How to Log In to an AP Without Changing Global Login Policy?
An engineer can log in to a WLC but cannot log in to the AP. Which configuration change allows the engineer to log in to the AP without changing the global login policy?
Community Votes
50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests per-AP credential override versus global AP login policy; the trap is confusing AAA override, which is a WLAN client feature, with AP administrative credential override.
This question tests how to log in to a specific Cisco access point without changing the global AP login policy. The correct answer is to override the credentials on that individual AP, which scopes the change to one device.
Choosing B (AAA override) because the word 'override' appears in both options; AAA override applies to WLAN client AAA attributes, not to AP CLI login credentials.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In Cisco AireOS WLC, AP CLI login credentials can be defined globally and then overridden per access point. Selecting "Override the credentials" on a single AP lets you assign a unique AP username and password for that AP only, which is exactly what the engineer needs: AP login works without touching the global login policy. The global policy remains intact for every other AP. This option also avoids any dependency on RADIUS or AAA for AP administrative access. Community member Le91 captured the distinction: "AAA override is WLAN specific and not related to the AP". Therefore C is the correct configuration change.Why the Other Options Are Wrong
A. Changing the WLC password only changes the credentials for logging in to the controller, not the AP; the engineer already can log in to the WLC, so this does nothing for AP access. B. AAA override is a client-facing WLAN feature used to push per-user VLAN, QoS, or ACL attributes after 802.1X or MAC authentication; it does not grant administrative login to an AP. D. Reloading the WLC is disruptive and does not alter credential configuration, so it cannot solve the AP login problem. None of these scope a credential change to a single AP.Community Comment Notes
Learners were split: the source key suggested B, and some posts, such as rrahim's second answer, argued that AAA override could override the global login policy. Others disagreed; Le91 pointed out "AAA override is WLAN specific and not related to the AP". The same commenter posting support for both B and C shows the confusion. The more accurate reading of Cisco WLC behavior is that per-AP credential override is the only option that changes AP login without changing the global policy. The vote split (B: 50, C: 50) is not evidence that B is correct.Exam Strategy
When a question contrasts global policy with per-device exceptions, look for the option that scopes the change to a single object. On AireOS WLC, AP CLI credentials are configured per AP under that AP's settings, so 'Override the credentials' is the targeted answer. Eliminate options that change controller-wide settings or invoke unrelated AAA client features.
Frequently Asked Questions
Why is AAA override wrong for AP login on a Cisco WLC?
AAA override applies to WLAN client authentication attributes such as VLAN, QoS, or ACL after 802.1X and does not control administrative CLI access to an access point.
Where do I configure per-AP credential override on a Cisco WLC?
In the WLC GUI, open the specific AP's configuration page, enable the credential override option, then set the AP username and password for that AP only.