Courseiva
hardMultiple ChoiceObjective-mapped

220-1202 Practice Question: A technician is troubleshooting a wireless…

A technician is troubleshooting a wireless network where users report intermittent connectivity and slow speeds. The network uses WPA2-Enterprise with EAP-TLS and certificate-based authentication. The technician notices that the RADIUS server logs show frequent certificate validation failures. What is the most likely root cause?

⚠ Common exam trap

The 220-1202 exam often tests the distinction between server-side and client-side certificate issues; the trap here is that candidates may assume the RADIUS server's certificate is the problem (Option B) because it is the central authentication point, but the logs specifically show 'validation failures' which in EAP-TLS typically refer to the client certificate failing validation by the server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Client devices have expired or untrusted certificates.

The RADIUS server logs show frequent certificate validation failures, which directly points to an issue with the certificates presented by the clients during EAP-TLS authentication. In WPA2-Enterprise with EAP-TLS, both the server and client must present valid certificates; if client certificates are expired or untrusted, the RADIUS server will reject the authentication, causing intermittent connectivity and slow speeds as clients fail to re-authenticate or roam.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The access point's firmware is outdated, causing packet loss.

    Why it's wrong here

    Outdated access point (AP) firmware causing packet loss would typically manifest as general connectivity problems, slow speeds, or dropped connections affecting many or all connected clients indiscriminately. While firmware can cause various issues, it's unlikely to specifically target and intermittently fail certificate validation for only some client devices while others connect successfully. This scenario points away from a universal AP-level problem.

  • The RADIUS server's certificate has expired.

    Why it's wrong here

    If the RADIUS server's certificate were expired, all client devices attempting 802.1X authentication would consistently fail to establish a trusted connection with the authentication server. The server's identity could not be verified, leading to a complete authentication breakdown for all clients, not just intermittent issues affecting some users. This is a universal failure, not a selective one.

  • Client devices have expired or untrusted certificates.

    Why this is correct

    When client devices possess expired or untrusted certificates, their authentication attempts against the RADIUS server will intermittently fail. Some authentication protocols, like EAP-TLS, rely on client-side certificates for identity verification. If a client's certificate is no longer valid or not trusted by the authentication server, the connection will be rejected, leading to disconnects and subsequent re-attempts, which aligns with intermittent issues for some users.

  • The wireless channel is overlapping with neighboring networks.

    Why it's wrong here

    Wireless channel overlap primarily results in increased interference, reduced signal quality, and slower data transfer rates due to retransmissions. This type of interference impacts the physical and data link layers of the OSI model, affecting general network performance and reliability. It does not directly cause specific authentication failures related to certificate validation, which is a higher-layer security protocol issue.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.