350-401 · Question #969
350-401 Question #969: Real Exam Question with Answer & Explanation
The correct answer is A: Enable AAA Override.. To allow a RADIUS server like Cisco ISE to dynamically assign a guest VLAN after web authentication, the "AAA Override" feature must be enabled on the WLAN.
Question
A wireless administrator must create a new web authentication corporate SSID that will be using ISE as the external RADIUS server. The guest VLAN must be specified after the authentication completes. Which action must be performed to allow the ISE server to specify the guest VLAN?
Options
- AEnable AAA Override.
- BEnable Network Access Control State.
- CSet AAA Policy name.
- DSet RADIUS Profiling.
Explanation
To allow a RADIUS server like Cisco ISE to dynamically assign a guest VLAN after web authentication, the "AAA Override" feature must be enabled on the WLAN.
Common mistakes.
- B. Enabling "Network Access Control State" relates to posture assessment and enabling/disabling NAC functionality, not the dynamic assignment of VLANs by a RADIUS server.
- C. Setting an "AAA Policy name" defines which AAA server group or policy to use for authentication, but it does not intrinsically enable the WLC to override local VLAN settings based on RADIUS attributes.
- D. "RADIUS Profiling" is a feature of ISE that identifies endpoint types based on collected attributes, used for policy decisions, but it does not directly enable the WLC to accept dynamic VLAN assignments.
Concept tested. Cisco WLC AAA Override for dynamic VLAN
Topics
Community Discussion
No community discussion yet for this question.