nerdexam
Cisco

300-365 · Question #68

Which feature should an engineer select to implement the use of VLAN tagging, QoS, and ACLs to clients based on RADIUS attributes?

The correct answer is C. AAA override. AAA override on a Cisco WLC WLAN allows a RADIUS server to dynamically assign per-client VLAN, QoS, and ACL policies by returning the corresponding attributes in the Access-Accept message.

WLAN Security Deployment

Question

Which feature should an engineer select to implement the use of VLAN tagging, QoS, and ACLs to clients based on RADIUS attributes?

Options

  • Aper-WLAN RADIUS source support
  • Bclient profiling
  • CAAA override
  • Dcaptive bypassing
  • Eidentity-based networking

How the community answered

(30 responses)
  • B
    3% (1)
  • C
    93% (28)
  • E
    3% (1)

Why each option

AAA override on a Cisco WLC WLAN allows a RADIUS server to dynamically assign per-client VLAN, QoS, and ACL policies by returning the corresponding attributes in the Access-Accept message.

Aper-WLAN RADIUS source support

Per-WLAN RADIUS source support specifies which RADIUS server interface is used for a given WLAN and does not enable dynamic attribute-based policy assignment.

Bclient profiling

Client profiling classifies endpoints by device type or OS using DHCP and HTTP fingerprinting but does not apply VLAN, QoS, or ACL policies from RADIUS attributes.

CAAA overrideCorrect

AAA override, when enabled on a WLC WLAN, instructs the controller to accept and apply RADIUS-returned attributes such as Tunnel-Private-Group-ID (VLAN), QoS-Level, and ACL-Name on a per-client basis. This overrides the static WLAN-level configuration, enabling identity-aware network segmentation and policy enforcement without requiring separate SSIDs. It is the specific WLC feature that enables RADIUS attribute-driven dynamic policy assignment.

Dcaptive bypassing

Captive bypassing allows specific clients to skip the captive portal entirely and is unrelated to RADIUS attribute-based policy assignment.

Eidentity-based networking

Identity-based networking is a broader architectural concept; the specific WLC configuration option that applies RADIUS attributes to override WLAN defaults is called AAA override.

Concept tested: Cisco WLC AAA override for RADIUS attribute-based policy

Source: https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-10/config-guide/b_cg810/b_cg810_chapter_010111.html

Topics

#AAA override#RADIUS attributes#VLAN assignment#identity-based networking

Community Discussion

No community discussion yet for this question.

Full 300-365 Practice