nerdexam
Cisco

200-301 · Question #1569

Refer to the exhibit. An engineer is using the Cisco WLC GUI to configure a WLAN for WPA2 encryption with AES and preshared key Cisc0123456. After the engineer selects the WPA + WPA2 option from the L

The correct answer is C. Select PSK from the Auth Key Mgmt drop-down list, set the PSK Format to ASCII, and enter the D. Select the WPA2 Policy and AES check boxes.. To configure WPA2 encryption with AES and a preshared key, the engineer must select the WPA2 Policy and AES checkboxes, and configure PSK from the Auth Key Mgmt dropdown with the correct format and key.

Submitted by tarun92· Mar 5, 2026Network Access

Question

Refer to the exhibit. An engineer is using the Cisco WLC GUI to configure a WLAN for WPA2 encryption with AES and preshared key Cisc0123456. After the engineer selects the WPA + WPA2 option from the Layer 2 Security drop-down list, which two tasks must they perform to complete the process? (Choose two.)

Exhibits

200-301 question #1569 exhibit 1
200-301 question #1569 exhibit 2

Options

  • ASelect the WPA2 Policy, AES, and TKIP check boxes.
  • BSelect ASCII from the PSK Format drop-down list, enter the key, and leave the Auth Key Mgmt
  • CSelect PSK from the Auth Key Mgmt drop-down list, set the PSK Format to ASCII, and enter the
  • DSelect the WPA2 Policy and AES check boxes.
  • ESelect CCKM from the Auth Key Mgmt drop-down list, set the PSK Format to Hex, and enter the

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    10% (4)
  • C
    83% (33)
  • E
    5% (2)

Why each option

To configure WPA2 encryption with AES and a preshared key, the engineer must select the WPA2 Policy and AES checkboxes, and configure PSK from the Auth Key Mgmt dropdown with the correct format and key.

ASelect the WPA2 Policy, AES, and TKIP check boxes.

Selecting TKIP is incorrect because the requirement explicitly specifies AES encryption, and TKIP is an older, less secure encryption method not recommended for WPA2.

BSelect ASCII from the PSK Format drop-down list, enter the key, and leave the Auth Key Mgmt

This option is incomplete; it correctly mentions setting the PSK format and entering the key but omits the critical step of explicitly selecting 'PSK' for Auth Key Management.

CSelect PSK from the Auth Key Mgmt drop-down list, set the PSK Format to ASCII, and enter theCorrect

To utilize a preshared key, 'PSK' must be chosen from the Auth Key Mgmt drop-down list, and then the PSK Format (ASCII for 'Cisc0123456') and the actual key must be entered.

DSelect the WPA2 Policy and AES check boxes.Correct

To enforce WPA2 encryption with AES, the 'WPA2 Policy' checkbox must be selected from the available options, and subsequently, the 'AES' checkbox within that policy must also be enabled.

ESelect CCKM from the Auth Key Mgmt drop-down list, set the PSK Format to Hex, and enter the

CCKM (Cisco Centralized Key Management) is a fast roaming mechanism, not an Auth Key Management method for PSK, and the PSK format for 'Cisc0123456' should be ASCII, not Hex.

Concept tested: Cisco WLC WPA2-PSK with AES configuration

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/wlan_security_wpa_wpa2.html

Topics

#WPA2#WLC GUI#PSK configuration#wireless security

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice