How to Log In to an AP Without Changing Global Login Policy?

Implement device access controls (including RADIUS and TACACS+)
Answer Correct answer: C — Override the credentials on the individual AP so the engineer can log in without changing the global AP login policy.

An engineer can log in to a WLC but cannot log in to the AP. Which configuration change allows the engineer to log in to the AP without changing the global login policy?

  1. Change the WLC password.
  2. Set up AAA override.
  3. Override the credentials. Correct Answer
  4. Reload the WLC.

Community Votes

B
50%
C
50%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests per-AP credential override versus global AP login policy; the trap is confusing AAA override, which is a WLAN client feature, with AP administrative credential override.

This question tests how to log in to a specific Cisco access point without changing the global AP login policy. The correct answer is to override the credentials on that individual AP, which scopes the change to one device.

Choosing B (AAA override) because the word 'override' appears in both options; AAA override applies to WLAN client AAA attributes, not to AP CLI login credentials.

Community Discussion (4 comments)

rrahim 👍 1 Selected: C
C. Override the credentials. To allow the engineer to log in to the AP without changing the global login policy, the override the credentials option must be configured. This allows the engineer to use specific credentials to log in to the AP, bypassing the global login policy temporarily. Explanation of the options: A. Change the WLC password: Changing the WLC password does not affect the ability to log in to the AP. The AP login credentials are separate from the WLC login credentials. B. Set up AAA override: AAA override is used to apply RADIUS server attributes (e.g., VLANs, ACLs) to clients, not for logging in to APs. C. Override the credentials: This is correct. Overriding the credentials allows the engineer to log in to the AP using specific credentials without changing the global login policy. D. Reload the WLC: Reloading the WLC will restart the controller but will not resolve the issue of logging in to the AP.
rrahim 👍 1 Selected: B
B. Set up AAA override. Explanation: AAA Override: This feature allows you to configure specific login credentials for individual APs, overriding the global login policy. This enables the engineer to log in to the AP using the override credentials without affecting the global configuration. Why not the other options? A. Change the WLC password: This would affect the global login policy and is not specific to the AP. C. Override the credentials: This is not a valid configuration option for logging in to the AP. D. Reload the WLC: This would restart the WLC but would not resolve the login issue for the AP.
Le91 👍 1 Selected: C
C is correct answer. AAA override is WLAN specific and not related to the AP
robi1020 👍 1 Selected: B
AAA override (Authentication, Authorization, and Accounting) allows the WLC to override the global login policy for specific devices, such as Access Points. By setting up AAA override, the engineer can use their login credentials to access the AP directly, even if the global login policy might not permit direct access to the AP. This configuration change ensures that the engineer can log in to the AP without impacting the global login policy settings, maintaining security and access control across the network.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Cisco AireOS WLC, AP CLI login credentials can be defined globally and then overridden per access point. Selecting "Override the credentials" on a single AP lets you assign a unique AP username and password for that AP only, which is exactly what the engineer needs: AP login works without touching the global login policy. The global policy remains intact for every other AP. This option also avoids any dependency on RADIUS or AAA for AP administrative access. Community member Le91 captured the distinction: "AAA override is WLAN specific and not related to the AP". Therefore C is the correct configuration change.

Why the Other Options Are Wrong

A. Changing the WLC password only changes the credentials for logging in to the controller, not the AP; the engineer already can log in to the WLC, so this does nothing for AP access. B. AAA override is a client-facing WLAN feature used to push per-user VLAN, QoS, or ACL attributes after 802.1X or MAC authentication; it does not grant administrative login to an AP. D. Reloading the WLC is disruptive and does not alter credential configuration, so it cannot solve the AP login problem. None of these scope a credential change to a single AP.

Community Comment Notes

Learners were split: the source key suggested B, and some posts, such as rrahim's second answer, argued that AAA override could override the global login policy. Others disagreed; Le91 pointed out "AAA override is WLAN specific and not related to the AP". The same commenter posting support for both B and C shows the confusion. The more accurate reading of Cisco WLC behavior is that per-AP credential override is the only option that changes AP login without changing the global policy. The vote split (B: 50, C: 50) is not evidence that B is correct.

Exam Strategy

When a question contrasts global policy with per-device exceptions, look for the option that scopes the change to a single object. On AireOS WLC, AP CLI credentials are configured per AP under that AP's settings, so 'Override the credentials' is the targeted answer. Eliminate options that change controller-wide settings or invoke unrelated AAA client features.

Frequently Asked Questions

Why is AAA override wrong for AP login on a Cisco WLC?

AAA override applies to WLAN client authentication attributes such as VLAN, QoS, or ACL after 802.1X and does not control administrative CLI access to an access point.

Where do I configure per-AP credential override on a Cisco WLC?

In the WLC GUI, open the specific AP's configuration page, enable the credential override option, then set the AP username and password for that AP only.

More 300-430 FAQ →

Related Analysis

← Back to 300-430 Study Guide