hardMultiple ChoiceObjective-mapped
220-1102 Practice Question: A network administrator is configuring a new…
A network administrator is configuring a new wireless network for a hospital that requires the highest level of security for patient data. The network must support 802.1X authentication with smart cards. Which combination of security protocols and authentication methods should be used?
⚠ Common exam trap
Candidates often assume WPA3 is always more secure than WPA2, but for enterprise 802.1X with smart cards, WPA2-Enterprise with EAP-TLS is the correct and fully supported combination, while WPA3-Enterprise with EAP-TTLS does not enforce client certificate authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2-Enterprise with EAP-TLS.
WPA2-Enterprise with EAP-TLS provides the highest level of security for a hospital network requiring 802.1X authentication with smart cards. EAP-TLS uses mutual authentication via digital certificates (which can be stored on smart cards), eliminating the risk of credential theft or man-in-the-middle attacks. WPA2-Enterprise is the appropriate underlying encryption framework for this scenario, as it supports the required 802.1X/EAP integration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2-PSK with PEAP-MSCHAPv2.
Why it's wrong here
WPA2-PSK (Pre-Shared Key) is designed for home or small office environments where a single passphrase authenticates all devices, making it fundamentally incompatible with the 802.1X framework required for enterprise-grade, centralized authentication. Furthermore, PEAP-MSCHAPv2 relies on username and password credentials for authentication, which does not support or utilize smart card technology for client identity verification. This combination fails to meet the requirements for a secure enterprise network leveraging smart cards.
- ✗
WPA3-Personal with SAE.
Why it's wrong here
WPA3-Personal, utilizing Simultaneous Authentication of Equals (SAE), is specifically engineered for individual users or small office/home office (SOHO) networks, providing enhanced security over WPA2-PSK. However, it operates on a pre-shared key model and fundamentally lacks support for the 802.1X authentication framework, which is essential for enterprise networks requiring centralized authentication and smart card integration. Therefore, it cannot accommodate smart card-based authentication.
- ✓
WPA2-Enterprise with EAP-TLS.
Why this is correct
WPA2-Enterprise is the appropriate security mode for corporate environments because it leverages the 802.1X framework for robust, centralized authentication against a RADIUS server. EAP-TLS (Extensible Authentication Protocol-Transport Layer Security) is a highly secure EAP method that performs mutual authentication using digital certificates on both the client and the server. This certificate-based authentication is inherently compatible with smart cards, as smart cards securely store the client's private key and certificate, making this the ideal solution for the specified requirements.
- ✗
WPA3-Enterprise with EAP-TTLS.
Why it's wrong here
While WPA3-Enterprise offers the strongest available encryption and security features for enterprise networks, EAP-TTLS (Tunneled Transport Layer Security) typically encapsulates less secure authentication protocols like MSCHAPv2 within a TLS tunnel. Although EAP-TTLS can support certificate-based authentication, its primary and most common implementation relies on username/password credentials, which does not directly leverage or require smart card technology for client authentication, making it a less suitable choice compared to EAP-TLS for smart card integration.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Windows Security Features
Key term
Transport Layer Security
Transport Layer Security (TLS) is a cryptographic protocol that provides secure, encrypted communication between two devices over a network, such as between a web browser and a server.
Key term
Hypertext Transfer Protocol Secure
Hypertext Transfer Protocol Secure, or HTTPS, is the secure version of HTTP that encrypts data between a web browser and a website using SSL/TLS to protect sensitive information like passwords and credit card numbers.
About these practice questions
One of 495 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.