nerdexam
Cisco

200-301 · Question #1414

Refer to the exhibit. A network engineer must configure the WLC to allow only DHCP and DNS packets for User1 and User2. Which configuration must be used?

The correct answer is C. Enable Web policy and Authentication in the Layer 3 Security configuration.. To allow only DHCP and DNS traffic for unauthenticated users (User1 and User2) on a WLC, the engineer should configure Layer 3 Web Policy and Authentication.

Submitted by daniela_cl· Mar 5, 2026Network Access

Question

Refer to the exhibit. A network engineer must configure the WLC to allow only DHCP and DNS packets for User1 and User2. Which configuration must be used?

Exhibits

200-301 question #1414 exhibit 1
200-301 question #1414 exhibit 2

Options

  • AEnable Web Authentication for 802.1X standard in the Layer 2 Security configuration
  • BEnable Fallback Policy with MAC filtering under the Layer 3 Security configuration
  • CEnable Web policy and Authentication in the Layer 3 Security configuration.
  • DEnable Web Authentication under the AAA Server configuration on the WLAN.

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    80% (28)
  • D
    11% (4)

Why each option

To allow only DHCP and DNS traffic for unauthenticated users (User1 and User2) on a WLC, the engineer should configure Layer 3 Web Policy and Authentication.

AEnable Web Authentication for 802.1X standard in the Layer 2 Security configuration

Web Authentication is a Layer 3 process, while 802.1X is Layer 2, and this combination is not the primary mechanism for setting specific pre-authentication traffic policies.

BEnable Fallback Policy with MAC filtering under the Layer 3 Security configuration

Fallback Policy with MAC filtering provides a different security function for client authentication and device identification, but it does not granularly control pre-authentication traffic to permit only DHCP and DNS.

CEnable Web policy and Authentication in the Layer 3 Security configuration.Correct

On a WLC, enabling a Layer 3 Web policy, often associated with a captive portal or web authentication, allows for the configuration of a pre-authentication access control list (ACL). This ACL can be specifically set to permit only essential services like DHCP and DNS packets for unauthenticated users before they complete the web-based authentication process.

DEnable Web Authentication under the AAA Server configuration on the WLAN.

Enabling Web Authentication under the AAA Server configuration is about integrating with the authentication server, not about defining the traffic policy for unauthenticated clients on the WLC itself.

Concept tested: WLC Layer 3 Web Policy (Captive Portal pre-authentication access)

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/b_cg85_chapter_01101.html

Topics

#WLC security policies#WLAN access control#Web authentication

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice