200-301 - Security Fundamentals - Section 5.7

Configure and verify Layer 2 security features (DHCP snooping, dynamic ARP inspection, and port security), describe wireless security protocols (WPA, WPA2, WPA3), and configure a WLAN using WPA2 PSK in the GUI.

Protect the access layer with port security to limit MAC addresses per port, DHCP snooping to drop rogue server replies on untrusted ports, and dynamic ARP inspection to block ARP spoofing using the snooping binding table. Compare the wireless security generations - WPA, WPA2 with AES/CCMP, and WPA3 with SAE - and configure a WLAN with WPA2 pre-shared key authentication from the controller GUI.

Port securityDHCP snoopingDynamic ARP inspectionWPA/WPA2/WPA3WPA2 PSK

Practice question for this objective

Free sampleSecurity Fundamentalsmedium

An administrator is creating a WLAN named CORP-WIFI in the controller GUI for staff laptops. The network has no authentication server, must encrypt traffic with the strongest cipher WPA2 supports, and staff will authenticate with a shared passphrase. Which combination of Layer 2 security settings should be selected in the GUI?

  • ALayer 2 security WPA+WPA2 with the WPA2 policy and TKIP cipher enabled, and the authentication key management set to PSK.
  • BLayer 2 security WPA+WPA2 with the WPA2 policy and AES (CCMP) ciphers enabled, and the authentication key management set to PSK. Correct
  • CLayer 2 security WPA+WPA2 with AES (CCMP) enabled and the authentication key management set to 802.1X.
  • DLayer 2 security None with a WPA2 pre-shared key entered in the advanced web policy fields for the passphrase.
Configure a WPA2 PSK WLAN in the GUI by selecting the WPA2 policy with AES (CCMP) and PSK key management. A WPA2 personal WLAN requires the WPA2 policy with the AES-CCMP cipher, which is the strong mandatory cipher for WPA2, and PSK chosen as the authentication key management so clients authenticate with a shared passphrase rather than via an 802.1X RADIUS server.

Why A is wrong: TKIP is the weaker legacy cipher retained for compatibility, so choosing it does not meet the requirement for the strongest WPA2 encryption.

Why B is correct: WPA2 with AES-CCMP is the strongest WPA2 cipher, and selecting PSK as the key management lets staff authenticate with a shared passphrase without a RADIUS server.

Why C is wrong: The cipher is correct, but 802.1X key management requires a RADIUS authentication server, which the scenario explicitly does not provide.

Why D is wrong: Selecting None disables Layer 2 encryption entirely, and a WPA2 passphrase cannot be applied through a web policy field, so traffic would be unencrypted.

See more 200-301 practice questions, answers explained.

More in this domain

Back to all Security Fundamentals objectives, or the 200-301 cert hub.

Examworthy is not affiliated with or endorsed by Cisco. Original, blueprint-aligned practice material only.