Courseiva
Security Engineering →easyMultiple Choice

CAS-004 Security Engineering Practice Question

A security administrator is configuring a wireless network for a small office. The requirement is to use the strongest available encryption and authentication method that is supported by modern devices and does not require a separate authentication server. Which of the following should the administrator choose?

⚠ Common exam trap

The trap here is assuming that WPA2-Enterprise is always stronger than Personal modes, but it requires an authentication server, which the scenario explicitly rules out.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

WPA3-Personal with SAE

WPA3-Personal with SAE is the most secure method for a pre-shared key network. It provides forward secrecy and resists offline dictionary attacks, which are weaknesses in WPA2-Personal. It does not require a RADIUS server, satisfying the constraint. WPA2-Enterprise requires a server, WEP is obsolete, and WPA2-Personal is weaker than WPA3-Personal. Therefore, WPA3-Personal is the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    WPA2-Enterprise with PEAP-MSCHAPv2

    Why it's wrong here

    WPA2-Enterprise with PEAP-MSCHAPv2 provides per-user authentication via a RADIUS server, which is not available in this scenario because the requirement explicitly states no separate authentication server. Additionally, PEAP-MSCHAPv2 is considered weaker due to vulnerabilities that allow credential relay. While Enterprise mode offers better user management, it fails the constraint of not requiring a separate server.

  • ✗

    WEP with 128-bit key

    Why it's wrong here

    WEP is an obsolete and insecure protocol that can be cracked in minutes regardless of key length. It should never be used in any new deployment. While it does not require a separate authentication server, it fails the requirement of being the strongest or even adequately secure. Modern devices may not even support WEP, making it a poor choice for a small office network.

  • ✓

    WPA3-Personal with SAE

    Why this is correct

    WPA3-Personal with SAE (Simultaneous Authentication of Equals) is the strongest available method for a pre-shared key network. SAE replaces the WPA2 four-way handshake with a Dragonfly handshake that provides forward secrecy and protects against offline dictionary attacks. It does not require an authentication server and is supported by modern devices. This meets all requirements: strongest encryption/authentication and no separate server.

  • ✗

    WPA2-Personal with AES-CCMP

    Why it's wrong here

    WPA2-Personal with AES-CCMP is a solid choice and widely supported, but it is not the strongest available method. WPA3-Personal improves upon WPA2 by using SAE (Simultaneous Authentication of Equals) to provide forward secrecy and resistance to offline dictionary attacks. Since the requirement is to use the strongest available method without a separate authentication server, WPA3-Personal is superior to WPA2-Personal.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.