CAS-004 Security Engineering Practice Question
A security administrator is reviewing the configuration of a wireless network. The network uses WPA3-Enterprise with 802.1X authentication. The administrator wants to ensure that the authentication server validates the identity of the supplicant before granting network access. Which protocol should be used to encapsulate the authentication credentials?
⚠ Common exam trap
It's easy for candidates to confuse tunneled EAP methods like PEAP with true mutual certificate-based authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EAP-TLS
EAP-TLS requires certificates on both the supplicant and the authentication server, enabling mutual authentication. This ensures the server validates the supplicant's identity before granting access. PEAP and EAP-TTLS typically authenticate only the server with a certificate, while EAP-MD5 lacks mutual authentication entirely. Thus, EAP-TLS is the correct choice for strong mutual identity validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
EAP-MD5
Why it's wrong here
EAP-MD5 provides only one-way authentication of the client to the server using a password hash. It does not support mutual authentication, and the server does not validate the client's identity beyond the password. It is considered insecure and is not recommended for WPA3-Enterprise. This option fails to meet the requirement for mutual authentication.
- ✗
EAP-TTLS
Why it's wrong here
EAP-TTLS also creates a TLS tunnel and allows legacy authentication methods inside. Like PEAP, the server usually authenticates with a certificate, but the client may use a password. While it can support client certificates, it is not inherently mutual certificate-based. The requirement for the server to validate the supplicant's identity is best met by EAP-TLS, which mandates certificates on both sides.
- ✓
EAP-TLS
Why this is correct
EAP-TLS uses mutual certificate-based authentication, where both the supplicant and the authentication server present certificates. This ensures the server validates the supplicant's identity and vice versa, meeting the requirement. It is widely supported in WPA3-Enterprise and provides strong security without passwords, making it ideal for environments requiring robust mutual authentication.
- ✗
PEAP
Why it's wrong here
PEAP establishes a TLS tunnel but typically only the server authenticates with a certificate; the client authenticates with a password or token inside the tunnel. The server does not validate the client via certificate unless additional inner methods like EAP-TLS are used. PEAP alone does not provide mutual certificate-based authentication, so it does not fully meet the requirement.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.