Courseiva
hardMultiple ChoiceObjective-mapped

220-1202 Practice Question: A network administrator is configuring a new…

A network administrator is configuring a new wireless network for a hospital that requires the highest level of security for patient data. The network must support 802.1X authentication with smart cards. Which combination of security protocols and authentication methods should be used?

⚠ Common exam trap

Candidates often assume WPA3 is always more secure than WPA2, but for enterprise 802.1X with smart cards, WPA2-Enterprise with EAP-TLS is the correct and fully supported combination, while WPA3-Enterprise with EAP-TTLS does not enforce client certificate authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

WPA2-Enterprise with EAP-TLS.

WPA2-Enterprise with EAP-TLS provides the highest level of security for a hospital network requiring 802.1X authentication with smart cards. EAP-TLS uses mutual authentication via digital certificates (which can be stored on smart cards), eliminating the risk of credential theft or man-in-the-middle attacks. WPA2-Enterprise is the appropriate underlying encryption framework for this scenario, as it supports the required 802.1X/EAP integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WPA2-PSK with PEAP-MSCHAPv2.

    Why it's wrong here

    WPA2-PSK (Pre-Shared Key) is designed for home or small office environments where a single passphrase authenticates all devices, making it fundamentally incompatible with the 802.1X framework required for enterprise-grade, centralized authentication. Furthermore, PEAP-MSCHAPv2 relies on username and password credentials for authentication, which does not support or utilize smart card technology for client identity verification. This combination fails to meet the requirements for a secure enterprise network leveraging smart cards.

  • WPA3-Personal with SAE.

    Why it's wrong here

    WPA3-Personal, utilizing Simultaneous Authentication of Equals (SAE), is specifically engineered for individual users or small office/home office (SOHO) networks, providing enhanced security over WPA2-PSK. However, it operates on a pre-shared key model and fundamentally lacks support for the 802.1X authentication framework, which is essential for enterprise networks requiring centralized authentication and smart card integration. Therefore, it cannot accommodate smart card-based authentication.

  • WPA2-Enterprise with EAP-TLS.

    Why this is correct

    WPA2-Enterprise is the appropriate security mode for corporate environments because it leverages the 802.1X framework for robust, centralized authentication against a RADIUS server. EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) is a highly secure EAP method that performs mutual authentication using digital certificates on both the client and the server. This certificate-based authentication is inherently compatible with smart cards, as smart cards securely store the client's private key and certificate, making this the ideal solution for the specified requirements.

  • WPA3-Enterprise with EAP-TTLS.

    Why it's wrong here

    While WPA3-Enterprise offers the strongest available encryption and security features for enterprise networks, EAP-TTLS (Tunneled Transport Layer Security) typically encapsulates less secure authentication protocols like MSCHAPv2 within a TLS tunnel. Although EAP-TTLS can support certificate-based authentication, its primary and most common implementation relies on username/password credentials, which does not directly leverage or require smart card technology for client authentication, making it a less suitable choice compared to EAP-TLS for smart card integration.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.