mediumMultiple Choice
350-401 Practice Question: Given the following WLAN configuration on a Cisco…
Given the following WLAN configuration on a Cisco 9800 WLC:
wlan test-wlan 1 test-ssid client vlan VLAN10
no security wpa no security wpa2
security wpa3
no security ft
What is a potential issue with this configuration?
⚠ Common exam trap
Cisco often tests the fact that enabling WPA3 does not automatically configure an AKM, and candidates mistakenly assume that 'security wpa3' alone is sufficient, overlooking the required key management statement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The WLAN is missing a security key management (AKM) configuration.
The configuration enables WPA3 but omits a security key management (AKM) policy. WPA3 requires an AKM suite (e.g., SAE for personal or 802.1X for enterprise) to negotiate authentication and key derivation. Without an AKM configured, the WLAN will fail to enable or will not allow clients to associate, as the WLC cannot determine the key management protocol.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The WLAN is missing a security key management (AKM) configuration.
Why this is correct
WPA3 authentication relies on a specific AKM, SAE (Simultaneous Authentication of Equals), which must be explicitly declared in the WLAN security profile. The CLI snippet lacks the 'security wpa3 akm sae' command, meaning the controller has no key management agreement to present to WPA3 clients. Without a defined AKM, the WPA3 encryption suite cannot negotiate session keys, so the WLAN remains non-functional for WPA3-capable devices even though other parameters like SSID and VLAN are correct.
- ✗
The client VLAN is incorrectly configured.
Why it's wrong here
The client VLAN assignment shown in the configuration is within the valid range and correctly mapped to the intended client subnet, so IP delivery would work post-association. However, VLAN misconfiguration would typically manifest as DHCP failure or lack of network access after the client is already authenticated, not as a failure during the WPA3 security handshake. Thus, the VLAN is not the root cause because the client never reaches the stage where VLAN assignment matters.
- ✗
WPA3 is not supported on this platform.
Why it's wrong here
Cisco 9800 Series Wireless LAN Controllers support WPA3 across supported access points with proper IOS XE versions, so a platform limitation is not a valid explanation. The configuration snippet already shows WPA3-related security parameters, indicating the platform recognizes the feature; otherwise, those commands would be rejected. The issue is the missing AKM subcommand, not hardware or software capability, as the controller can handle WPA3 once the proper key management is configured.
- ✗
The SSID name is too long.
Why it's wrong here
The SSID in the configuration is well under the IEEE 802.11 maximum of 32 octets, so its length is compliant and cannot be the cause of the WLAN failure. SSID length only influences beacon frame overhead and client visibility, but it has no bearing on WPA3 SAE key exchange or AKM selection. Therefore, this option incorrectly frames a cosmetic parameter as a security blocker, when the actual problem is the absent SAE AKM definition.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.