Restricting a WLAN to DHCP and DNS with a Web Policy
Refer to the exhibit. A network engineer must configure the WLC to allow only DHCP and DNS packets for User1 and User2. Which configuration must be used? - 
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Pre-authentication ACLs that permit only DHCP/DNS live under Layer 3 Security > Web Policy on the WLC; that is the only option that maps to traffic restriction before full auth.
To let unauthenticated clients reach only DHCP and DNS, the WLC uses a Layer 3 Security Web Policy together with a pre-authentication ACL. This is configured under the WLAN's Layer 3 Security, not under Layer 2 802.1X or AAA server web auth.
Picking 802.1X (A) or AAA web auth (D): those change the auth method, not the permitted traffic. MAC filtering fallback (B) filters by MAC, not by protocol (DHCP/DNS).
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
C is correct. A WLC Web Policy configured under Layer 3 Security applies a pre-authentication ACL that can permit only DHCP and DNS traffic before a client fully authenticates, which is exactly the stated requirement.Why the Other Options Are Wrong
A (Web Authentication for 802.1X) changes the Layer 2 auth method and does not restrict protocols. B (Fallback Policy with MAC filtering) filters by MAC address, not by DHCP/DNS. D (Web Authentication under AAA Server) is an auth placement, not the DHCP/DNS traffic ACL.Community Comment Notes
The community vote is C (89). One commenter notes none of the options mention ACLs directly, but Layer 3 Web Policy is the configuration that carries the pre-auth ACL controlling DHCP/DNS.Official Reference
Related Analysis
Practice All 200-301 Questions
Access 220 questions with complete answers and detailed explanations.
View Full 200-301 Practice Test →