Courseiva
mediumMultiple Select

350-401 Practice Question: Which two statements about the Cisco FlexConnect…

Which two statements about the Cisco FlexConnect architecture are true? (Choose two.)

⚠ Common exam trap

350-401 often tests the misconception that FlexConnect APs must always tunnel traffic to the WLC; candidates forget that local switching and standalone mode are core FlexConnect capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FlexConnect APs can locally switch client data traffic when the CAPWAP tunnel to the WLC is down.

Option A is correct because FlexConnect's defining feature is local switching: the AP bridges client traffic directly onto the local wired VLAN at the branch, and this continues to function in standalone mode when the CAPWAP control tunnel to the WLC is lost. Option C is correct because FlexConnect groups let you apply a common set of VLAN-to-WLAN mappings, ACLs, and other settings to multiple APs, simplifying branch configuration and enabling features like VLAN-based central switching. Option B is wrong because FlexConnect explicitly supports local switching rather than requiring all client traffic to be tunneled to the WLC. Option D is wrong because FlexConnect APs are designed for branch deployments where the WLC is remote over a Layer 3 network, not directly Layer 2 attached. Option E is wrong because FlexConnect APs do support native VLAN tagging on their uplink switch port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    FlexConnect APs can locally switch client data traffic when the CAPWAP tunnel to the WLC is down.

    Why this is correct

    FlexConnect enables local switching, so the AP bridges client traffic directly onto the access VLAN rather than tunnelling it to the WLC. When the CAPWAP control tunnel drops, clients on that locally switched WLAN retain connectivity and continue forwarding data.

  • ✗

    FlexConnect APs must always tunnel all client traffic back to the WLC for central switching.

    Why it's wrong here

    FlexConnect supports local switching, where the AP bridges client traffic onto the local wired network, so tunnelling everything centrally is false. It is tempting because central switching is the default in local mode, but FlexConnect exists precisely to avoid the WAN backhaul; central tunnelling suits branch designs requiring centralised policy.

  • ✓

    FlexConnect APs can be assigned to a FlexConnect group to share the same VLAN and ACL configuration.

    Why this is correct

    FlexConnect groups let multiple access points inherit one shared VLAN-to-WLAN mapping and ACL set, so branch sites avoid configuring each AP individually. This satisfies the stem's requirement for centralised, reusable configuration across APs, with the group acting as the common policy container that members reference.

  • ✗

    FlexConnect APs require a direct Layer 2 connection to the WLC at all times.

    Why it's wrong here

    FlexConnect APs can operate in standalone mode when the WLC is unreachable, so a permanent Layer 2 connection is not required; they use CAPWAP over routed links. It is tempting because local-mode APs need controller reachability, but FlexConnect is designed for WAN-separated branches; direct Layer 2 suits local-mode deployments.

  • ✗

    FlexConnect APs cannot support native VLAN tagging on the uplink interface.

    Why it's wrong here

    FlexConnect APs do support native VLAN tagging on the uplink, so this statement is false. It tempts candidates because FlexConnect's local switching model separates client VLANs from the AP management VLAN, which can suggest tagging is unsupported; in reality, native VLAN tagging is configured on the switch port for the AP's untagged management traffic.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.