CWNA Case Studies & Practical Application 4 — Questions and Answers
Question 1: A network engineer is asked to design a WLAN for a multi-floor office building with 500 employees. The design requires seamless roaming with centralized policy. Which architecture is MOST appropriate?
- Autonomous APs with local switching and independent configuration
- Controller-based (centralized) WLAN architecture with a wireless LAN controller (WLC) (Correct answer)
- Ad-hoc mesh network with peer-to-peer client connections
- Peer-to-peer Wi-Fi Direct connections between workstations
Correct answer: Controller-based (centralized) WLAN architecture with a wireless LAN controller (WLC)
A centralized WLAN controller enables consistent policy enforcement, seamless roaming, and centralized management across all APs in the building.
Question 2: After a WLAN upgrade to 802.11ac, a VoIP application team reports increased jitter on wireless calls. QoS was not reconfigured during the upgrade. What should be implemented?
- Increase AP transmit power to reduce retransmissions
- Implement WMM (Wi-Fi Multimedia) with DSCP-to-UP mapping for voice traffic (Correct answer)
- Disable 5 GHz and run VoIP only on 2.4 GHz
- Switch VoIP to use TCP instead of UDP
Correct answer: Implement WMM (Wi-Fi Multimedia) with DSCP-to-UP mapping for voice traffic
WMM prioritizes voice traffic using the AC_VO access category, and DSCP-to-WMM mapping ensures upstream markings are honored by the AP.
Question 3: A security audit reveals that an employee's laptop is sharing an SSID using Windows hotspot functionality, allowing other employees to bypass NAC controls. What type of device is this classified as?
- Rogue client
- Soft rogue AP (software-based rogue AP) (Correct answer)
- Evil twin AP
- Ad-hoc peer node
Correct answer: Soft rogue AP (software-based rogue AP)
A software-based hotspot running on an employee laptop is classified as a soft rogue AP because it creates an unauthorized access point on the corporate network.
Question 4: A WLAN deployment in a healthcare facility must comply with HIPAA. Patient data traverses the wireless network. Which encryption standard is REQUIRED at a minimum?
- WEP 128-bit to ensure broad device compatibility
- WPA2 with AES-CCMP (or stronger) to protect PHI in transit (Correct answer)
- WPA-TKIP for legacy medical device support
- Open authentication with VPN tunneling as the only acceptable method
Correct answer: WPA2 with AES-CCMP (or stronger) to protect PHI in transit
HIPAA requires strong encryption for PHI in transit; WPA2-AES (CCMP) is the minimum accepted standard for wireless protection of protected health information.
Question 5: A company is troubleshooting poor throughput on a 5 GHz 802.11ac network. A spectrum analyzer shows the channel is clear, but clients report slow speeds. A packet capture reveals many retransmissions. What is the MOST likely cause?
- The SSID broadcast interval is too long
- Clients are at the edge of coverage with marginal SNR, causing high error rates (Correct answer)
- The WLC is configured with too many SSIDs
- The DHCP lease time is too short, causing frequent re-association
Correct answer: Clients are at the edge of coverage with marginal SNR, causing high error rates
Marginal SNR causes high frame error rates and retransmissions even when no external interference is present, indicating insufficient signal strength at client locations.
Question 6: An IT team is deploying WLAN for a K-12 school that must comply with CIPA. Which WLAN feature directly supports CIPA compliance?
- Enabling 802.11r for fast roaming between classrooms
- Segmenting student traffic to a filtered VLAN with content filtering applied (Correct answer)
- Deploying WPA3-SAE on student SSIDs
- Using 6 GHz band exclusively for student devices
Correct answer: Segmenting student traffic to a filtered VLAN with content filtering applied
CIPA requires content filtering for minors; routing student WLAN traffic through a dedicated VLAN with upstream content filtering satisfies this requirement.
Question 7: A site survey for an outdoor campus network uses a 5 GHz band. You notice that some APs on DFS channels intermittently lose connectivity for clients. What is the MOST likely explanation?
- Clients are roaming too aggressively between APs
- Radar detection events are causing the APs to vacate the DFS channels (Correct answer)
- The APs are entering power-save mode during low-traffic periods
- The outdoor APs are overheating and throttling radio power
Correct answer: Radar detection events are causing the APs to vacate the DFS channels
DFS channels require radar avoidance; when a radar signal is detected, the AP must vacate the channel within 10 seconds and wait up to 30 minutes before reusing it.
A network engineer is asked to design a WLAN for a multi-floor office building with 500 employees.
The design requires seamless roaming with centralized policy.
Which architecture is MOST appropriate?