Cisco CCNA 200-301 Wireless Security and WPA2-PSK Practice Test
Topic 39 focuses on Wireless Security and WPA2-PSK for the Cisco Certified Network Associate (CCNA) certification and the 200-301 exam, using Cisco networking and Cisco IOS concepts where relevant. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
What is an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Incorrect Answers
Answer A is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Answer C is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Answer D is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Question 2
Which Wi-Fi security generation is based on IEEE 802.11i and commonly associated with AES-CCMP?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Incorrect Answers
Answer A is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Answer D is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Question 3
Which newer Wi-Fi security generation improves protections and uses SAE for personal-mode authentication?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Incorrect Answers
Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Answer B is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.
Answer C is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Question 4
Which shared secret is used by all authorized clients in a personal-mode WLAN?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a shared secret used by all authorized clients in a personal-mode WLAN.
Incorrect Answers
Answer A is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Answer B is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Answer C is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Question 5
Which framework is used for per-user or per-device enterprise authentication, often backed by a RADIUS server?
Correct Answer: C
Correct Answer
Answer C is correct because the selected answer describes a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Incorrect Answers
Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer B is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 6
What is the strong encryption and integrity mechanism commonly associated with WPA2?
Correct Answer: A
Correct Answer
Answer A is correct because the selected answer describes the strong encryption and integrity mechanism commonly associated with WPA2.
Incorrect Answers
Answer B is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Answer C is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 7
Which legacy Wi-Fi protection mechanism is associated with WPA and considered weaker than modern AES-based approaches?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Incorrect Answers
Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer B is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Answer C is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Question 8
Which term describes simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal?
Correct Answer: C
Correct Answer
Answer C is correct because Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Incorrect Answers
Answer A is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Answer B is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.
Answer D is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Question 9
Which WPA2 deployment authenticates clients using a pre-shared key rather than an enterprise authentication server?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Incorrect Answers
Answer A is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Answer C is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Answer D is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Question 10
Which WPA2 deployment commonly uses 802.1X and a centralized authentication server for individual credentials?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Incorrect Answers
Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Answer D is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.
Question 11
For WPA, which statement is accurate?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Incorrect Answers
Answer A is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Answer C is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 12
A security review identifies a WLAN using the IEEE 802.11i security generation and AES-CCMP. Which statement correctly characterizes WPA2 in that deployment?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Incorrect Answers
Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer B is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 13
For WPA3, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because it accurately defines WPA3. The matching definition is: A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Incorrect Answers
Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Answer B is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 14
A personal-mode WLAN has one secret configured for all authorized clients. Which statement describes the security credential being shared?
Correct Answer: A
Correct Answer
Answer A is correct because the choice accurately describes Pre-shared key: A shared secret used by all authorized clients in a personal-mode WLAN.
Incorrect Answers
Answer B is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Answer C is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer D is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Question 15
A wireless security design replaces a shared WLAN password with individual authentication backed by a RADIUS server. Which statement explains the role of 802.1X?
Correct Answer: A
Correct Answer
Answer A is correct because the selected answer describes a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Incorrect Answers
Answer B is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Answer C is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Answer D is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.
Question 16
For AES-CCMP, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes the strong encryption and integrity mechanism commonly associated with WPA2.
Incorrect Answers
Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Answer B is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.
Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 17
For TKIP, which statement is accurate?
Correct Answer: B
Correct Answer
Answer B is correct because it accurately defines TKIP. The matching definition is: A legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Incorrect Answers
Answer A is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Answer C is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer D is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.
Question 18
For SAE, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because the choice accurately describes SAE: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Incorrect Answers
Answer B is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Answer C is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Answer D is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Question 19
For WPA2-Personal, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because the selected answer describes a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Incorrect Answers
Answer B is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Answer C is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Answer D is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Question 20
For WPA2-Enterprise, which statement is accurate?
Correct Answer: C
Correct Answer
Answer C is correct because the selected answer describes a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Incorrect Answers
Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Answer B is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 21
During a defensive configuration review, the design calls for the following capability: An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP. Which option names that capability most accurately?
Correct Answer: A
Correct Answer
Answer A is correct because WPA directly provides the function required by the scenario. An older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Incorrect Answers
Answer B is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Answer C is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Answer D is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Question 22
A WLAN upgrade uses the security generation associated with IEEE 802.11i and AES-CCMP rather than legacy WPA with TKIP. Which generation is being deployed?
Correct Answer: C
Correct Answer
Answer C is correct because the operational requirement in the stem maps to WPA2: A Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Incorrect Answers
Answer A is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Answer B is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Answer D is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 23
While working on an access-control investigation, an administrator encounters this requirement: A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication. Which answer is the most precise match?
Correct Answer: C
Correct Answer
Answer C is correct because WPA3 is the most precise fit for the stated requirement. A newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Incorrect Answers
Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Answer B is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Answer D is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Question 24
In a campus security deployment, the team must identify the technology that provides the following function: A shared secret used by all authorized clients in a personal-mode WLAN. Which option should be selected?
Correct Answer: C
Correct Answer
Answer C is correct because the scenario is describing the role of Pre-shared key. A shared secret used by all authorized clients in a personal-mode WLAN.
Incorrect Answers
Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer B is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Answer D is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Question 25
An organization needs wireless access decisions based on individual identities rather than one shared password. Which authentication framework should connect clients, access devices and the authentication server?
Correct Answer: D
Correct Answer
Answer D is correct because 802.1X directly provides the function required by the scenario. A framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Incorrect Answers
Answer A is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.
Answer B is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Answer C is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Question 26
During a defensive configuration review, the design calls for the following capability: The strong encryption and integrity mechanism commonly associated with WPA2. Which option names that capability most accurately?
Correct Answer: B
Correct Answer
Answer B is correct because the operational requirement in the stem maps to AES-CCMP: The strong encryption and integrity mechanism commonly associated with WPA2.
Incorrect Answers
Answer A is incorrect because the “WPA” option describes a different concept: an older Wi-Fi security generation introduced as an improvement over WEP, commonly associated with TKIP.
Answer C is incorrect because the “WPA2” option describes a different concept: a Wi-Fi security generation based on IEEE 802.11i and commonly associated with AES-CCMP.
Answer D is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Question 27
A wireless audit finds an older WPA protection mechanism that should be replaced by a modern AES-based approach. Which listed mechanism is the legacy one?
Correct Answer: C
Correct Answer
Answer C is correct because TKIP is the most precise fit for the stated requirement. A legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Incorrect Answers
Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer B is incorrect because the “SAE” option describes a different concept: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Answer D is incorrect because the “WPA2-Enterprise” option describes a different concept: a WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Question 28
While working on an access-control investigation, an administrator encounters this requirement: Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal. Which answer is the most precise match?
Correct Answer: A
Correct Answer
Answer A is correct because the scenario is describing the role of SAE. Simultaneous Authentication of Equals, the password-authentication method used by WPA3-Personal.
Incorrect Answers
Answer B is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer C is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Answer D is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Question 29
In a campus security deployment, the team must identify the technology that provides the following function: A WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server. Which option should be selected?
Correct Answer: B
Correct Answer
Answer B is correct because WPA2-Personal directly provides the function required by the scenario. A WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Incorrect Answers
Answer A is incorrect because the “AES-CCMP” option describes a different concept: the strong encryption and integrity mechanism commonly associated with WPA2.
Answer C is incorrect because the “Pre-shared key” option describes a different concept: a shared secret used by all authorized clients in a personal-mode WLAN.
Answer D is incorrect because the “TKIP” option describes a different concept: a legacy Wi-Fi protection mechanism associated with WPA and considered weaker than modern AES-based approaches.
Question 30
A WPA2 WLAN uses individual credentials with 802.1X and a central authentication server. Which WPA2 deployment mode is configured?
Correct Answer: A
Correct Answer
Answer A is correct because the operational requirement in the stem maps to WPA2-Enterprise: A WPA2 deployment that commonly uses 802.1X and a centralized authentication server for individual credentials.
Incorrect Answers
Answer B is incorrect because the “802.1X” option describes a different concept: a framework used for per-user or per-device enterprise authentication, often backed by a RADIUS server.
Answer C is incorrect because the “WPA3” option describes a different concept: a newer Wi-Fi security generation that improves protections and uses SAE for personal-mode authentication.
Answer D is incorrect because the “WPA2-Personal” option describes a different concept: a WPA2 deployment that authenticates clients using a pre-shared key rather than an enterprise authentication server.
Popular posts
Recent Posts
