Courseiva
Security Engineering →easyMultiple Choice

CAS-004 Security Engineering Practice Question

A security administrator is reviewing the configuration of a wireless network. The network uses WPA3-Enterprise with 802.1X authentication. The administrator wants to ensure that the authentication server validates the identity of the supplicant before granting network access. Which protocol should be used to encapsulate the authentication credentials?

⚠ Common exam trap

It's easy for candidates to confuse tunneled EAP methods like PEAP with true mutual certificate-based authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EAP-TLS

EAP-TLS requires certificates on both the supplicant and the authentication server, enabling mutual authentication. This ensures the server validates the supplicant's identity before granting access. PEAP and EAP-TTLS typically authenticate only the server with a certificate, while EAP-MD5 lacks mutual authentication entirely. Thus, EAP-TLS is the correct choice for strong mutual identity validation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    EAP-MD5

    Why it's wrong here

    EAP-MD5 provides only one-way authentication of the client to the server using a password hash. It does not support mutual authentication, and the server does not validate the client's identity beyond the password. It is considered insecure and is not recommended for WPA3-Enterprise. This option fails to meet the requirement for mutual authentication.

  • ✗

    EAP-TTLS

    Why it's wrong here

    EAP-TTLS also creates a TLS tunnel and allows legacy authentication methods inside. Like PEAP, the server usually authenticates with a certificate, but the client may use a password. While it can support client certificates, it is not inherently mutual certificate-based. The requirement for the server to validate the supplicant's identity is best met by EAP-TLS, which mandates certificates on both sides.

  • ✓

    EAP-TLS

    Why this is correct

    EAP-TLS uses mutual certificate-based authentication, where both the supplicant and the authentication server present certificates. This ensures the server validates the supplicant's identity and vice versa, meeting the requirement. It is widely supported in WPA3-Enterprise and provides strong security without passwords, making it ideal for environments requiring robust mutual authentication.

  • ✗

    PEAP

    Why it's wrong here

    PEAP establishes a TLS tunnel but typically only the server authenticates with a certificate; the client authenticates with a password or token inside the tunnel. The server does not validate the client via certificate unless additional inner methods like EAP-TLS are used. PEAP alone does not provide mutual certificate-based authentication, so it does not fully meet the requirement.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.