hardMultiple Choice
220-1102 Practice Question: A technician is troubleshooting a wireless…
A technician is troubleshooting a wireless network where users report intermittent connectivity. The network uses WPA2-Enterprise with a RADIUS server. The technician notices that the RADIUS server logs show frequent authentication failures from one specific access point. What is the most likely cause?
⚠ Common exam trap
CompTIA often tests the distinction between client-side authentication failures (e.g., wrong PSK or certificate) and infrastructure-side authentication failures (e.g., RADIUS shared secret mismatch), and the trap here is that candidates may confuse a RADIUS server certificate issue with a per-AP shared secret problem, not realizing that a certificate expiry would affect all APs uniformly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The access point's RADIUS shared secret is incorrect.
The RADIUS shared secret is a pre-shared key configured on both the access point and the RADIUS server to authenticate the AP itself. If the secret on the specific AP does not match the server's configuration, the server will reject authentication requests from that AP, causing intermittent connectivity for clients associated with it. The logs showing frequent authentication failures from one AP point directly to a mismatch in this shared secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The access point is using a different channel than the others.
Why it's wrong here
Channel differences affect signal interference, not RADIUS authentication.
- ✗
The RADIUS server certificate has expired.
Why it's wrong here
An expired certificate would cause client authentication failures, not access point-to-RADIUS failures.
- ✓
The access point's RADIUS shared secret is incorrect.
Why this is correct
The shared secret is used for authentication between the AP and RADIUS server; a mismatch causes failures.
- ✗
The clients are using WPA2-PSK instead of WPA2-Enterprise.
Why it's wrong here
Client misconfiguration would not cause RADIUS server logs to show failures from the access point.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Troubleshoot: Windows Boot Failures
Key term
PSK
A pre-shared key (PSK) is a secret string of characters shared in advance between two parties to authenticate and encrypt wireless or VPN communications.
Key term
Pre-shared Key
A secret password or passphrase that two devices share beforehand to prove they are allowed to connect and communicate securely.
About these practice questions
One of 687 original 220-1202 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.