nerdexam
Cisco

200-301 · Question #895

Refer to the exhibit. The network engineer is configuring a new WLAN and is told to use a setup password for authentication instead of the RADIUS servers. Which additional set of tasks must the engine

The correct answer is D. Select WPA2 Policy Disable PMF Enable PSK. To configure a WLAN for authentication using a shared password instead of RADIUS, the engineer must enable WPA2 policy with Pre-Shared Key (PSK) authentication.

Submitted by yuki_2020· Mar 5, 2026

Question

Refer to the exhibit. The network engineer is configuring a new WLAN and is told to use a setup password for authentication instead of the RADIUS servers. Which additional set of tasks must the engineer perform to complete the configuration?

Exhibits

200-301 question #895 exhibit 1
200-301 question #895 exhibit 2

Options

  • ADisable PMF Enable PSK Enable 802.1x
  • BSelect WPA Policy Enable CCKM Enable PSK
  • CSelect WPA Policy Select WPA2 Policy Enable FT PSK
  • DSelect WPA2 Policy Disable PMF Enable PSK

How the community answered

(40 responses)
  • A
    5% (2)
  • B
    10% (4)
  • C
    3% (1)
  • D
    83% (33)

Why each option

To configure a WLAN for authentication using a shared password instead of RADIUS, the engineer must enable WPA2 policy with Pre-Shared Key (PSK) authentication.

ADisable PMF Enable PSK Enable 802.1x

Enabling 802.1x is incorrect because 802.1x is used for enterprise authentication with RADIUS servers, which the question explicitly states is not being used.

BSelect WPA Policy Enable CCKM Enable PSK

While PSK is correct, selecting only `WPA Policy` (implying WPA1) is less secure than WPA2. CCKM (Cisco Centralized Key Management) is a proprietary fast roaming feature, not the primary authentication mechanism for a 'setup password'.

CSelect WPA Policy Select WPA2 Policy Enable FT PSK

While PSK is correct and WPA2 Policy is appropriate, selecting `WPA Policy` (WPA1) is less secure, and `FT PSK` (Fast Transition PSK) is an advanced fast roaming feature, not the fundamental authentication method.

DSelect WPA2 Policy Disable PMF Enable PSKCorrect

To use a setup password for authentication instead of RADIUS, the Pre-Shared Key (PSK) authentication method must be enabled. WPA2 Policy is the most common and secure choice for PSK authentication in modern WLANs. Protected Management Frames (PMF) is an optional 802.11w feature that enhances security by protecting management frames, and while generally recommended, disabling it is a valid configuration option depending on network requirements or compatibility.

Concept tested: WLAN WPA2-PSK security configuration

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/wlan_security.html

Topics

#WLAN configuration#WPA2-PSK#Wireless authentication#PMF

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice