Configuring a WLAN for WPA2 PSK with MAC-Filter Restrictions

Configure and verify WLAN within the GUI using WPA2 PSK Interpret the wireless LAN GUI configuration for client connectivity, such as WLAN creation, security settings, QoS profiles, and advanced settings
Answer Correct answer: C, D — Enable the WPA2 Policy (C) to use PSK authentication and enable MAC Filtering (D) to permit only specific client MAC addresses onto the WLAN.

Refer to the exhibit. A network engineer is configuring a WLAN to use a WPA2 PSK and allow only specific clients to join. Which two actions must be taken to complete the process? (Choose two.) - image

  1. Enable the OSEN Policy option.
  2. Enable the 802.1X option for Authentication Key Management.
  3. Enable the WPA2 Policy option. Correct Answer
  4. Enable the MAC Filtering option. Correct Answer
  5. Enable the CCKM option for Authentication Key Management.

Community Votes

CD
80%
BC
20%

80% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

PSK and 802.1X are the two mutually exclusive WLAN authentication modes — choosing PSK rules out 802.1X/CCKM, leaving WPA2 Policy plus MAC Filtering as the required pair.

To build a WLAN that authenticates users with a pre-shared key, the WLAN must use the WPA2 security policy with PSK. To restrict joining to specific clients, MAC Filtering maintains an allowlist of permitted MAC addresses; all others are rejected. 802.1X and CCKM are certificate/EAP-based and incompatible with PSK.

Picking 802.1X (B) or CCKM (E): those are enterprise/EAP auth, not PSK. The question explicitly says WPA2 PSK, so only the WPA2 Policy and MAC Filtering apply.

Community Discussion (5 comments)

JSMM 👍 1 Selected: CD
MAC Filtering lets you manage an allowlist of MAC addresses that can access the LAN. All others are blocked.
exiledwl 👍 2
Given answer is correct Can't be B as there are 2 main authentication modes, PSK and 802.1x, questions is asking for PSK, check jeremys it lab day 57 @24:30
sy0_061 👍 3 Selected: CD
When we select PSK, we give the users a password they can enter to authenticate. This password is Pre Shared Key (PSK). So we can't choose an 802.1x since that uses a cert authentication instead of password. Mac filtering will allow us to choose who can join and who can't. Choosing the WPA2 policy is straight forward.
[Removed] 👍 1 Selected: BC
Answer C is straightforward. Answer B is correct because, while 802.1X is an IEEE standard, CCKM is a proprietary Cisco technology which requires specific, compatible hardware.
MinSun600 👍 1
correct answer is BC

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

C (WPA2 Policy) is required so the WLAN uses PSK authentication, and D (MAC Filtering) creates an allowlist that permits only specific client MAC addresses to join. Together they satisfy "WPA2 PSK" and "allow only specific clients."

Why the Other Options Are Wrong

A (OSEN) is for Hotspot 2.0, not PSK. B (802.1X) and E (CCKM) are certificate/EAP-based authentication, which conflict with the PSK requirement stated in the question. With PSK selected, 802.1X is explicitly ruled out.

Community Comment Notes

The leading vote is CD (80) versus BC (20). Top commenters explain that PSK uses a password, not a certificate, so 802.1X cannot be chosen, and that MAC Filtering is what restricts which clients may join.

Official Reference

Related Analysis

Practice All 200-301 Questions

Access 220 questions with complete answers and detailed explanations.

View Full 200-301 Practice Test →

← Back to 200-301 Study Guide