SRWE MODULE 10–13 CHECKPOINT EXAM | COMPLETE PRACTICE QUESTIONS,
ANSWERS & STUDY GUIDE 2026/2027
Which step is required before creating a new WLAN on a Cisco 3500 series WLC?
Create a new SSID
Build or have an SNMP server available
Create a new VLAN interface
Build or have a RADIUS server available - ANS ✔✔Create a new VLAN interface
The company handbook states that employees cannot have microwave ovens in their offices. Instead, all
employees must use the microwave ovens located in employee cafeteria. What wireless security risk is
the company trying to avoid?
Interception of data
Accidental interference
improperly configured devices
Rogue access points - ANS ✔✔Accidental interference
Which protocol should be used to mitigate the vulnerability of using Telnet to remotely manage network
devices?
SNMP
TFTP
SSH
SCP - ANS ✔✔SSH
What are three techniques for mitigating VLAN attacks (choose three)
Enable trunking manually
Enable Source Guard
Disable DTP
Use private VLANs
Enable BPDU guard
Set the native VLAN to an unused VLAN - ANS ✔✔Enable trunking manually, Disable DTP, Set the native
VLAN to an unused VLAN
a network administrator of a college is configuring the WLAN user authentication process. Wireless users
are required to enter username and password credentials that will be verified by a server. Which server
would provide such service?
SNMP
AAA
RADIUS
, NAT - ANS ✔✔RADIUS
What represents a best practice concerning discovery protocols such as CDP and LLDP on network
devices?
Use the open standard LLDP rather than CDP
Enable CDP on edge devices and enable LLDP on interior devices
Use the default router setting for CDP and LLDP
Disable both protocols on all interfaces where they are not required - ANS ✔✔Disable both protocols on
all interfaces where they are not required
What is an advantage of SSID cloaking?
It is the best way to secure a wireless network
It provides free internet access in public locations where knowing the SSID is of no concern
SSIDs are very difficult to discover because APs do not broadcast them
Clients will have to manually identify the SSID to connect to the network - ANS ✔✔Clients will have to
manually identify the SSID to connect to the network
Match each functional component of AAA with its description
1. Authentication
2. Accounting
3. Authorization
A. Determines what resources users can access or the operations they are allowed to perform
B. Proves that users are who they say they are
C. Records what users do and what they access - ANS ✔✔1=B, 2=C, 3=A
What is the function provided by CAPWAP protocol in a corporate wireless network?
CAPWAP provides the encapsulation and forwarding of wireless user traffic between an access point and
a wireless LAN controller
CAPWAP provides the encryption of wireless user traffic between an access point and a wireless client
CAPWAP provides connectivity between an access point using IPv6 addressing and a wireless client using
IPv4 addressing
CAPWAP creates a tunnel on TCP ports in order to allow a WLC to configure an autonomous access point
- ANS ✔✔CAPWAP provides the encapsulation and forwarding of wireless user traffic between an access
point and a wireless LAN controller
As part of the new security policy, all switches on the network are configured to automatically learn MAC
addresses for each port. All running configurations are saved at the start and close of every business day.
A severe thunderstorm causes an extended power outage several hours after the close of business.
When the switches are brought back online, the dynamically learned MAC addresses are retained. Which
port security configuration enabled this?
Sticky secure MAC addresses
Static secure MAC addresses
ANSWERS & STUDY GUIDE 2026/2027
Which step is required before creating a new WLAN on a Cisco 3500 series WLC?
Create a new SSID
Build or have an SNMP server available
Create a new VLAN interface
Build or have a RADIUS server available - ANS ✔✔Create a new VLAN interface
The company handbook states that employees cannot have microwave ovens in their offices. Instead, all
employees must use the microwave ovens located in employee cafeteria. What wireless security risk is
the company trying to avoid?
Interception of data
Accidental interference
improperly configured devices
Rogue access points - ANS ✔✔Accidental interference
Which protocol should be used to mitigate the vulnerability of using Telnet to remotely manage network
devices?
SNMP
TFTP
SSH
SCP - ANS ✔✔SSH
What are three techniques for mitigating VLAN attacks (choose three)
Enable trunking manually
Enable Source Guard
Disable DTP
Use private VLANs
Enable BPDU guard
Set the native VLAN to an unused VLAN - ANS ✔✔Enable trunking manually, Disable DTP, Set the native
VLAN to an unused VLAN
a network administrator of a college is configuring the WLAN user authentication process. Wireless users
are required to enter username and password credentials that will be verified by a server. Which server
would provide such service?
SNMP
AAA
RADIUS
, NAT - ANS ✔✔RADIUS
What represents a best practice concerning discovery protocols such as CDP and LLDP on network
devices?
Use the open standard LLDP rather than CDP
Enable CDP on edge devices and enable LLDP on interior devices
Use the default router setting for CDP and LLDP
Disable both protocols on all interfaces where they are not required - ANS ✔✔Disable both protocols on
all interfaces where they are not required
What is an advantage of SSID cloaking?
It is the best way to secure a wireless network
It provides free internet access in public locations where knowing the SSID is of no concern
SSIDs are very difficult to discover because APs do not broadcast them
Clients will have to manually identify the SSID to connect to the network - ANS ✔✔Clients will have to
manually identify the SSID to connect to the network
Match each functional component of AAA with its description
1. Authentication
2. Accounting
3. Authorization
A. Determines what resources users can access or the operations they are allowed to perform
B. Proves that users are who they say they are
C. Records what users do and what they access - ANS ✔✔1=B, 2=C, 3=A
What is the function provided by CAPWAP protocol in a corporate wireless network?
CAPWAP provides the encapsulation and forwarding of wireless user traffic between an access point and
a wireless LAN controller
CAPWAP provides the encryption of wireless user traffic between an access point and a wireless client
CAPWAP provides connectivity between an access point using IPv6 addressing and a wireless client using
IPv4 addressing
CAPWAP creates a tunnel on TCP ports in order to allow a WLC to configure an autonomous access point
- ANS ✔✔CAPWAP provides the encapsulation and forwarding of wireless user traffic between an access
point and a wireless LAN controller
As part of the new security policy, all switches on the network are configured to automatically learn MAC
addresses for each port. All running configurations are saved at the start and close of every business day.
A severe thunderstorm causes an extended power outage several hours after the close of business.
When the switches are brought back online, the dynamically learned MAC addresses are retained. Which
port security configuration enabled this?
Sticky secure MAC addresses
Static secure MAC addresses