- 4.9/5.0
- 282 Questions
- Updated on: 27-Aug-2026
- Designing Cisco Enterprise Wireless Networks (ENWLSD)
- 22825 Prepared
Free Cisco 300-425 Practice Questions 2026 | Designing Cisco Enterprise Wireless Networks (ENWLSD)
A network engineer needs to create a wireless design to bridge wired IP surveillance cameras in the parking lot through a mesh AP. To which operate mode of the AP should the cameras connect?
A. Flexconnect
B. MAP
C. RAP
D. Local
Explanation:
Key Requirements:
Bridging wired IP cameras in a parking lot via a mesh AP.
The cameras are wired devices, so they must connect to an AP’s Ethernet port.
Why MAP (Option B) is Correct:
MAPs (Mesh Access Points) are designed to provide wired connectivity in a mesh network:
They extend the network by connecting to a RAP (Root AP) wirelessly.
Their Ethernet ports can bridge wired devices (like cameras) back to the network.
RAPs (Option C) typically connect to the wired LAN and do not host wired clients.
Why Other Options Are Incorrect:
Option A (FlexConnect): AP mode for branch office tunneling, not mesh bridging.
Option C (RAP): Root APs uplink to the wired network—they don’t host downstream wired clients.
Option D (Local): Refers to client-serving mode, not bridging.
Reference:
Cisco Outdoor Mesh Deployment Guide: States that MAPs provide wired bridging for devices like cameras.
Cisco 1560 Series Mesh AP Datasheet: Confirms Ethernet bridging support on MAPs.
An engineer is designing an outdoor mesh network to cover several sports fields. The core of the network is located in a building at the entrance of a sports complex. Which type of antenna should be used with the RAP for backhaul connectivity?
A. 5 GHz. 8-dBi omnidirectional antenna
B. 2.4 GHz. 8-dBi patch antenna
C. 2.4 GHz. 14-dBi omnidirectional antenna
D. 5 GHz. 14-DBi patch antenna
Explanation:
Key Requirements for the Outdoor Mesh Backhaul:
Sports Field Coverage:
Requires focused, high-gain backhaul links to reach distant MAPs (Mesh Access Points).
Core Location:
The RAP (Root AP) is in a building at the entrance, so it needs directional antennas to target specific fields.
Why Option D is Correct:
5 GHz Band:
Less interference than 2.4 GHz (critical for reliable backhaul).
More non-overlapping channels (e.g., UNII-1/2/3 bands).
14-dBi Patch Antenna:
Directional (focuses signal toward sports fields, reducing wasted energy).
High gain extends range while maintaining link quality.
Why Other Options Are Incorrect:
Option A (5 GHz Omni):
Omnidirectional antennas waste power broadcasting in all directions (unsuitable for targeted backhaul).
Option B (2.4 GHz Patch):
2.4 GHz is congested (poor for high-capacity backhaul).
8 dBi is too low for long-range sports field coverage.
Option C (2.4 GHz Omni):
Omnidirectional + 2.4 GHz = Worst choice (interference + unfocused coverage).
Reference:
Cisco Outdoor Mesh Antenna Guide: Recommends 5 GHz directional antennas for backhaul.
A wireless engineer must design a backhaul link. The engineer has a mesh access point that has a wired connection back to the infrastructure. What must be changed in the AP role before a change is made in the AP mode?
A. monitor
B. RAP
C. bridge
D. local
Explanation:
Key Scenario:
A mesh AP has a wired connection back to the infrastructure (i.e., it is the root of the mesh network).
Before changing the AP mode (e.g., from local to bridge), the AP role must first be set to RAP.
Why RAP (Option B) is Correct:
AP Role vs. AP Mode:
Role: Defines the AP’s function in the mesh (RAP, MAP).
Mode: Defines how clients connect (local, flex, bridge).
Design Workflow:
Step 1: Set the AP role to RAP (since it’s the root wired node).
Step 2: Configure the mode (e.g., bridge for wired clients).
Why Other Options Are Incorrect
Option A (Monitor): A passive scanning role, unrelated to mesh.
Option C (Bridge): An AP mode, not a role (cannot be set before role).
Option D (Local): An AP mode for client serving, not a role.
Reference:
Cisco Mesh Deployment Guide: States that RAP role must be assigned first before mode changes.
Cisco 1560 Series AP Configuration: Requires role configuration before mode.
What is the wireless signal loss of large cases of liquid materials being stored in a warehouse environment?
A. It is higher than dry goods.
B. It is not impactful to the RF design.
C. It is less than dry goods.
D. It is impactful but overall negligible to the RF design.
Explanation:
Key Concept:
Liquid materials (e.g., water, chemicals) absorb and scatter RF signals more than dry goods (e.g., boxes, wood, plastic).
Water, in particular, has a high dielectric constant, causing significant signal attenuation.
Large cases of liquids act like RF barriers, weakening Wi-Fi signals passing through them.
Why Option A is Correct:
Higher signal loss: Liquids cause 3–20 dB+ attenuation depending on density (vs. dry goods at ~3–6 dB).
Impact on RF Design:
Requires more APs or higher power to penetrate liquid-storage areas.
Cisco’s warehouse design guides explicitly account for liquid-induced attenuation.
Why Other Options Are Incorrect:
Option B (Not impactful): Incorrect. Liquids do impact RF (verified in real-world deployments).
Option C (Less than dry goods): Opposite of reality. Liquids attenuate more.
Option D (Impactful but negligible): Contradictory. If impactful, it’s not negligible in design.
Reference:
Cisco Warehouse Wireless Design Guide: Recommends additional APs near liquid storage.
An engineer is designing a network deployment for a college with six buildings Each building must have a WLC located in the IDF to support the APs. The wireless clients should be able to roam between the APs and the controllers. Which type of wireless architecture should be used?
A. Distributed
B. Centralized
C. Cloud
D. Autonomous
Explanation:
Key Requirements:
Six buildings, each with a WLC in the IDF (Intermediate Distribution Frame).
Seamless roaming between APs and controllers across buildings.
Why Distributed Architecture (Option A) is Correct:
Local Controllers in Each Building:
A distributed architecture places a WLC in each building’s IDF, optimizing local traffic handling and reducing latency.
Mobility Domain Roaming:
Controllers are grouped into a mobility group, allowing clients to roam seamlessly between APs on different WLCs.
Scalability and Redundancy:
If one WLC fails, only one building is affected (vs. centralized, where all buildings rely on a single WLC).
Why Other Options Are Incorrect:
Option B (Centralized):
All APs connect to a single central WLC, which is not scalable for six buildings and introduces a single point of failure
.
Option C (Cloud):
Cloud controllers (e.g., Meraki) don’t align with the requirement for on-premises WLCs in IDFs.
Option D (Autonomous):
Autonomous APs operate independently (no WLC), making roaming and centralized management impossible.
Reference:
Cisco Campus Wireless Design Guide: Recommends distributed WLCs for multi-building deployments.
Cisco Mobility Groups Documentation: Explains how controllers share client sessions for roaming.
A university is in the process of designing a wireless network in an auditorium that seats 500 students and supports student laptops. Which design methodology should the university implement in the auditorium?
A. roaming design model
B. voice design model
C. location design model
D. high-density design model
Explanation:
Key Requirements:
Auditorium with 500+ students (ultra-high client density).
Support for laptops (implying concurrent data, video, and possibly VoIP traffic).
Why High-Density Design (Option D) is Correct:
AP Placement and Cell Sizing:
Smaller cells (more APs with lower transmit power) to avoid co-channel interference.
Typical density: 1 AP per 50–100 users (e.g., 5–10 APs for 500 seats).
Channel Planning:
Use 5 GHz exclusively (more non-overlapping channels than 2.4 GHz).
20 MHz channels (not 40/80 MHz) to maximize channel reuse.
Client Load Balancing:
Band steering (push clients to 5 GHz) and Airtime Fairness to prevent slow clients from hogging airtime.
Why Other Options Are Incorrect:
Option A (Roaming Design): Focuses on mobility (e.g., hallways), not static high-density seating.
Option B (Voice Design): Optimized for low-latency VoIP, not mass data traffic.
Option C (Location Design): For RTLS/asset tracking, not capacity.
Reference:
Cisco High-Density Design Guide: Recommends 1 AP per 75 users in lecture halls.
The wireless team must configure a new voice SSID for optimized roaming across multiple WLCs with Cisco 8821 phones. Which two settings accomplish this goal? (Choose two.)
A. Configure mobility groups between WLCs.
B. Use Cisco Centralized Key Management for authentication.
C. Configure AP groups between WLCs.
D. Configure AVC profile on new SSID.
E. Use AVC to tag traffic voice traffic as best effort.
B. Use Cisco Centralized Key Management for authentication.
Explanation:
Key Requirements:
Voice SSID for Cisco 8821 phones (VoWLAN).
Optimized roaming across multiple WLCs.
Solution 1: Mobility Groups (Option A)
Why?
Mobility groups allow WLCs to share client state information, enabling seamless roaming between controllers.
Without this, phones would reauthenticate when moving between WLCs, causing call drops.
Reference:
Cisco Wireless LAN Controller Configuration Guide: "Mobility groups are required for inter-controller roaming."
Solution 2: Cisco Centralized Key Management (CCKM) (Option B)
Why?
CCKM enables fast secure roaming (802.11r-like behavior) for Cisco phones.
Reduces reauthentication time from ~500 ms to sub-50 ms, critical for voice.
Reference:
Cisco VoWLAN Design Guide: "CCKM is recommended for Cisco 8821/8845 phones."
Why Other Options Are Incorrect:
Option C (AP Groups): AP groups are for local AP organization, not roaming.
Option D (AVC Profile): AVC is for application visibility, not roaming optimization.
Option E (AVC for Best Effort): Voice traffic must be tagged as Platinum (Voice), not Best Effort.
An engineer must design and configure a wireless network for: • pervasive coverage in an oil terminal • casual web and email traffic • 5 GHz What is the best design?
A. Keep the power assignment as auto and disable 802.11n and 802.11ac MCS rate.
B. Disable all data rates below 24 Mbps and keep the power assignment on the AP as auto.
C. Keep all the data rates enabled and set the AP power assignment mode to auto.
D. Disable all data rates below 54 Mbps and assign static power level 1 on all access points.
Explanation:
Why Option B is Correct?
Pervasive Coverage Requirement:
The oil terminal requires consistent coverage, meaning APs should provide a strong signal without excessive overlap.
Auto power assignment allows APs to dynamically adjust transmit power for optimal coverage and minimal interference.
Casual Web & Email Traffic (Low Bandwidth Needs):
Since the traffic is light (web/email), disabling low data rates (below 24 Mbps) improves efficiency by:
Reducing airtime usage (slow clients consume more airtime).
Encouraging clients to connect at higher rates, improving overall network performance.
5 GHz Band Optimization:
5 GHz has less interference and more channels than 2.4 GHz.
Disabling very low rates (e.g., 6, 9, 12, 18 Mbps) ensures clients don’t linger on inefficient connections
Why Other Options Are Incorrect?
Option A: Keep power auto, disable 802.11n/ac MCS rates
Disabling MCS rates (Modulation and Coding Scheme) hurts performance because 802.11n/ac rely on MCS for high-speed transmissions.
Unnecessary for casual traffic and would reduce efficiency in a 5 GHz network.
Option C: Keep all data rates enabled, power auto
Keeping all data rates enabled allows slow clients to connect at low speeds (e.g., 6 Mbps), wasting airtime and degrading performance.
Not optimal for pervasive coverage because slow clients can cause congestion.
Option D: Disable rates below 54 Mbps, static power level 1
Disabling below 54 Mbps is too aggressive—some clients may struggle to connect, especially at the edge of coverage.
Static power level 1 (lowest power) reduces coverage range, which contradicts the pervasive coverage requirement.
Reference:
Cisco Wireless LAN Design Best Practices recommends disabling low data rates for efficiency
Cisco’s High-Density Design Guide suggests auto power adjustment for balanced coverage.
An enterprise network administrator is asked to set up an experimental WLAN for a collaboration project with a local service provider. The WLAN must be anchored to a WLC in the service provider data center using legacy mobility mode. After the configurations are completed on the WLCs and the firewalls in the path, the data path mobility tunnel is failing to come up. What should be performed by the administrator to debug the issue?
A. Establish a Telnet connection from a local PC to the firewall on port 97.
B. Use the mapping command on the WL
C. Establish a Telnet connection from a local PC to the firewall on port 16666.
D. Use the mapping command on the WL
Explanation:
Why Option D is Correct?
Legacy Mobility Tunnel Issue:
In legacy mobility mode, the mobility tunnel between the enterprise WLC and service provider WLC uses UDP port 16666 (by default).
If the tunnel fails, the mapping command on the WLC helps debug the issue by:
Verifying mobility group peers.
Checking if UDP 16666 is reachable between WLCs.
Identifying firewall blocking issues.
Key Debugging Steps:
Run show mobility summary to check mobility peers.
Use mapping
Verify firewall rules allow bidirectional UDP 16666 traffic.
Why Other Options Are Incorrect?
Option A: Telnet to firewall on port 97
Port 97 is irrelevant to mobility tunnels.
Mobility tunnels use UDP 16666, not TCP 97.
Option B: Use the mapping command on the WLC (Incomplete Option)
This seems similar to Option D but is cut off, making it invalid.
Option C: Telnet to firewall on port 16666
Telnet uses TCP, but mobility tunnels use UDP 16666.
A Telnet test won’t verify UDP connectivity (must use mapping or ping with UDP checks).
Reference:
Cisco Wireless LAN Controller Configuration Guide, "Mobility Groups"
Mobility tunnels require UDP 16666 (default) between WLCs
The mapping command tests tunnel reachability.
Firewall Requirements for Mobility:
Must allow UDP 16666 in both directions.
Refer to the exhibit. An enterprise is using wireless as the main network connectivity for clients. To ensure service continuity. a pair of controllers will be installed in a datacentre. An engineer is designing SSO on the pair of controllers. What needs to be included in the design to avoid having the secondary controller go into maintenance mode?
A. The Keep alive timer is too low. which causes synchronization problems.
B. The connection between the redundancy ports is missing.
C. The redundancy port must be the same subnet as the redundancy mgmt.
D. The Global Configuration of SSO is set to Disabled on the controller.
Explanation:
Why Option B is Correct?
SSO (Stateful Switchover) Requirements:
For SSO to work properly, the primary and secondary WLCs must be connected via their redundancy ports (typically a direct cable or VLAN).
If this connection is missing or broken, the secondary WLC cannot synchronize with the primary and will go into maintenance mode (failing to take over if the primary fails).
Impact of Missing Redundancy Link:
Without the redundancy port connection:
Heartbeat messages fail, causing the secondary to lose sync.
The secondary WLC cannot receive real-time state updates from the primary.
The system defaults to maintenance mode instead of staying in hot standby.
Why Other Options Are Incorrect?
Option A: Keepalive timer is too low
While a misconfigured keepalive timer can cause synchronization issues, it does not force the secondary into maintenance mode—it may just cause flapping.
The main issue is the physical/logical redundancy link.
Option C: Redundancy port must be in the same subnet as redundancy management
This is not a strict requirement for SSO.
The redundancy port can be on a different subnet as long as routing is properly configured (though Cisco recommends direct connection for reliability).
Option D: Global Configuration of SSO is set to Disabled
If SSO is disabled, the secondary WLC would not even attempt synchronization—it would operate as a standalone controller, not go into maintenance mode.
Reference:
Cisco Wireless LAN Controller High Availability Guide
SSO requires a redundancy port connection (direct or via a dedicated VLAN).
Without it, the secondary WLC cannot maintain state sync and enters maintenance mode.
Cisco Best Practices for SSO:
Use a dedicated, low-latency link for redundancy ports.
| Page 9 out of 29 Pages |