Courseiva
mediumMultiple Choice

350-401 Client Isolation Practice Question

An engineer is deploying a wireless network in a hospital that requires strict security and client isolation. The network must support 802.1X authentication for employees and a separate guest SSID with a captive portal. The engineer configures the WLC with RADIUS servers for 802.1X and a local web server for the captive portal. However, guest users can access the internal network after authentication. What configuration change is needed?

⚠ Common exam trap

A common misconception is that enabling client isolation on a guest SSID is sufficient to prevent guest users from accessing the internal network. In reality, client isolation only blocks wireless client-to-client communication, not traffic to wired hosts. The correct approach is to apply a VLAN ACL or use a separate VLAN with firewall rules to restrict access to internal subnets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a VLAN ACL on the guest VLAN to block access to internal subnets.

Applying a VLAN ACL on the guest VLAN explicitly blocks traffic from the guest wireless network to the internal subnets. This ensures that after captive portal authentication, guest users cannot access internal resources. Option A is incorrect because client isolation (peer-to-peer blocking) only prevents wireless clients from communicating with each other on the same SSID; it does not block traffic from wireless clients to wired hosts on the internal network. Option B is incorrect because 802.1X authentication is for employees, and requiring it for guests would defeat the purpose of an open guest SSID with captive portal. Option D is incorrect because placing the guest SSID on the same VLAN as the employee SSID would give guest users Layer 2 access to internal hosts, which is exactly what needs to be prevented.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable client isolation (peer-to-peer blocking) on the guest SSID.

    Why it's wrong here

    Client isolation (peer-to-peer blocking) is a wireless controller feature that suppresses Ethernet bridging between wireless clients associated to the same SSID. It does not inspect or filter traffic that leaves the wireless network, so guest clients can still route to any internal subnet if the guest VLAN allows it. Wireless-level isolation therefore addresses only client-to-client communication, not the guest VLAN's default route or inter-VLAN routing policies.

  • ✗

    Configure 802.1X authentication for the guest SSID as well.

    Why it's wrong here

    Configuring 802.1X for the guest SSID requires every guest to possess enterprise credentials or a certificate, which defeats the purpose of an open captive-portal guest network. Even if authentication succeeded, 802.1X only verifies identity; it does not by itself enforce deny rules toward internal subnets unless combined with RADIUS-assigned VLANs or downloadable ACLs. Thus, it adds significant onboarding friction and still fails to block guest traffic to internal hosts.

  • ✓

    Apply a VLAN ACL on the guest VLAN to block access to internal subnets.

    Why this is correct

    Applying a VLAN ACL on the guest VLAN is the correct fix because it filters traffic at Layer 3/4 on the VLAN's SVI, allowing you to explicitly deny any traffic destined to internal subnets (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) while permitting public internet access. Unlike wireless features, this ACL is enforced regardless of the access point or client type, and it operates after the client has already obtained an IP address. It provides centralized, rule-based protection for the entire guest network segment.

  • ✗

    Place the guest SSID on the same VLAN as the employee SSID.

    Why it's wrong here

    Placing the guest SSID on the same VLAN as the employee SSID gives untrusted guest clients direct Layer 2 access to employee workstations, printers, and servers on that segment. Such clients can perform local LAN attacks such as ARP spoofing, DHCP theft, or port scans without traversing a routed boundary, and any IP ACL applied on the VLAN would also affect employee traffic. This configuration completely removes the security zone separation that an isolated guest VLAN is designed to provide.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.