easyMultiple Choice
220-1202 Practice Question: That their smartphone cannot connect to the…
A user reports that their smartphone cannot connect to the office Wi-Fi, but other devices can. The network uses WPA2-Enterprise with PEAP-MSCHAPv2. The technician checks the phone's settings and sees that it is configured for WPA2-PSK. What is the most likely reason for the connection failure?
⚠ Common exam trap
CompTIA often tests the distinction between WPA2-PSK and WPA2-Enterprise, trapping candidates who assume all WPA2 configurations are interchangeable or that the issue is a simple connectivity problem like a hidden SSID or MAC filter.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The phone is using the wrong security protocol.
The phone is configured for WPA2-PSK (Pre-Shared Key), but the office network uses WPA2-Enterprise with PEAP-MSCHAPv2. WPA2-Enterprise requires 802.1X authentication with a RADIUS server, using EAP methods like PEAP-MSCHAPv2, while WPA2-PSK uses a single shared passphrase. The mismatch in security protocols prevents the phone from completing the 4-way handshake, causing the connection failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The phone's Wi-Fi antenna is damaged.
Why it's wrong here
A damaged antenna would prevent the phone associating with any access point, yet the phone is configured for WPA2-PSK while the network requires WPA2-Enterprise with PEAP-MSCHAPv2, so authentication cannot complete. Antenna faults are the correct diagnosis when a device fails to see or associate with any wireless network at all.
- ✓
The phone is using the wrong security protocol.
Why this is correct
WPA2-Enterprise with PEAP-MSCHAPv2 requires 802.1X authentication against a RADIUS server using user credentials and a server certificate. The phone is configured for WPA2-PSK, a preshared-key method, so the authentication exchange fails before association completes, explaining why only this device cannot connect.
- ✗
The router's SSID is hidden.
Why it's wrong here
A hidden SSID still permits association once the profile is configured, and the phone's WPA2-PSK setting against a WPA2-Enterprise network prevents the PEAP-MSCHAPv2 exchange from starting. Hidden SSIDs are the correct diagnosis when a device cannot discover a network but authenticates successfully once the profile is added manually.
- ✗
The phone's MAC address is filtered.
Why it's wrong here
MAC filtering would block the device regardless of its security configuration, but the phone is set to WPA2-PSK against a WPA2-Enterprise network, so the 802.1X authentication exchange never occurs. MAC filtering is the right answer when a device with correct credentials and settings is still refused association.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.