CAS-004 Security Engineering Practice Question
A security administrator is configuring a wireless network for a small office. The requirement is to use the strongest available encryption and authentication method that is supported by modern devices and does not require a separate authentication server. Which of the following should the administrator choose?
⚠ Common exam trap
The trap here is assuming that WPA2-Enterprise is always stronger than Personal modes, but it requires an authentication server, which the scenario explicitly rules out.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA3-Personal with SAE
WPA3-Personal with SAE is the most secure method for a pre-shared key network. It provides forward secrecy and resists offline dictionary attacks, which are weaknesses in WPA2-Personal. It does not require a RADIUS server, satisfying the constraint. WPA2-Enterprise requires a server, WEP is obsolete, and WPA2-Personal is weaker than WPA3-Personal. Therefore, WPA3-Personal is the correct choice.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2-Enterprise with PEAP-MSCHAPv2
Why it's wrong here
WPA2-Enterprise with PEAP-MSCHAPv2 provides per-user authentication via a RADIUS server, which is not available in this scenario because the requirement explicitly states no separate authentication server. Additionally, PEAP-MSCHAPv2 is considered weaker due to vulnerabilities that allow credential relay. While Enterprise mode offers better user management, it fails the constraint of not requiring a separate server.
- ✗
WEP with 128-bit key
Why it's wrong here
WEP is an obsolete and insecure protocol that can be cracked in minutes regardless of key length. It should never be used in any new deployment. While it does not require a separate authentication server, it fails the requirement of being the strongest or even adequately secure. Modern devices may not even support WEP, making it a poor choice for a small office network.
- ✓
WPA3-Personal with SAE
Why this is correct
WPA3-Personal with SAE (Simultaneous Authentication of Equals) is the strongest available method for a pre-shared key network. SAE replaces the WPA2 four-way handshake with a Dragonfly handshake that provides forward secrecy and protects against offline dictionary attacks. It does not require an authentication server and is supported by modern devices. This meets all requirements: strongest encryption/authentication and no separate server.
- ✗
WPA2-Personal with AES-CCMP
Why it's wrong here
WPA2-Personal with AES-CCMP is a solid choice and widely supported, but it is not the strongest available method. WPA3-Personal improves upon WPA2 by using SAE (Simultaneous Authentication of Equals) to provide forward secrecy and resistance to offline dictionary attacks. Since the requirement is to use the strongest available method without a separate authentication server, WPA3-Personal is superior to WPA2-Personal.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.