CCNA Network Services and Security Practice Question
Which two statements accurately describe basic WLAN security at the CCNA level?
⚠ Common exam trap
Avoid confusing open networks with secured ones and remember that WEP is outdated and insecure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2 is generally considered stronger than WEP for wireless security.
Option A is correct because WPA2 uses AES-CCMP encryption, which is cryptographically far stronger than WEP's flawed RC4-based implementation with its weak IVs and easily cracked keys. Option C is correct because an open WLAN transmits frames without any encryption or authentication, so any nearby client can capture and read the traffic, unlike a WLAN protected by WPA2/WPA3. Option B is wrong because open wireless access provides no encryption at all, only association without credentials. Option D is wrong because SSID length is just a network name and has no cryptographic role; WEP's weakness lies in its RC4/IV design, not the SSID. Option E is wrong because WPA2 mandates AES-CCMP, while TKIP is associated with the older WPA (and WPA2's optional TKIP compatibility mode), not WPA2's standard encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
WPA2 is generally considered stronger than WEP for wireless security.
Why this is correct
WPA2 uses AES-CCMP with strong key management, whereas WEP's RC4 with static, easily cracked keys offers negligible protection. This satisfies the stem's requirement for an accurate CCNA-level security statement by naming the actual encryption and keying difference between the two standards.
- ✗
Open wireless access provides meaningful default encryption.
Why it's wrong here
Open authentication performs no key exchange or encryption, so frames travel in cleartext; any confidentiality requires 802.11i (WPA2/WPA3) or a VPN overlay. It is tempting because captive portals and guest Wi-Fi commonly use open mode, but that is for frictionless onboarding, not default encryption.
When this WOULD be correct
If the question were to ask about the benefits of open wireless access in a controlled environment, such as a guest network with additional security measures in place, one might argue that it provides a form of encryption through other means, like VPNs used by clients.
- ✓
Open wireless access does not provide the same protection as a secured WLAN.
Why this is correct
Open wireless access transmits traffic without authentication or encryption, so anyone in range can capture and read it. This satisfies the stem's requirement for an accurate statement by contrasting the absence of any cryptographic protection with the confidentiality a secured WLAN provides.
- ✗
A longer SSID makes WEP cryptographically strong.
Why it's wrong here
SSID length is a naming field, not key material; WEP's RC4 stream cipher with a 24-bit IV and static keys remains breakable regardless of SSID length. It is tempting because a longer name feels like added entropy, but SSIDs are broadcast in beacons, so they are public, not secret.
When this WOULD be correct
If the exam question were to ask about factors that influence the strength of encryption methods, a longer SSID could be considered in a hypothetical context where it is mistakenly believed to add complexity to the encryption process, thus making it seem stronger.
- ✗
WPA2 relies on TKIP encryption
Why it's wrong here
WPA2 mandates CCMP, which uses AES in counter mode with CBC-MAC; TKIP belongs to WPA (and WPA2's optional mixed mode). TKIP's RC4-based Michael countermeasures were deprecated, so citing it as WPA2's encryption misstates the standard's required cipher suite.
When this WOULD be correct
If the exam question asked about the characteristics of network protocols in a mixed environment, including both wired and wireless technologies, and specifically inquired about the relationship between WPA2 and Ethernet protocols, this option could be correct in a context that mistakenly conflates the two.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓WPA2 is generally considered stronger than WEP for wireless security.Correct answer▾
Why this is correct
WPA2 uses AES-CCMP with strong key management, whereas WEP's RC4 with static, easily cracked keys offers negligible protection. This satisfies the stem's requirement for an accurate CCNA-level security statement by naming the actual encryption and keying difference between the two standards.
✗Open wireless access provides meaningful default encryption.Wrong answer — click to see why▾
Why this is wrong here
Open wireless access does not provide any encryption by default, making it inherently insecure. Therefore, stating that it offers meaningful default encryption is incorrect.
★ When this WOULD be the correct answer
If the question were to ask about the benefits of open wireless access in a controlled environment, such as a guest network with additional security measures in place, one might argue that it provides a form of encryption through other means, like VPNs used by clients.
Why candidates choose this
Candidates may confuse the term 'open' with the idea that some level of security or encryption is automatically applied, especially if they have encountered scenarios where open networks are secured through additional protocols.
✗A longer SSID makes WEP cryptographically strong.Wrong answer — click to see why▾
Why this is wrong here
This option is wrong because a longer SSID does not enhance the security of WEP; WEP's vulnerabilities are due to its weak encryption algorithm, not the length of the SSID.
★ When this WOULD be the correct answer
If the exam question were to ask about factors that influence the strength of encryption methods, a longer SSID could be considered in a hypothetical context where it is mistakenly believed to add complexity to the encryption process, thus making it seem stronger.
Why candidates choose this
Candidates may be tempted by this option due to a misunderstanding of how SSIDs and encryption work, mistakenly believing that increasing the length of the SSID could somehow enhance security measures.
✗WPA2 relies on TKIP encryptionWrong answer — click to see why▾
Why this is wrong here
WPA2 relies on TKIP encryption is false because WPA2 defaults to AES-CCMP, not TKIP (TKIP is used in WPA).
★ When this WOULD be the correct answer
If the exam question asked about the characteristics of network protocols in a mixed environment, including both wired and wireless technologies, and specifically inquired about the relationship between WPA2 and Ethernet protocols, this option could be correct in a context that mistakenly conflates the two.
Why candidates choose this
Candidates may confuse WPA2 with other networking terms due to a lack of clarity on the differences between wireless security protocols and wired network configurations, leading to the selection of this option.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Switchport Access and Trunk Modes
Key term
Temporal Key Integrity Protocol
TKIP is a security protocol used in Wi-Fi networks to strengthen encryption by dynamically changing the encryption key for each data packet.
Key term
Compatibility mode
Compatibility mode is a software setting that allows a program or operating system designed for an older version of Windows to run on a newer version by mimicking the older environment.
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.