Courseiva
mediumMultiple ChoiceObjective-mapped

220-1202 Practice Question: A technician is configuring a new wireless…

A technician is configuring a new wireless network for a school. The network must support hundreds of student devices simultaneously and provide strong security. The school wants to use a single SSID with individual logins for students. Which security protocol should the technician choose?

⚠ Common exam trap

CompTIA A+ emphasizes the distinction between 'Enterprise' and 'Personal' modes. The trap here is that candidates see 'WPA2-Enterprise with 802.1X and RADIUS' and assume it is sufficient for high-security individual logins, overlooking that WPA3-Enterprise with 192-bit encryption is the only option that combines individual authentication with the strongest mandated encryption suite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

WPA3-Enterprise with 192-bit encryption.

WPA3-Enterprise with 192-bit encryption is the correct choice because it provides the strongest security for a large-scale deployment with individual logins. It uses 802.1X authentication with a RADIUS server, supporting unique credentials for each student, and mandates 192-bit minimum-strength security suite (CNSA Suite) for encryption, offering enhanced protection against brute-force and dictionary attacks compared to WPA2-Enterprise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • WPA2-PSK with a long passphrase.

    Why it's wrong here

    WPA2-PSK (Pre-Shared Key) relies on a single, shared passphrase for all users to authenticate to the wireless network. While a long passphrase enhances resistance against brute-force attacks, this method inherently lacks individual user accountability and makes key management cumbersome and insecure for larger deployments. It does not provide the per-user authentication and authorization capabilities essential for robust enterprise or educational environments.

  • WPA2-Enterprise with 802.1X and RADIUS.

    Why it's wrong here

    WPA2-Enterprise, leveraging 802.1X and a RADIUS server, provides robust individual user authentication and authorization, addressing the security limitations of shared keys. However, for a new wireless network deployment, WPA3-Enterprise is the superior and recommended choice. WPA3 offers significant cryptographic enhancements, including more resilient key establishment and protection against offline dictionary attacks, making WPA2-Enterprise a less optimal selection for future-proofing and maximum security.

  • WPA3-Enterprise with 192-bit encryption.

    Why this is correct

    WPA3-Enterprise is the most secure and scalable option for a new wireless network requiring individual user authentication and robust data protection. It utilizes 802.1X and a RADIUS server for per-user access control and accountability, preventing unauthorized access and improving auditing. The inclusion of 192-bit encryption, part of the "Suite B" security profile, provides significantly stronger cryptographic protection against modern threats, ensuring the highest level of confidentiality and integrity for sensitive network traffic.

  • WPA3-Personal with SAE.

    Why it's wrong here

    WPA3-Personal, while introducing Simultaneous Authentication of Equals (SAE) for enhanced security over WPA2-Personal, still operates on the principle of a single, shared passphrase for network access. This fundamental design choice means it cannot provide the individual user authentication, authorization, and accountability required for enterprise or educational networks. It is primarily designed for home or small office environments where per-user security policies are not a critical requirement.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.