Cisco CCNA 200-301 Wireless Security and WPA2-PSK Practice Test

Topic 39 focuses on Wireless Security and WPA2-PSK for the Cisco Certified Network Associate (CCNA) certification and the 200-301 exam, using Cisco networking and Cisco IOS concepts where relevant. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

What is an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP?

  1. SAE
  2. WPA
  3. TKIP
  4. WPA3

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Incorrect Answers

Answer A is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Answer C is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

Answer D is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

 

Question 2

Which Wi-Fi security generation is based on IEEE 802.11i and commonly associated with AES-CCMP?

  1. WPA3
  2. WPA2
  3. SAE
  4. WPA2-Personal

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

Incorrect Answers

Answer A is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Answer D is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

 

Question 3

Which newer Wi-Fi security generation improves protections and uses SAE for personal-mode authentication?

  1. WPA
  2. Pre-shared key
  3. 802.1X
  4. WPA3

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Incorrect Answers

Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Answer B is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.

Answer C is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

 

Question 4

Which shared secret is used by all authorized clients in a personal-mode WLAN?

  1. WPA2-Enterprise
  2. 802.1X
  3. WPA2
  4. Pre-shared key

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a shared secret used by all authorized clients in a personal-mode WLAN.

Incorrect Answers

Answer A is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

Answer B is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Answer C is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

 

Question 5

Which framework is used for per-user or per-device enterprise authentication, often backed by a RADIUS server?

  1. AES-CCMP
  2. WPA2-Personal
  3. 802.1X
  4. SAE

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Incorrect Answers

Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer B is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 6

What is the strong encryption and integrity mechanism commonly associated with WPA2?

  1. AES-CCMP
  2. TKIP
  3. WPA2-Enterprise
  4. SAE

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes the strong encryption and integrity mechanism commonly associated with WPA2.

Incorrect Answers

Answer B is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

Answer C is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 7

Which legacy Wi-Fi protection mechanism is associated with WPA and considered weaker than modern AES-based approaches?

  1. AES-CCMP
  2. WPA3
  3. WPA2
  4. TKIP

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

Incorrect Answers

Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer B is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Answer C is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

 

Question 8

Which term describes simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal?

  1. WPA2-Enterprise
  2. Pre-shared key
  3. SAE
  4. TKIP

Correct Answer: C

 

Correct Answer

Answer C is correct because Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Incorrect Answers

Answer A is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

Answer B is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.

Answer D is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

 

Question 9

Which WPA2 deployment authenticates clients using a pre-shared key rather than an enterprise authentication server?

  1. SAE
  2. WPA2-Personal
  3. 802.1X
  4. WPA2-Enterprise

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Incorrect Answers

Answer A is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Answer C is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Answer D is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

 

Question 10

Which WPA2 deployment commonly uses 802.1X and a centralized authentication server for individual credentials?

  1. AES-CCMP
  2. WPA2-Enterprise
  3. SAE
  4. Pre-shared key

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

Incorrect Answers

Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Answer D is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.

 

Question 11

For WPA, which statement is accurate?

  1. A WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
  2. An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
  3. A legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
  4. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Incorrect Answers

Answer A is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Answer C is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 12

A security review identifies a WLAN using the IEEE 802.11i security generation and AES-CCMP. Which statement correctly characterizes WPA2 in that deployment?

  1. The strong encryption and integrity mechanism commonly associated with WPA2.
  2. A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
  3. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
  4. A Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

Incorrect Answers

Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer B is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 13

For WPA3, which statement is accurate?

  1. An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
  2. The strong encryption and integrity mechanism commonly associated with WPA2.
  3. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
  4. A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Correct Answer: D

 

Correct Answer

Answer D is correct because it accurately defines WPA3. The matching definition is: A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Incorrect Answers

Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Answer B is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 14

A personal-mode WLAN has one secret configured for all authorized clients. Which statement describes the security credential being shared?

  1. A shared secret used by all authorized clients in a personal-mode WLAN.
  2. A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
  3. The strong encryption and integrity mechanism commonly associated with WPA2.
  4. A Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

Correct Answer: A

 

Correct Answer

Answer A is correct because the choice accurately describes Pre-shared key: A shared secret used by all authorized clients in a personal-mode WLAN.

Incorrect Answers

Answer B is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Answer C is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer D is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

 

Question 15

A wireless security design replaces a shared WLAN password with individual authentication backed by a RADIUS server. Which statement explains the role of 802.1X?

  1. A framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
  2. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
  3. A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
  4. A shared secret used by all authorized clients in a personal-mode WLAN.

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Incorrect Answers

Answer B is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Answer C is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Answer D is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.

 

Question 16

For AES-CCMP, which statement is accurate?

  1. An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
  2. A shared secret used by all authorized clients in a personal-mode WLAN.
  3. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
  4. The strong encryption and integrity mechanism commonly associated with WPA2.

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes the strong encryption and integrity mechanism commonly associated with WPA2.

Incorrect Answers

Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Answer B is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.

Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 17

For TKIP, which statement is accurate?

  1. A WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
  2. A legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
  3. The strong encryption and integrity mechanism commonly associated with WPA2.
  4. A shared secret used by all authorized clients in a personal-mode WLAN.

Correct Answer: B

 

Correct Answer

Answer B is correct because it accurately defines TKIP. The matching definition is: A legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

Incorrect Answers

Answer A is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Answer C is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer D is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.

 

Question 18

For SAE, which statement is accurate?

  1. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
  2. A WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
  3. An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
  4. A framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Correct Answer: A

 

Correct Answer

Answer A is correct because the choice accurately describes SAE: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Incorrect Answers

Answer B is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Answer C is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Answer D is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

 

Question 19

For WPA2-Personal, which statement is accurate?

  1. A WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
  2. A WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
  3. A framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
  4. The strong encryption and integrity mechanism commonly associated with WPA2.

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Incorrect Answers

Answer B is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

Answer C is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Answer D is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

 

Question 20

For WPA2-Enterprise, which statement is accurate?

  1. An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
  2. The strong encryption and integrity mechanism commonly associated with WPA2.
  3. A WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
  4. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

Incorrect Answers

Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Answer B is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 21

During a defensive configuration review, the design calls for the following capability: An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP. Which option names that capability most accurately?

  1. WPA
  2. WPA2-Personal
  3. WPA2
  4. WPA3

Correct Answer: A

 

Correct Answer

Answer A is correct because WPA directly provides the function required by the scenario. An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Incorrect Answers

Answer B is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Answer C is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

Answer D is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

 

Question 22

A WLAN upgrade uses the security generation associated with IEEE 802.11i and AES-CCMP rather than legacy WPA with TKIP. Which generation is being deployed?

  1. WPA2-Personal
  2. WPA2-Enterprise
  3. WPA2
  4. SAE

Correct Answer: C

 

Correct Answer

Answer C is correct because the operational requirement in the stem maps to WPA2: A Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

Incorrect Answers

Answer A is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Answer B is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 23

While working on an access-control investigation, an administrator encounters this requirement: A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication. Which answer is the most precise match?

  1. WPA
  2. SAE
  3. WPA3
  4. WPA2

Correct Answer: C

 

Correct Answer

Answer C is correct because WPA3 is the most precise fit for the stated requirement. A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Incorrect Answers

Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Answer B is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Answer D is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

 

Question 24

In a campus security deployment, the team must identify the technology that provides the following function: A shared secret used by all authorized clients in a personal-mode WLAN. Which option should be selected?

  1. AES-CCMP
  2. SAE
  3. Pre-shared key
  4. TKIP

Correct Answer: C

 

Correct Answer

Answer C is correct because the scenario is describing the role of Pre-shared key. A shared secret used by all authorized clients in a personal-mode WLAN.

Incorrect Answers

Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer B is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Answer D is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

 

Question 25

An organization needs wireless access decisions based on individual identities rather than one shared password. Which authentication framework should connect clients, access devices and the authentication server?

  1. Pre-shared key
  2. WPA3
  3. SAE
  4. 802.1X

Correct Answer: D

 

Correct Answer

Answer D is correct because 802.1X directly provides the function required by the scenario. A framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Incorrect Answers

Answer A is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.

Answer B is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

 

Question 26

During a defensive configuration review, the design calls for the following capability: The strong encryption and integrity mechanism commonly associated with WPA2. Which option names that capability most accurately?

  1. WPA
  2. AES-CCMP
  3. WPA2
  4. WPA2-Personal

Correct Answer: B

 

Correct Answer

Answer B is correct because the operational requirement in the stem maps to AES-CCMP: The strong encryption and integrity mechanism commonly associated with WPA2.

Incorrect Answers

Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.

Answer C is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.

Answer D is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

 

Question 27

A wireless audit finds an older WPA protection mechanism that should be replaced by a modern AES-based approach. Which listed mechanism is the legacy one?

  1. AES-CCMP
  2. SAE
  3. TKIP
  4. WPA2-Enterprise

Correct Answer: C

 

Correct Answer

Answer C is correct because TKIP is the most precise fit for the stated requirement. A legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

Incorrect Answers

Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer B is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Answer D is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

 

Question 28

While working on an access-control investigation, an administrator encounters this requirement: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal. Which answer is the most precise match?

  1. SAE
  2. AES-CCMP
  3. 802.1X
  4. WPA3

Correct Answer: A

 

Correct Answer

Answer A is correct because the scenario is describing the role of SAE. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.

Incorrect Answers

Answer B is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer C is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Answer D is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

 

Question 29

In a campus security deployment, the team must identify the technology that provides the following function: A WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server. Which option should be selected?

  1. AES-CCMP
  2. WPA2-Personal
  3. Pre-shared key
  4. TKIP

Correct Answer: B

 

Correct Answer

Answer B is correct because WPA2-Personal directly provides the function required by the scenario. A WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

Incorrect Answers

Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.

Answer C is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.

Answer D is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.

 

Question 30

A WPA2 WLAN uses individual credentials with 802.1X and a central authentication server. Which WPA2 deployment mode is configured?

  1. WPA2-Enterprise
  2. 802.1X
  3. WPA3
  4. WPA2-Personal

Correct Answer: A

 

Correct Answer

Answer A is correct because the operational requirement in the stem maps to WPA2-Enterprise: A WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.

Incorrect Answers

Answer B is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.

Answer C is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.

Answer D is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.

img