Courseiva
mediumMultiple Choice

350-401 Practice Question: Runs the following command on a Cisco WLC: WLC#…

A network engineer runs the following command on a Cisco WLC:

WLC# show ap config general AP-2

AP Name: AP-2 MAC Address: aabb.cc00.0200 Country Code: US - United States Regulatory Domain: 802.11bg: -A 802.11a: -A AP Submode: FlexConnect AP Mode: FlexConnect AP Join Priority: 2 Primary Controller: WLC-1 Secondary Controller: WLC-2 Tertiary Controller: WLC-3

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the distinction between AP modes, and the trap here is that candidates see 'AP Mode: FlexConnect' but mistakenly associate it with Local mode behavior (tunneling all traffic) or assume the AP must be directly connected at Layer 2, when in fact FlexConnect is designed for remote sites with Layer 3 connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The AP can locally switch client traffic and maintain connectivity even if the WLC is unreachable.

The output shows 'AP Submode: FlexConnect' and 'AP Mode: FlexConnect', which indicates the AP is operating in FlexConnect mode. In FlexConnect mode, the AP can locally switch client traffic (data plane) and maintain client connectivity even if the WLC becomes unreachable, as the control plane is separated from the data plane. This is a key characteristic of FlexConnect, unlike Local mode where all traffic must be tunneled to the WLC.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The AP is operating in Local mode and will tunnel all traffic to the WLC.

    Why it's wrong here

    The AP is explicitly in FlexConnect mode, not Local mode. In Local mode, the AP encapsulates every client frame in CAPWAP and tunnels it to the WLC for bridging and switching, making the controller an inline dependency for data traffic. FlexConnect, however, decouples the data path from the controller and can switch traffic locally or tunnel it on a per-VLAN basis—so the AP is not operating as a Local-mode AP.

  • ✓

    The AP can locally switch client traffic and maintain connectivity even if the WLC is unreachable.

    Why this is correct

    This is the correct choice. A FlexConnect AP can switch wireless client traffic directly on its wired interface, which removes the need to backhaul user frames to the WLC. If the CAPWAP control tunnel to the WLC is lost, the AP enters standalone mode and continues to serve the locally switched WLANs, ensuring client connectivity for remote branch sites. This resilient behavior is the primary design goal of FlexConnect, distinguishing it from Local mode.

  • ✗

    The AP will only work if the WLC is directly connected at Layer 2.

    Why it's wrong here

    This is false because FlexConnect is purpose-built for remote sites where the AP and WLC are separated by a Layer 3 WAN, not a direct Layer 2 connection. The control plane uses CAPWAP, which operates over IP, so the AP and WLC do not need to share a broadcast domain or be physically adjacent. Requiring a Layer 2 direct link would make FlexConnect useless for distributed branch deployments.

  • ✗

    The AP is in Monitor mode and will not serve clients.

    Why it's wrong here

    This is incorrect because Monitor mode is a passive operating state in which the radio continuously scans the airspace for rogue devices and performs RF monitoring, and it does not serve any client traffic. In contrast, a FlexConnect AP actively advertises SSIDs, processes client associations, and switches data locally or tunnels it per configuration. Therefore, describing a FlexConnect AP as a Monitor-mode AP contradicts its fundamental client-serving functionality.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.