behaviour.

WLAN client troubleshooting — association, authentication and DHCP.

How SSID, authentication method and pre-shared key affect wireless access.

Watch out for

Common Wireless Infrastructure exam traps

  • ▸WPA2-Enterprise uses 802.1X and a RADIUS server, not a pre-shared key.
  • ▸WPA3 provides stronger encryption but backwards compatibility is not guaranteed.
  • ▸A client can associate to an AP and still fail to reach the network.
  • ▸5 GHz gives higher throughput but shorter range than 2.4 GHz.

Practice set

Wireless Infrastructure questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full wireless explanation →

A network administrator is deploying Cisco Application Centric Infrastructure (ACI) and needs to allow two endpoint groups (EPGs) in different bridge domains to communicate while applying a contract that permits only TCP port 443. Which ACI construct provides the policy enforcement point where the contract is applied?

Question 2hardmultiple choice
Read the full wireless explanation →

A company is deploying a new Cisco wireless LAN controller (WLC) and wants to use RADIUS for authenticating wireless users. The WLC is configured with the RADIUS server IP, shared secret, and authentication port 1812. However, users are unable to authenticate. The network engineer checks the RADIUS server logs and sees that the server is receiving authentication requests from the WLC but is responding with an 'Access-Reject' message. The WLC logs show 'RADIUS server not responding' for the same server. What is the most likely cause?

Question 3hardmultiple choice
Read the full wireless explanation →

An enterprise is migrating from a traditional three-tier campus design to a software-defined access (SD-Access) fabric. The engineer needs to ensure that the existing wireless infrastructure integrates seamlessly. Which component of SD-Access is responsible for integrating wireless and wired policies?

Question 4mediummultiple choice
Read the full DHCP explanation →

An architect is planning a virtualized infrastructure for a branch office that will host a Cisco ISRv router and a local DHCP server. The architect wants to minimize management overhead and ensure the VMs can be easily backed up. Which hypervisor deployment model is most appropriate?

Question 5easymultiple choice
Read the full wireless explanation →

A network engineer executes the following command on Router R2:

R2# show ip sla configuration 1

IP SLAs Infrastructure Engine-II

Entry number: 1 Owner: admin Tag: Type of operation to perform: icmp-echo Target address: 192.168.2.10 Source address: 192.168.2.1 Type Of Service parameter: 0x0 Request size (ARR data portion): 28 Operation timeout (milliseconds): 5000 Frequency (seconds): 60 Next Scheduled Start Time: Start Time already passed Group Scheduled : FALSE Life (seconds): Forever Entry Ageout (seconds): never Recurring (Starting Everyday, Starting Time: 00:00:01) Status of entry (SNMP RowStatus): Active Threshold (milliseconds): 5000 Distribution Statistics: Number of statistic hours kept: 2 Number of statistic distribution buckets kept: 1 Statistic distribution interval (milliseconds): 20 Enhanced History:

Based on this output, what is the frequency of the IP SLA operation?

Question 6mediumdrag order
Read the full wireless explanation →

Drag and drop the steps of the hierarchical campus network design process into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 7mediummultiple choice
Open the full VLAN trunking answer →

An organization is implementing 802.1X for wireless users using Cisco ISE as the RADIUS server. The network engineer configures the wireless LAN controller (WLC) with 802.1X authentication. Users report that they can connect to the SSID but cannot access any network resources. The engineer checks the WLC and sees that users are authenticated and assigned to VLAN 100. The engineer also checks the switchport connecting the WLC and sees it is a trunk. What is the most likely issue?

Question 8mediummulti select
Read the full wireless explanation →

Which three statements about VRF path isolation in a service provider network are true? (Choose three.)

Drag and drop each wireless roaming method on the left to its matching 802.11 standard on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

802.11r

802.11k

802.11k

802.11v

802.11v

Question 10hardmultiple choice
Read the full wireless explanation →

An enterprise network uses TACACS+ for device administration and RADIUS for network access (VPN and wireless). The TACACS+ server is configured to authorize commands. A network engineer notices that after a recent upgrade of the TACACS+ server software, some commands that were previously authorized are now being denied. The engineer checks the router configuration and sees 'aaa authorization commands 15 default group tacacs+'. The TACACS+ server logs show that the authorization requests are being sent and responded to. What is the most likely cause?

Question 11mediummultiple choice
Read the full wireless explanation →

A network administrator is using Cisco DNA Center Assurance to monitor the health of a wireless network. The administrator notices that a particular access point is reporting a high number of client association failures. Which Cisco DNA Center Assurance feature should be used to correlate these failures with client device types and identify the root cause?

Question 12mediummulti select
Read the full wireless explanation →

A network engineer is analyzing Cisco DNA Center Assurance data to troubleshoot a wireless client's poor performance. The engineer observes that the client's health score is low due to high retry rates and low SNR. Which TWO Assurance metrics should the engineer examine to further diagnose the issue? (Choose two.)

Question 13mediummultiple choice
Read the full DHCP explanation →

A network administrator is using the Cisco DNA Center Assurance application to troubleshoot a user's slow wireless experience. The administrator notices that the client's onboarding time is high and wants to see a detailed timeline of the client's onboarding process, including association, authentication, and DHCP phases. Which Cisco DNA Center Assurance feature provides this information?

Question 14mediummultiple choice
Read the full wireless explanation →

A network engineer is troubleshooting a wireless connectivity issue in a campus network managed by Cisco DNA Center. The Assurance module shows that several access points have high client association failures. The engineer checks the wireless controller configuration and finds that the APs are registered and functional. What is the most likely cause of the association failures?

Question 15easymultiple choice
Read the full wireless explanation →

A network engineer is configuring a Cisco Wireless LAN Controller (WLC) for a new wireless network. The engineer wants to ensure that client traffic is tunneled back to the WLC and that the WLC is the single point of management for the access points. Which mode should the access points be configured in?

Question 16mediummultiple choice
Read the full wireless explanation →

A network architect is designing a new branch office that requires a controller-based wireless solution with centralized management, but the branch has limited bandwidth and must continue forwarding client traffic locally even if the WAN link to the headquarters controller fails. The branch has a single Cisco Catalyst 9800-L controller and several Cisco Catalyst 9100 access points. Which deployment mode should the architect choose for the access points?

Question 17hardmultiple choice
Read the full wireless explanation →

A network engineer is designing a Cisco SD-Access fabric for a campus network. The fabric must support both wired and wireless clients, and the engineer wants to ensure that traffic from wired endpoints is encapsulated and forwarded through the fabric without requiring the endpoints to change their IP addresses. Which component of the SD-Access architecture is responsible for encapsulating traffic from wired endpoints and forwarding it to the fabric edge?

Question 18mediummultiple choice
Read the full wireless explanation →

A network engineer is configuring a Cisco wireless LAN controller (WLC) to support a new wireless network for guests. The requirement is that guest clients must be isolated from the corporate network and only have internet access. Which feature should be configured on the WLC?

Question 19mediummultiple choice
Open the full VLAN trunking answer →

A network architect is designing a new branch office that must support wired and wireless users on the same Layer 2 segment while enforcing consistent security policy regardless of where a user connects. The design must minimize the number of VLANs and IP subnets that must be provisioned as users move between floors. Which Cisco architecture feature should be used to meet these requirements?

Question 20mediummultiple choice
Read the full wireless explanation →

A network architect is designing a Cisco SD-Access fabric for a hospital campus. The hospital requires that guest wireless users be allowed access only to the internet, while clinical staff devices must reach internal EHR servers. The fabric uses Cisco DNA Center and Cisco Identity Services Engine for policy. Which fabric component enforces the group-based policy between these user groups?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Wireless Infrastructure sessions

Start a Wireless Infrastructure only practice session

Every question in these sessions is drawn from the Wireless Infrastructure domain — nothing else.

Related practice questions

Related 350-401 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 350-401 exam test about Wireless Infrastructure?
Wireless security questions usually test authentication protocols (WPA2/WPA3), encryption modes, 802.11 standards and troubleshooting clients that cannot connect or associate.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Wireless Infrastructure questions in a focused session?
Yes — the session launcher on this page draws every question from the Wireless Infrastructure domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 350-401 topics?
Use the topic links above to move to related areas, or go back to the 350-401 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 350-401 exam covers. They are not copied from any real exam or dump site.