Cisco 400-351 CCIE Wireless Written Exam Online Training
Cisco 400-351 Online Training
The questions for 400-351 were last updated at Oct 23,2025.
- Exam Code: 400-351
- Exam Name: CCIE Wireless Written Exam
- Certification Provider: Cisco
- Latest update: Oct 23,2025
FlexConnect APs have already been deployed in a branch office for local switching. Currently the WLAN in the large audition is proposed to change to a high-density design and thus some low data rates are proposed to be disabled while keeping the data rates in other areas under the same Cisco WLC.
Which two configuration settings must be modified in the Cisco WLC to achieve this configuration? (Choose two.)
- A . Fape Profile
- B . FlexConnect Groups
- C . AP Groups
- D . RF Profiles
- E . Mobility Groups
Refer to the exhibit.

What is the best way to resolve this issue?
- A . Use the certificate authority on the Cisco Identity Services Engine.
- B . Install a server certificate signed by a well-known public CA on the WLC.
- C . Install a server certificate signed by a well-known public CA on the RADIUS server.
- D . Disable certificate checks on the client.
Refer to the exhibit.

A network administrator is installing a new converged access Cisco WLC. The uplink connection is to be a Gigabit port channel.
Which characteristic is true?
- A . The port channel is currently down.
- B . The port channel mode is set to active and sends PDUs at 1 sec intervals.
- C . The port channels uses a Cisco proprietary protocol.
- D . The port-channel member interfaces must be set to trunk mode.
- E . The port channel mode is set to active and sends PDUs at 30 sec intervals.
You are the network administrator at ACME Corporation and currently troubleshooting a Central Web Authentication issue where the guest users are not being redirected to the ISE guest login portal. You have verified that all configuration on the ISE is correct and that the ISE is sending the redirect URL for the client.
Which configuration check can help to resolve the issue?
- A . Verify if the SSID is configured for WPA2-AES Layer 2 security.
- B . Verify if authentication priority for web-auth is set to RADIUS.
- C . Verify if AAA override is enabled for the guest SSID.
- D . Verify if SNMO NAC is enabled on the guest SSID.
- E . Verify if RADIUS accounting interim update is enabled on the guest SSID.
- F . Verify if the RFC 3567 support is enabled under ISE configuration on the Cisco WLC.
Refer to the exhibit.

Which statement about the rogue access point screenshot is true?
- A . SSID on this rogue AP is WMM enabled and this rogue AP is contained by single closest detecting access point at a given time.
- B . This rogue AP is contained by AP-1 and AP-2 in round-robin fashion during off-channel scan period.
- C . This rogue AP is working on channel 1 and is manually contained using all detecting access points.
- D . AP-2 sends de-authentication packets on air using BSSID 74:a2:e6:71:51:c3 as part of containment process.
Refer to the exhibit.

You are troubleshooting location accuracy problems on a customer deployment. You have done the wireless design and you are sure that the APs are correctly placed on the Cisco Prime map. Everything is correctly synchronized between WLC, PI, and MSE but you are sometimes getting elements tracked on the wrong floor.
After you get this debug output from MSE, which step is next?
- A . Run a new calibration model and ensure that it is applied on the floor.
- B . Reduce the confidence level on MSE when the last heard value is higher than 150 seconds.
- C . Discard RSSI values lower than -75 dbm.
- D . Check if the AP with MAC address 00:1c:0f:4c:45:60 is physically located on the floor where the element was wrongly located and if the inter-floor attenuation is weal.
Heartbeats are used to maintain the high-availability status of an application.
Which factor is most important?
- A . routing
- B . bandwidth
- C . round-trip time
- D . latency
When configuring an autonomous access point, which configuration broadcasts two SSIIDs?
- A . dot11 ssiddata1vlan 10authentication openauthentication key-management wpa version 1wpa-psk asci cisco123guset-modeend!dot11 ssiddata2vlan 11authentication openauthentication key-management wpa version 2wpa-psk asci Cisco12345guset-modeend
- B . dot11 ssiddata1vlan 10authentication openauthentication key-management wpa version 1wpa-psk asci cisco123mbssid guset-modeend!dot11 ssiddata2vlan 11authentication openauthentication key-management wpa version 2wpa-psk asci Cisco12345mbssid guset-modeend
- C . dot11 ssiddata1vlan 10authentication openauthentication key-management wpa version 1wpa-psk asci cisco123end!dot11 ssiddata2vlan 11authentication openauthentication key-management wpa version 2wpa-psk asci Cisco12345end
- D . dot11 ssiddata1vlan 10authentication openauthentication key-management wpa version 1wpa-psk asci cisco123mbssidend!dot11 ssiddata2vlan 11authentication openauthentication key-management wpa version 2wpa-psk asci Cisco12345mbssidend
- E . mbssid!dot11 ssiddata1vlan 10authentication openauthentication key-management wpa version 1wpapsk asci cisco123end!dot11 ssiddata2vlan 11authentication openauthentication key-management wpa version 2wpa-psk asci Cisco12345guset-modeend
Which object table contains information about the clients know to the server in Cisco NHRP MIB implementation?
- A . NHRP Client Statistics Table
- B . NHRP Server NHC Table
- C . NHRP Cache Table
- D . NHRP Purge Request Table
Which option is a feature of a Cisco Autonomous AP that prevents over-the-air direct P2P communication, which forces all traffic to hit the first-hop router where security policy is enforced?
- A . Publicly Secure Packet Forwarding
- B . Wi-Fi Direct Clients Policy
- C . P2P Blocking Action
- D . P2P Secure Packet