mediumMultiple Select
350-401 Practice Question: Which two statements about the Cisco FlexConnect…
Which two statements about the Cisco FlexConnect architecture are true? (Choose two.)
⚠ Common exam trap
350-401 often tests the misconception that FlexConnect APs must always tunnel traffic to the WLC; candidates forget that local switching and standalone mode are core FlexConnect capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FlexConnect APs can locally switch client data traffic when the CAPWAP tunnel to the WLC is down.
Option A is correct because FlexConnect's defining feature is local switching: the AP bridges client traffic directly onto the local wired VLAN at the branch, and this continues to function in standalone mode when the CAPWAP control tunnel to the WLC is lost. Option C is correct because FlexConnect groups let you apply a common set of VLAN-to-WLAN mappings, ACLs, and other settings to multiple APs, simplifying branch configuration and enabling features like VLAN-based central switching. Option B is wrong because FlexConnect explicitly supports local switching rather than requiring all client traffic to be tunneled to the WLC. Option D is wrong because FlexConnect APs are designed for branch deployments where the WLC is remote over a Layer 3 network, not directly Layer 2 attached. Option E is wrong because FlexConnect APs do support native VLAN tagging on their uplink switch port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
FlexConnect APs can locally switch client data traffic when the CAPWAP tunnel to the WLC is down.
Why this is correct
FlexConnect enables local switching, so the AP bridges client traffic directly onto the access VLAN rather than tunnelling it to the WLC. When the CAPWAP control tunnel drops, clients on that locally switched WLAN retain connectivity and continue forwarding data.
- ✗
FlexConnect APs must always tunnel all client traffic back to the WLC for central switching.
Why it's wrong here
FlexConnect supports local switching, where the AP bridges client traffic onto the local wired network, so tunnelling everything centrally is false. It is tempting because central switching is the default in local mode, but FlexConnect exists precisely to avoid the WAN backhaul; central tunnelling suits branch designs requiring centralised policy.
- ✓
FlexConnect APs can be assigned to a FlexConnect group to share the same VLAN and ACL configuration.
Why this is correct
FlexConnect groups let multiple access points inherit one shared VLAN-to-WLAN mapping and ACL set, so branch sites avoid configuring each AP individually. This satisfies the stem's requirement for centralised, reusable configuration across APs, with the group acting as the common policy container that members reference.
- ✗
FlexConnect APs require a direct Layer 2 connection to the WLC at all times.
Why it's wrong here
FlexConnect APs can operate in standalone mode when the WLC is unreachable, so a permanent Layer 2 connection is not required; they use CAPWAP over routed links. It is tempting because local-mode APs need controller reachability, but FlexConnect is designed for WAN-separated branches; direct Layer 2 suits local-mode deployments.
- ✗
FlexConnect APs cannot support native VLAN tagging on the uplink interface.
Why it's wrong here
FlexConnect APs do support native VLAN tagging on the uplink, so this statement is false. It tempts candidates because FlexConnect's local switching model separates client VLANs from the AP management VLAN, which can suggest tagging is unsupported; in reality, native VLAN tagging is configured on the switch port for the AP's untagged management traffic.
Visual reference
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco AP Modes
Cisco AP Modes are different operational states a wireless access point can use, determining how it handles traffic, management, and security in a network.
Key term
VLAN Trunking
VLAN Trunking is a method to carry traffic for multiple VLANs over a single network link between switches or between a switch and a router.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.