Question 348 of 1,389
CCNA Network Services and Security Practice Question
Which wireless security method is considered strongest among these choices for modern enterprise WLAN deployments?
⚠ Common exam trap
A frequent exam trap is selecting WPA instead of WPA2 with AES because WPA sounds like a newer or stronger protocol than WEP. However, WPA uses TKIP, which is less secure and considered legacy. Another trap is underestimating the insecurity of open authentication, which provides no encryption and leaves WLAN traffic exposed. Candidates might also mistakenly think WEP is acceptable due to its historical use, but it is deprecated and easily cracked. The key mistake is not recognizing that WPA2 with AES is the current minimum security standard for enterprise wireless networks, making it the strongest choice among the options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2 with AES
WPA2 with AES provides substantially stronger security than WEP, legacy WPA, or open authentication. In current enterprise environments, WPA2 and WPA3 are the expected baseline approaches depending on platform support.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WEP
Why it's wrong here
WEP uses the RC4 stream cipher with a short, static key and a 24-bit initialization vector (IV), which leads to predictable keystream reuse when IVs eventually repeat. By capturing enough packets, an attacker can recover the key within minutes using readily available tools, so WEP provides only a false sense of security. Because it is fundamentally broken and deprecated, it offers far weaker protection than WPA2 with AES.
When this WOULD be correct
If the exam question asked for the wireless security method that was historically used in early WLANs or in legacy systems, WEP could be considered correct. For example, a question might specify 'Which wireless security method was commonly used before WPA and is still found in some older devices?'
- ✗
WPA
Why it's wrong here
WPA was created as a temporary fix for WEP and uses TKIP, which retains the RC4 cipher but adds per-packet key mixing, a 48-bit IV sequence, and a Michael message integrity code. However, TKIP and Michael have known vulnerabilities that allow an attacker to recover the keystream or forge packets, especially with QoS enabled, and the reliance on RC4 remains a fundamental weakness. Thus WPA is only marginally better than WEP and is far less secure than the AES-CCMP used in WPA2.
When this WOULD be correct
In a scenario where the exam question asks for the best security method for a legacy system that only supports WPA, or if the question specifies a context where backward compatibility is prioritized over security, then WPA could be considered the correct answer.
- ✓
WPA2 with AES
Why this is correct
WPA2 with AES is the strongest option because it employs AES-CCMP, a 128-bit block cipher operating in counter mode with CBC-MAC for integrity, which together provide robust confidentiality, data-origin authentication, and replay protection. The per-frame key derivation and the cryptanalytic resistance of AES make brute-force or keystream-reuse attacks infeasible, making it the only listed option that meets modern wireless security standards.
- ✗
Open authentication
Why it's wrong here
Open authentication offers no security at all: any client can associate without proving identity, and all data is transmitted in plaintext. There is no encryption, integrity check, or access control on the wireless medium, so an attacker can trivially capture, modify, or inject frames. This is effectively a denial of any confidentiality, making it the weakest possible choice for protecting a WLAN.
When this WOULD be correct
If the exam question asked for the simplest method of connecting devices in a controlled environment where security is not a concern, such as a guest network for temporary access, then open authentication could be considered correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.
✓WPA2 with AESCorrect answer▾
Why this is correct
WPA2 with AES is the strongest option because it employs AES-CCMP, a 128-bit block cipher operating in counter mode with CBC-MAC for integrity, which together provide robust confidentiality, data-origin authentication, and replay protection. The per-frame key derivation and the cryptanalytic resistance of AES make brute-force or keystream-reuse attacks infeasible, making it the only listed option that meets modern wireless security standards.
✗WEPWrong answer — click to see why▾
Why this is wrong here
WEP uses RC4 encryption with static keys and is vulnerable to multiple attacks, including IV reuse and key cracking. It is deprecated and should never be used in any modern deployment.
★ When this WOULD be the correct answer
If the exam question asked for the wireless security method that was historically used in early WLANs or in legacy systems, WEP could be considered correct. For example, a question might specify 'Which wireless security method was commonly used before WPA and is still found in some older devices?'
Why candidates choose this
Students may think WEP is acceptable because it was the original Wi-Fi security standard and is still found in legacy devices, but it provides no real security today.
✗WPAWrong answer — click to see why▾
Why this is wrong here
WPA uses TKIP encryption, which is weaker than AES and has known vulnerabilities. It was designed as a temporary upgrade from WEP and is not recommended for modern networks.
★ When this WOULD be the correct answer
In a scenario where the exam question asks for the best security method for a legacy system that only supports WPA, or if the question specifies a context where backward compatibility is prioritized over security, then WPA could be considered the correct answer.
Why candidates choose this
WPA is often confused with WPA2 because of similar names, and students may assume it is still secure since it is an improvement over WEP.
✗Open authenticationWrong answer — click to see why▾
Why this is wrong here
Open authentication provides no encryption or authentication, leaving all traffic exposed. It is only suitable for public hotspots or guest networks with separate security measures.
★ When this WOULD be the correct answer
If the exam question asked for the simplest method of connecting devices in a controlled environment where security is not a concern, such as a guest network for temporary access, then open authentication could be considered correct.
Why candidates choose this
Students might think 'open' means easy to use or that it is acceptable for some scenarios, but it offers no security and is not considered a wireless security method.
Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: May 17, 2026
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.