IT認証試験問題集
毎月、GOWUKAKUは1500人以上の受験者が試験準備を助けて、試験に合格するために受験者にご協力します
 ホームページ / 350-101 問題集  / 350-101 問題練習

Cisco 350-101 問題練習

Implementing and Operating Cisco Wireless Core Technologies (350-101 WLCOR)v1.0 試験

最新更新時間: 2026/09/21

【秋学習応援セール|10月限定キャンペーン】:350-101 最新真題を買う時、日本語版と英語版両方を同時に獲得できます。

実際の問題集を練習し、試験のポイントを了解し、テストに申し込むするかどうかを決めることができます。

さらに試験準備時間の35%を節約するには、350-101 問題集を使用してください。

 / 3

Question No : 1
Which wireless connection occurs when there are no physical obstacles between the receiver and transmitter?

正解:
Explanation:
The correct answer is line-of-sight. In RF terminology, line-of-sight describes a wireless path where the transmitting antenna and receiving antenna have an unobstructed visual or RF path between them. Cisco’s RF power documentation defines this directly: antennas that can see each other without obstacles between them are considered to be in line of sight. This is especially important in outdoor, bridge, mesh, and point-to-point wireless designs, where buildings, terrain, foliage, or other obstructions can degrade or block the RF path.
The other options describe different RF behaviors. Attenuation is signal loss as RF energy travels through free space, cables, walls, or other materials. Reflection occurs when RF energy bounces off a surface such as metal, glass, or concrete, often contributing to multipath. Beamforming is an antenna/transmission technique that focuses RF energy toward a client or receiver to improve signal quality; it is not the condition of having no obstacles. Cisco mesh planning guidance also emphasizes verifying whether a wireless link has clear line of sight before deployment, reinforcing that LOS is a path condition, not a modulation or security feature.
Reference topic: RF Fundamentals ― RF propagation, path loss, line-of-sight, obstruction effects, and wireless link planning.

Question No : 2
Refer to the exhibit.



An engineer is preparing a Cisco 9800-L WLC for deployment in a sensitive area. Only encrypted remote management via SSH is allowed, and all other VTY access methods must be disabled. The 9800-L WLC will be part of a larger deployment, and an external audit will check for any unencrypted management protocols. According to the requirements, only SSH is allowed for remote CLI sessions.
Which set of commands must be executed to complete the Cisco IOS XE CLI configuration on the WLC?

正解:
Explanation:
The correct configuration is option C because Cisco IOS XE restricts inbound protocols on VTY lines with the transport input command. Cisco’s Catalyst 9800 best-practice guidance states that administrators should confirm SSH is enabled and Telnet is disabled for better controller security, and that the Catalyst 9800 follows standard Cisco IOS XE behavior for enabling or disabling Telnet and SSH. Cisco IOS XE SSH documentation explicitly shows line vty line_number [ending_line_number] followed by transport input ssh, and explains that this prevents non-SSH Telnet connections, limiting access to SSH only.
The existing exhibit already includes the SSH prerequisites: hostname, domain name, RSA key generation, AAA new-model, a default login method using local credentials, and a local privileged user. The missing VTY configuration must therefore apply that default AAA login list to the VTY lines with login authentication default and restrict inbound transport to SSH. Cisco AAA documentation confirms that login authentication default applies the configured default authentication list to the line or set of lines.
Option A is incomplete and does not explicitly permit SSH.
Option B uses invalid syntax.
Option D omits the required input keyword.
Reference topics: Catalyst 9800 secure management, VTY access control, SSH, Telnet hardening, AAA login authentication, and IOS XE device administration.

Question No : 3
Which solution enables a seamless user experience when roaming in a wireless network?

正解:
Explanation:
Fast transition is the correct solution because it refers to IEEE 802.11r Fast BSS Transition, which reduces the authentication delay when a wireless client roams from one AP to another. Cisco describes 802.11r Fast Transition as a feature for seamless wireless roaming and states that, after configuration, the WLAN supports faster client roaming between access points. Cisco’s Catalyst 9800 roaming documentation also identifies 802.11r as the mechanism focused on seamless transition between APs, while 802.11k and 802.11v assist with neighbor reporting and network-assisted roaming decisions.
The core advantage is that key negotiation and authentication preparation occur before or during the roam, reducing the interruption experienced by latency-sensitive applications such as voice, video, collaboration tools, and real-time enterprise applications. Static VLAN policy only controls segmentation and does not accelerate roaming. Optimized roaming can help discourage sticky clients from remaining associated to poor-quality APs, but it is not the primary fast-roam authentication mechanism. A redundant RF profile is not an 802.11 roaming solution.
Reference topics: 802.11r Fast BSS Transition, client roaming, WLAN mobility behavior, Catalyst 9800 WLAN security, and seamless roaming design.

Question No : 4
A network engineer must ensure that guest users connecting to a Cisco 9800 WLC are assigned IP addresses from a specific subnet that is separate from corporate users. The guest network must support at least 200 simultaneous connections and isolate traffic from internal devices. The DHCP server must allocate addresses only within the 10.20.30.0/24 subnet.
Which action must the network engineer take to accomplish this task?

正解:
Explanation:
The correct action is to create a dedicated guest interface/VLAN and bind it to the guest WLAN through the Catalyst 9800 policy profile. In Catalyst 9800 architecture, the WLAN defines the SSID and wireless security parameters, while the policy profile defines client forwarding policy, VLAN mapping, DHCP-related behavior, and access policy. Cisco’s Catalyst 9800 VLAN configuration procedure places the VLAN selection under the Policy Profile > Access Policies section, where a VLAN or VLAN group is mapped to the WLAN policy profile. Cisco also documents that DHCP can be configured per interface or per WLAN and recommends using the DHCP server address assigned to the relevant interface for WLAN client addressing.
A dedicated guest VLAN backed by the 10.20.30.0/24 DHCP scope provides up to 254 usable addresses, satisfying the 200-client requirement while keeping guest users separated from corporate users at Layer 3/VLAN boundaries.
Option A and C are wrong because a shared DHCP pool violates the requirement for a guest-only subnet; DHCP option 43 is for AP/controller discovery, not client addressing.
Option D is not scalable and does not define DHCP allocation.
Reference topics: Catalyst 9800 policy profiles, WLAN-to-policy mapping, guest VLAN segmentation, DHCP scopes, and guest network isolation.

Question No : 5
Refer to the exhibit.



A Cisco 9800 WLC is deployed at a branch location to facilitate secure client connectivity. A network engineer configures a WLAN using WPA2 Enterprise authentication and activates the RADIUS server-based method to align with company security policies.
Which CLI command must be added to the box in the configuration to enable client authentication for this WLAN?

正解:
Explanation:
The correct command is security dot1x authentication-list RADIUS_AUTH_LIST. On a Catalyst 9800 WLC, the WLAN configuration must bind the WLAN’s 802.1X authentication process to an AAA authentication method list. Cisco’s Catalyst 9800 802.1X configuration workflow shows the WLAN entered with wlan <profile-name> <wlan-id> <ssid-name>, followed by the command security dot1x authentication-list <dot1x-list-name>. Cisco configuration guide examples also show the same syntax under WLAN configuration mode as Device(config-wlan)# security dot1x authentication-list auth-list-name.
In the exhibit, security wpa akm dot1x enables 802.1X as the key-management method, while security wpa wpa2 and security wpa wpa2 ciphers aes establish WPA2/AES security. These statements define the WLAN security framework, but they do not identify which AAA method list will be used to reach the RADIUS backend. The missing command must therefore attach the named authentication list RADIUS_AUTH_LIST to dot1x authentication.
Options A, B, and C are parser-invalid or incorrectly ordered IOS XE syntax.
Reference topic: Client Connectivity Configuration ― WPA2-Enterprise WLAN configuration, 802.1X authentication, AAA method lists, RADIUS-backed client access, and Catalyst 9800 WLAN security commands.

Question No : 6
An engineer has been tasked with configuring a Cisco Catalyst 9100 AP to join a WLC using a static configuration as DHCP and DNS discovery methods are not available. The engineer has set the AP hostname to ‘AP053540555’, and has configured the AP with a static IP address, subnet mask, and default gateway. The engineer must now configure the AP to discover the primary WLC with hostname ‘WLC-PRIMARY’ and IP address ‘192.168.100.10’.
Which CLI command must the engineer use on the AP?

正解:
Explanation:
The correct AP-side command is capwap ap primary-base WLC-PRIMARY 192.168.100.10. Cisco’s Catalyst AP command reference shows the syntax for configuring the primary controller as capwap ap primary-base <controller-name> <controller-ip-address>, and provides the same structure in its example: capwap ap primary-base wlc-5520 209.165.200.224. Cisco’s Catalyst 9800 AP join documentation also identifies the primary controller discovery entry as capwap ap primary-base <wlc-hostname> <wlc-IP-address>.
This command statically primes the lightweight AP with the preferred WLC when DHCP option 43, DNS discovery, broadcast discovery, or prior learned controller information is unavailable. The hostname AP053540555 is only the AP’s local identity and is not part of the WLC discovery command.
Option A omits the primary-base keyword, so it is not valid syntax.
Option B places keywords in the wrong order and does not match Cisco CAPWAP AP CLI.
Option C omits the required controller name before the IP address.
Reference topics: Wireless Network Implementation ― CAPWAP discovery, AP priming, Catalyst 9100 AP onboarding, static WLC discovery, and Catalyst 9800 AP join process.

Question No : 7
What is a feature of an RTS frame in the context of 802.11 frame types?

正解:
Explanation:
An RTS frame is an 802.11 control frame used in the Request to Send/Clear to Send exchange. Cisco identifies RTS as a Request to Send frame and explains that 802.11 control frames assist in delivering data frames between stations. Cisco further states that the RTS/CTS function is optional, helps reduce collisions when hidden stations are associated to the same access point, and that a station sends an RTS frame as the first phase before transmitting a data frame.
Therefore, option B is correct because the RTS frame requests access to the wireless medium before data transmission. If the receiving station or AP replies with CTS, nearby stations defer transmission based on the duration information, reducing collision probability. This is especially relevant in hidden-node environments where two clients can hear the AP but cannot hear each other.
Option A refers to RF spectral-mask compliance, which is a physical-layer regulatory concept.
Option C confuses NAV behavior with roaming; RTS/CTS may influence virtual carrier sensing, not client roaming updates.
Option D is unrelated because frame compression is not an RTS function.
Reference topics: 802.11 frame types, control frames, RTS/CTS, CSMA/CA, hidden-node mitigation, and medium reservation.

Question No : 8
Refer to the exhibit.



An enterprise is deploying Cisco Catalyst 9800 WLCs and is using Catalyst Center as the management platform to oversee wireless access policies. To meet the organization's compliance requirements, all wireless endpoints must be evaluated with security posture validation before gaining access.
Which set of CLI commands must be added to the box in the code to complete the configuration?

正解:
Explanation:
The correct configuration is aaa-override followed by nac under the existing Catalyst 9800 wireless policy profile. The exhibit already places the administrator in policy-profile configuration mode with wireless profile policy my-policy, so the missing commands must be policy-profile subcommands, not another profile declaration. Cisco’s Catalyst 9800 configuration examples show the exact sequence: enter wireless profile policy <policy-profile-name>, enable aaa-override, enable nac, then configure VLAN and no shutdown.
aaa-override permits authorization attributes returned by AAA or Cisco ISE, such as VLAN, ACL, QoS, redirect ACL, or posture-related access controls, to override the locally defined policy. Cisco’s documentation explicitly states that AAA override applies policies coming from AAA or ISE servers, while nac enables Network Access Control in the policy profile. This is the required behavior when endpoints must be posture-validated before normal network access is granted. Cisco also notes that NAC State is enabled in the policy profile and can only be enabled when AAA override is enabled.
Option A is invalid because nac-policy is not the correct CLI keyword.
Options B and D omit NAC.
Reference topic: Client Connectivity Configuration ― Catalyst 9800 policy profiles, AAA override, NAC State, posture enforcement, and ISE-based access control.

Question No : 9
An organization must manage ongoing firmware updates for redundant controllers in the network. They will use Cisco Catalyst Center for deployment and visibility. The current environment uses centralized and distributed management approaches. Automation and reporting are critical to minimize operational workload.
Which method must be used to manage structured update processes and monitor progress throughout the update cycle?

正解:
Explanation:
The correct method is software image management workflows, specifically Cisco Catalyst Center Software Image Management, commonly referenced as SWIM. Cisco documents SWIM as the mechanism used to manage software upgrades and maintain consistency of image versions across the network. It provides an image repository, golden-image assignment, image distribution, activation, readiness checks, and scheduled execution. Cisco’s wireless automation guidance specifically states that SWIM is used to update Catalyst 9800 Series Wireless Controller software by distributing the image from the Catalyst Center repository to wireless controllers and upgrading the images running on those controllers; both stages can run immediately or be scheduled for a defined maintenance window.
Option C is also validated by Catalyst Center’s update-status and workflow views. Cisco documents Image Update Status as the view that shows all update tasks, filters by in-progress, success, or failure, and displays a progress bar for active updates. The workflow view then exposes distribution and activation task status, timing, prechecks, postchecks, checksum verification, and AP pre-image download details. Inventory snapshots and templates do not execute controller firmware upgrades, and “lifecycle workflow” is too generic.
Reference topics: Wireless Monitoring and Management ― Catalyst Center SWIM, image compliance, golden images, controller upgrade automation, and update progress reporting.

Question No : 10
What is the primary modulation technology used by 802.11ax in wireless communications?

正解:
Explanation:
The correct answer is orthogonal frequency-division multiple access, or OFDMA. Cisco identifies 802.11ax, also known as Wi-Fi 6, as the generation that introduces OFDMA-based operation to improve efficiency, especially in dense wireless environments. Cisco’s Catalyst 9800 documentation states that OFDMA support for 802.11ax APs improves performance in dense deployments, enables simultaneous data transmissions with OFDMA and MU-MIMO, and supports uplink and downlink multi-user operations across multiple client devices.
Strictly, OFDMA is a multi-user channel-access and subcarrier allocation method rather than a pure constellation modulation scheme. However, within 802.11ax fundamentals and this answer set, OFDMA is the defining PHY/MAC technology. It divides a 20, 40, 80, or 160 MHz channel into smaller resource units so multiple clients can transmit or receive in the same transmission opportunity. Cisco further explains that OFDMA improves wireless performance by using independently modulated subcarriers within frequencies, allowing simultaneous transmissions to and from multiple clients. FHSS and DSSS belong to older 802.11 PHY generations. QAM is used for symbol modulation, but “Quadrature Amplitude Modulation OFDMA” is not the primary 802.11ax technology name.
Reference topics: 802.11ax/Wi-Fi 6, OFDMA, resource units, uplink/downlink multi-user operation, and high-efficiency WLAN design.

Question No : 11
Which process is managed by Ministry of Internal Affairs and Communications in Japan?

正解:
Explanation:
The correct answer is RF technical standards. In Japan, wireless LAN and other radio equipment must operate under national RF regulatory requirements controlled by the Ministry of Internal Affairs and Communications, commonly referenced as MIC. TELEC, a registered certification body in Japan, states that specified radio equipment such as wireless LAN equipment used in Japan must conform to technical regulations regulated by MIC, and that radio equipment conformity certification validates conformance to the technical standards under Japan’s Radio Act.
This aligns directly with Cisco wireless regulatory-domain behavior. Cisco’s Catalyst 9800 country-code documentation explains that APs use legal frequencies approved for their regulatory domain, and for Japan regulatory-domain devices, Japan country codes must be configured so the controller and APs operate within permitted channel and power constraints. Cisco also states that country codes are assigned and verified on APs or wireless controllers to ensure regulatory compliance for wireless operation. Manufacturing batch inspection, customer onboarding, and supplier-chain evaluation are not RF spectrum regulatory functions.
Reference topics: RF Fundamentals ― regulatory domains, country codes, channel legality, transmit-power limits, and wireless compliance.

Question No : 12
Which feature does a high-gain patch antenna impart to a wireless signal?

正解:
Explanation:
A high-gain patch antenna is a directional antenna that concentrates RF energy into a defined coverage area rather than radiating equally in all directions. Cisco’s Wireless RF Reference Guide explains that antenna gain determines how RF power is radiated and that higher-gain antennas do not create additional transmit power; they focus existing power in a given direction. Cisco also distinguishes omnidirectional high-gain patterns, which flatten coverage, from directional antennas, which focus energy toward a target area.
That makes option C correct: a patch antenna imparts a focused beam, typically useful for covering a hallway, warehouse aisle, seating section, point-to-point link, or defined flat service area. Cisco’s antenna documentation also states that higher-gain antennas provide longer coverage distance but with a coverage-area tradeoff, especially in a particular direction.
Option A is incorrect because antenna gain does not restrict operation to a single narrow frequency; frequency support is determined by antenna design and radio band.
Option B describes channel overlap, not antenna behavior.
Option D does not describe a standard patch antenna radiation pattern.
Reference topics: RF Fundamentals ― antenna gain, directional antennas, patch antenna radiation patterns, beamwidth, and coverage-cell design.

Question No : 13
Users report slowness on the network, and it is suspected that certain applications are consuming all the bandwidth. A network engineer must enable the NBAR protocol to improve wireless client traffic visibility and provide advanced, granular, application classification, and analytics.
How should the network engineer configure NBAR on a 9800 WLC?

正解:
Explanation:
The correct configuration approach is to enable Application Visibility and Control on the policy profile. On the Catalyst 9800, WLANs are not configured as isolated monolithic objects; the WLAN profile is mapped to a policy profile through a policy tag, and many client traffic services are applied from that policy profile. Cisco defines AVC as the wireless feature set that identifies and monitors applications using DPI, creates rules to manage application bandwidth and usage, and integrates with Flexible NetFlow for per-application or per-protocol statistics. Cisco further states that AVC benefits from NBAR running on the AP or controller, and that the NBAR2 engine analyzes and recognizes traffic flows.
Operationally, Cisco’s 9800 AVC guide shows that AVC is enabled by navigating to Configuration > Services > Application Visibility and selecting the relevant Policy Profile. It also shows the CLI form under the policy profile: wireless profile policy AVC_testing followed by ip nbar protocol-discovery, with verification showing NBAR Protocol Discovery: Enabled.
Options A and B are incorrect because the feature is not enabled directly on the WLAN.
Option C is generic and incomplete; the Cisco feature construct is AVC.
Reference topics: AVC, NBAR2, Flexible NetFlow, Catalyst 9800 policy profiles, and wireless application visibility.

Question No : 14
Which benefit does enabling SNMP monitoring provide for Cisco wireless device management?

正解:
Explanation:
SNMP monitoring provides centralized visibility and event notification for Cisco wireless infrastructure. On Cisco Catalyst 9800 wireless controllers, SNMP traps are used to send alert messages from SNMP-enabled devices to an SNMP manager, and Cisco specifically documents wireless trap support for access points, clients, mesh, RF, rogue, mobility, RRM, and controller events. Cisco also states that AP-related traps such as crash, register, and no-radio-card events are enabled by default, and that configuring AP traps helps monitor AP status and troubleshoot issues.
Therefore, the direct operational benefit is alerts on access point status. SNMP is not limited to hardware-only metrics; it can expose client counts, joined AP counts, processor usage, memory usage, and wireless event notifications through supported OIDs and traps. Manual log review is the opposite of SNMP’s purpose because traps automate notification to a network management system. Fragmented statistics are also incorrect because SNMP enables centralized polling and trap collection across managed devices.
Reference topics: Wireless Monitoring and Management ― SNMP, MIB/OID monitoring, Catalyst 9800 wireless traps, AP status monitoring, and NMS integration.

Question No : 15
Refer to the exhibit.



A network administrator is working on a WLC to enable user access for employee tablets using PEAP-MSCHAPv2 with a RADIUS backend. The administrator verifies the external authentication configuration and plans to test network connectivity.
Which code snippet must be added to the configuration for the WLC to support authentication with an external server?

正解:
Explanation:
The missing command is radius server external-radius. On a Catalyst 9800 WLC, the external RADIUS server object must be declared first with radius server <server-name>. The following lines, address ipv4 10.10.10.100 auth-port 1812 acct-port 1813 and key radiuskey, are subcommands entered under that RADIUS server configuration mode. Cisco’s Catalyst 9800 802.1X configuration workflow starts by declaring the RADIUS server, then adding it to a RADIUS server group, then creating the authentication method list, and finally mapping that list to the WLAN. Cisco’s configuration guide example uses the same IOS XE structure: radius server <name>, followed by address ipv4 ... auth-port 1812 acct-port 1813 and key ....
The server group later references server name external-radius, so the RADIUS server object must be named external-radius exactly.
Option C would incorrectly create a server named RADIUS-GRP, which is already the AAA server group name, not the RADIUS server object.
Options B and D are invalid IOS XE syntax. PEAP-MSCHAPv2 itself is handled through the 802.1X/EAP exchange with the RADIUS server; the WLC acts as the authenticator and forwards authentication requests through the configured AAA method list.
Reference topic: Client Connectivity Configuration ― WPA2-Enterprise, 802.1X, RADIUS server objects, AAA groups, and WLAN authentication-list binding.

 / 3