Free 350-101 Practice Test Questions 2026

102 Questions


Last Updated On : 17-Aug-2026


Client Connectivity Configuration

Refer to the exhibit. A wireless controller is deployed at a branch location to facilitate guest client connectivity. A network engineer configures one WLAN using Web authentication and activates web-based method to align with company security policies. Which configuration enables client authentication for this WLAN?


A. security web-auth


B. wlan webauth 2 webauth


C. no security wpa wpa2


D. no security wpa akm dot1x





A.
  security web-auth

A network administrator at a marketing company manages a Cisco Catalyst 9800 Series Wireless Controller running Cisco IOS XE 17.x. The WLAN named XYZ-Guest is set up for visitors, and the administrator wants to implement a web authentication (WebAuth) portal using an external server to manage guest access. To ensure seamless and secure guest authentication, the controller must be configured to use an external WebAuth server for the WLAN. The administrator must configure the XYZ-Guest WLAN to use an external WebAuth server with a parameter map named webauth-ext. Which set of Cisco IOS XE commands must be used?


A. wireless wlan XYZ-Guestsecurity web-auth external webauth-ext


B. wireless wlan XYZ-Guest 2 XYZ-Guestparameter-map webauth-ext


C. wlan XYZ-Guest 2parameter external security-map webauth-ext


D. wlan XYZ-Guest 2 XYZ-Guestsecurity web-auth parameter-map webauth-ext





A.
  wireless wlan XYZ-Guestsecurity web-auth external webauth-ext

Refer to the exhibit. The Catalyst 9800 WLC logs show when a client with MAC address 9C:4E:36:8A:2B:F1 fails to connect to a WLAN configured for Wi-Fi Protected Access 3-Enterprise with 802.1X. Which action must the engineer take to resolve the issue?


A. Ensure that the AP is using the appropriate credentials.


B. Change the WLAN to Wi-Fi Protected Access 2-Personal and configure a preshared key.


C. Verify the client's Active Directory credentials and ensure that the RADIUS server is reachable.


D. Disable RADIUS NAC on the policy profile assigned to the WLAN.





C.
  Verify the client's Active Directory credentials and ensure that the RADIUS server is reachable.

A network engineer is integrating Cisco ISE with a wireless controller for 802.1X authentication. The controller is registered with Cisco ISE as a network device. To secure communication, the engineer must configure a shared secret for RADIUS authentication. Which CLI command on the WLC accomplishes this task?


A. 9800(config-radius-server)# radius enable authentication MySecretKey123


B. 9800(config-radius-server)# radius-server shared-secret MySecretKey123


C. 9800(config-radius-server)# ISE MySecretKey123


D. 9800(config-radius-server)# key 0 MySecretKey123





D.
  9800(config-radius-server)# key 0 MySecretKey123



Refer to the exhibit. A client authenticates via 802.1X against an ISE server that is configured to return a specific VLAN ID (VLAN 100) via an attribute value pair. However, the administrator notices that the client is placed in the wrong VLAN (VLAN 50). What must the administrator implement to resolve the issue?


A. Configure the policy profile to allow ISE to override the VLAN.


B. Configure VLAN 100 as an SVI on the WLC.


C. Configure VLAN 100 on the trunk ports of the WLC.


D. Configure AAA VLAN enable on the WLAN.





A.
  Configure the policy profile to allow ISE to override the VLAN.



Refer to the exhibit. A wireless controller is deployed at a branch location to facilitate secure client connectivity. A network engineer configures a WLAN using 802.1X to align with company security policies. Which configuration enables client authentication for this WLAN?


A. no ip mac-binding


B. security dot1x authentication-list ISE_GROUP


C. aaa override enable


D. wlan branch1 policy branch1_policy





B.
  security dot1x authentication-list ISE_GROUP

A network administrator at a marketing company is deploying a Cisco Catalyst 9800 Series Wireless Controller running Cisco IOS XE 17.x. The corporate WLAN named XYZ-Guest supports visitor devices. To address intermittent connectivity issues due to client association limits and short session timeouts, the network administrator must optimize the WLAN to allow more client connections and extend session timeouts for the devices. The administrator must set the maximum number of clients for the XYZ-Guest WLAN to 50 and must set a session timeout to prevent frequent device disconnections. Which two commands must be configured on the controller? (Choose two.)


A. wlan XYZ-Guest 1 XYZ-Guest client max-association 50


B. wireless profile policy XYZ-Guest-Pol client session timeout 2800


C. wlan XYZ-Guest 1 XYZ-Guest client session timeout 2800


D. wireless profile policy XYZ-Guest-Pol session timeout 2800


E. wlan XYZ-Guest 1 XYZ-Guest client association limit 50





C.
  wlan XYZ-Guest 1 XYZ-Guest client session timeout 2800

E.
  wlan XYZ-Guest 1 XYZ-Guest client association limit 50



A network administrator is working on a Cisco Catalyst 9800 WLC running Cisco IOS XE Software to enable user access for staff smartphones using WPA2-Enterprise with RADIUS. The administrator verifies the external authentication configuration and plans to test network connectivity. Which configuration command must be added to the box in the code to configure the WLC to support authentication with an external server?


A. security wpa enable


B. security dot1x authentication-list rad-group


C. security dot1x method-list rad-group


D. security wpa wpa2 akm dot1x





D.
  security wpa wpa2 akm dot1x

A retail store is setting up guest Wi-Fi on a Cisco 9800 WLC. The IT team has these requirements: When a guests associates, they are prompted for web authentication.
After login, traffic is restricted to internet-only access.
Guest WLAN must be available throughout all sales floors.
Guest WLAN must not impact the existing corporate WLAN.
Guest SSID must not require a password.
Which set of configurations must the IT team deploy to meet the requirements?


A. WPA2-Enterprise authentication on the guest WLAN and use dynamic VLAN assignment


B. Local web authentication on the guest SSID and apply ACLs to allow all traffic except FTP and SSH from the guest WLAN.


C. Central web authentication on the guest WLAN and apply an ACL that denies traffic between devices that use the internal subnets.


D. MAC filtering on the guest WLAN and enable client exclusion for segregation.





C.
  Central web authentication on the guest WLAN and apply an ACL that denies traffic between devices that use the internal subnets.

Which feature enables fast secure roaming in a wireless network?


A. DCA


B. 802.11r


C. 802.11ax


D. MIMO





B.
  802.11r



Refer to the exhibit. A network engineer must create a PSK WLAN that will be anchored to the DMZ. After this WLAN is created, users cannot connect to it. Based on the output from the RA trace, which action must the engineer take to resolve the issue?


A. Disable fast transition 802.11r on the WLAN.


B. Configure matching passwords on the client and the WLAN.


C. Remove the anchor WLC from the mobility group.


D. Configure matching WLANs on the foreign and the anchor.





B.
  Configure matching passwords on the client and the WLAN.

Exhibit:

Refer to the exhibit. An enterprise is deploying Cisco Catalyst 9800 WLCs and is using Catalyst Center as the management platform to oversee wireless access policies. To meet the organization's compliance requirements, all wireless endpoints must be evaluated with security posture validation before gaining access. Which set of CLI commands must be added to the box in the code to complete the configuration?


A. aaa-overridenac-policy


B. wireless profile policy my-policyaaa-override


C. aaa-overridenac


D. wireless profile policyaaa-override





C.
  aaa-overridenac


Page 3 out of 9 Pages
PreviousNext
234
350-101 Practice Test Home

What Makes Our Implementing and Operating Cisco Wireless Core Technologies (350-101 WLCOR)v1.0 Practice Test So Effective?

Real-World Scenario Mastery: Our 350-101 practice exam don't just test definitions. They present you with the same complex, scenario-based problems you'll encounter on the actual exam.

Strategic Weakness Identification: Each practice session reveals exactly where you stand. Discover which domains need more attention, before Implementing and Operating Cisco Wireless Core Technologies (350-101 WLCOR)v1.0 exam day arrives.

Confidence Through Familiarity: There's no substitute for knowing what to expect. When you've worked through our comprehensive 350-101 practice exam questions pool covering all topics, the real exam feels like just another practice session.