Cisco WLC AP Authentication for Rogue Containment

Implement access point authentication (including 802.1X) Manage alarms and rogues (APs and clients)
Answer Correct answer: A — AP Authentication must be enabled so rogue containment does not act on RRM neighbor packets from friendly APs across separate RF groups.

A wireless network has two RF groups where Cisco WLCs are joined. APs are associated with different controllers using the round-robin approach. Rogue containment must be deployed in all controllers, but the network must not be affected by any RRM neighbor packets sent by friendly APs. Which AP authentication protection type must be enabled?

  1. AP Authentication Correct Answer
  2. AP Wireless Protection Rules
  3. AP Security
  4. AP Access Control

Community Votes

A
75%
B
25%

75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the specific Cisco WLC feature that stops RRM neighbor packets from friendly APs from triggering rogue containment; the trap is confusing it with generic AP security or a non-existent 'AP Wireless Protection Rules' feature.

In a multi-controller Cisco WLC network with separate RF groups, AP Authentication prevents rogue containment from acting on RRM neighbor packets sent by friendly APs. The correct protection type is AP Authentication (A).

Many candidates choose AP Wireless Protection Rules (B) because it sounds like a granular policy, but Cisco WLC does not offer a feature by that name; AP Authentication is the actual setting under Security > AP Policies.

Community Discussion (4 comments)

rrahim 👍 1 Selected: A
In a wireless network with multiple controllers and APs, AP Authentication is the appropriate protection type to ensure that rogue containment is deployed without being affected by RRM (Radio Resource Management) neighbor packets sent by friendly APs. AP Authentication ensures that only authorized APs are allowed to join the network, preventing rogue APs from connecting. AP Authentication verifies the identity of APs attempting to join the network, ensuring they are legitimate and authorized. This prevents rogue APs from being added to the network and ensures that RRM neighbor packets are only sent by trusted APs. Option B (AP Wireless Protection Rules): This is not a valid option for preventing rogue APs or managing RRM neighbor packets. Option C (AP Security): This is a general term and not a specific feature for this scenario. Option D (AP Access Control): This is not the correct feature for managing rogue containment or RRM neighbor packets. By enabling AP Authentication, the network ensures that only authorized APs are part of the RF groups, and rogue containment can be effectively deployed without interference from unauthorized devices.
80b7716 👍 2 Selected: A
A is correct: below is the reference https://www.cisco.com/c/en/us/td/docs/wireless/controller/8-5/config-guide/b_cg85/radio_resource_management.html
largestyle 👍 1
Where is your source reference (book, URL etc) as I can find nothing relating to Cisco "AP Wireless Protection Rules"
robi1020 👍 1 Selected: B
Option B, AP Wireless Protection Rules, allows for more granular control over the behavior of APs, and it is often used to mitigate potential issues caused by the RRM neighbor packets without affecting the network's performance.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

AP Authentication is the Cisco WLC feature designed to validate access points before they join the controller. When enabled, the controller checks the AP's pre-shared key or certificate. In a deployment with multiple controllers in separate RF groups, an AP associated to one controller may be seen by another controller as a rogue AP. However, if AP Authentication is enabled, the controller recognizes the AP as friendly and does not trigger rogue containment, even if it receives RRM neighbor packets. This matches the requirement that rogue containment be deployed on all controllers without affecting friendly APs, as confirmed by the Cisco 8.5 RRM configuration guide.

Why the Other Options Are Wrong

Option B, "AP Wireless Protection Rules," is not a valid Cisco WLC feature; the WLC has "Wireless Protection Policies" but no such rule set. Option C, "AP Security," is too generic and does not correspond to a specific setting that prevents friendly APs from being contained. Option D, "AP Access Control," refers to access control lists or authorization, not to AP authentication for rogue prevention. None of these options provide the mechanism that distinguishes authenticated APs from rogues.

Community Comment Notes

One commenter, 80b7716, correctly points to the Cisco 8.5 RRM guide as the reference and selects A. Another, rrahim, explains that AP Authentication ensures only authorized APs join the network, preventing rogue APs from connecting. largestyle questions where the term "AP Wireless Protection Rules" comes from, noting no source can be found. robi1020 argues for B as providing "more granular control," but this feature does not exist in Cisco WLC; the correct setting remains AP Authentication.

Official Reference

Exam Strategy

When studying rogue detection and containment, memorize the exact Cisco WLC GUI terms: AP Authentication is under Security > AP Policies, while rogue policies are under Security > Wireless Protection Policies. In multi-controller scenarios, always consider how controllers authenticate APs across RF groups to avoid false containment.

Frequently Asked Questions

Why is AP Wireless Protection Rules not the correct answer?

Cisco WLC does not have a feature called AP Wireless Protection Rules; AP Authentication is the actual setting under Security > AP Policies that prevents friendly APs from being treated as rogues.

How does AP Authentication prevent RRM neighbor packets from triggering containment?

When AP Authentication is enabled, the controller validates APs via pre-shared key or certificate, so it recognizes friendly APs from other RF groups and does not contain them.

More 300-430 FAQ →

Related Analysis

← Back to 300-430 Study Guide