Courseiva

CCNA Network Services and Security Practice Question

Which two statements accurately describe basic WLAN security at the CCNA level?

⚠ Common exam trap

Avoid confusing open networks with secured ones and remember that WEP is outdated and insecure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA2 is generally considered stronger than WEP for wireless security.

Option A is correct because WPA2 uses AES-CCMP encryption, which is cryptographically far stronger than WEP's flawed RC4-based implementation with its weak IVs and easily cracked keys. Option C is correct because an open WLAN transmits frames without any encryption or authentication, so any nearby client can capture and read the traffic, unlike a WLAN protected by WPA2/WPA3. Option B is wrong because open wireless access provides no encryption at all, only association without credentials. Option D is wrong because SSID length is just a network name and has no cryptographic role; WEP's weakness lies in its RC4/IV design, not the SSID. Option E is wrong because WPA2 mandates AES-CCMP, while TKIP is associated with the older WPA (and WPA2's optional TKIP compatibility mode), not WPA2's standard encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    WPA2 is generally considered stronger than WEP for wireless security.

    Why this is correct

    WPA2 uses AES-CCMP with strong key management, whereas WEP's RC4 with static, easily cracked keys offers negligible protection. This satisfies the stem's requirement for an accurate CCNA-level security statement by naming the actual encryption and keying difference between the two standards.

  • ✗

    Open wireless access provides meaningful default encryption.

    Why it's wrong here

    Open authentication performs no key exchange or encryption, so frames travel in cleartext; any confidentiality requires 802.11i (WPA2/WPA3) or a VPN overlay. It is tempting because captive portals and guest Wi-Fi commonly use open mode, but that is for frictionless onboarding, not default encryption.

    When this WOULD be correct

    If the question were to ask about the benefits of open wireless access in a controlled environment, such as a guest network with additional security measures in place, one might argue that it provides a form of encryption through other means, like VPNs used by clients.

  • ✓

    Open wireless access does not provide the same protection as a secured WLAN.

    Why this is correct

    Open wireless access transmits traffic without authentication or encryption, so anyone in range can capture and read it. This satisfies the stem's requirement for an accurate statement by contrasting the absence of any cryptographic protection with the confidentiality a secured WLAN provides.

  • ✗

    A longer SSID makes WEP cryptographically strong.

    Why it's wrong here

    SSID length is a naming field, not key material; WEP's RC4 stream cipher with a 24-bit IV and static keys remains breakable regardless of SSID length. It is tempting because a longer name feels like added entropy, but SSIDs are broadcast in beacons, so they are public, not secret.

    When this WOULD be correct

    If the exam question were to ask about factors that influence the strength of encryption methods, a longer SSID could be considered in a hypothetical context where it is mistakenly believed to add complexity to the encryption process, thus making it seem stronger.

  • ✗

    WPA2 relies on TKIP encryption

    Why it's wrong here

    WPA2 mandates CCMP, which uses AES in counter mode with CBC-MAC; TKIP belongs to WPA (and WPA2's optional mixed mode). TKIP's RC4-based Michael countermeasures were deprecated, so citing it as WPA2's encryption misstates the standard's required cipher suite.

    When this WOULD be correct

    If the exam question asked about the characteristics of network protocols in a mixed environment, including both wired and wireless technologies, and specifically inquired about the relationship between WPA2 and Ethernet protocols, this option could be correct in a context that mistakenly conflates the two.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

✓WPA2 is generally considered stronger than WEP for wireless security.Correct answer▾

Why this is correct

WPA2 uses AES-CCMP with strong key management, whereas WEP's RC4 with static, easily cracked keys offers negligible protection. This satisfies the stem's requirement for an accurate CCNA-level security statement by naming the actual encryption and keying difference between the two standards.

✗Open wireless access provides meaningful default encryption.Wrong answer — click to see why▾

Why this is wrong here

Open wireless access does not provide any encryption by default, making it inherently insecure. Therefore, stating that it offers meaningful default encryption is incorrect.

★ When this WOULD be the correct answer

If the question were to ask about the benefits of open wireless access in a controlled environment, such as a guest network with additional security measures in place, one might argue that it provides a form of encryption through other means, like VPNs used by clients.

Why candidates choose this

Candidates may confuse the term 'open' with the idea that some level of security or encryption is automatically applied, especially if they have encountered scenarios where open networks are secured through additional protocols.

✗A longer SSID makes WEP cryptographically strong.Wrong answer — click to see why▾

Why this is wrong here

This option is wrong because a longer SSID does not enhance the security of WEP; WEP's vulnerabilities are due to its weak encryption algorithm, not the length of the SSID.

★ When this WOULD be the correct answer

If the exam question were to ask about factors that influence the strength of encryption methods, a longer SSID could be considered in a hypothetical context where it is mistakenly believed to add complexity to the encryption process, thus making it seem stronger.

Why candidates choose this

Candidates may be tempted by this option due to a misunderstanding of how SSIDs and encryption work, mistakenly believing that increasing the length of the SSID could somehow enhance security measures.

✗WPA2 relies on TKIP encryptionWrong answer — click to see why▾

Why this is wrong here

WPA2 relies on TKIP encryption is false because WPA2 defaults to AES-CCMP, not TKIP (TKIP is used in WPA).

★ When this WOULD be the correct answer

If the exam question asked about the characteristics of network protocols in a mixed environment, including both wired and wireless technologies, and specifically inquired about the relationship between WPA2 and Ethernet protocols, this option could be correct in a context that mistakenly conflates the two.

Why candidates choose this

Candidates may confuse WPA2 with other networking terms due to a lack of clarity on the differences between wireless security protocols and wired network configurations, leading to the selection of this option.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.