CAS-004 Security Engineering Practice Question
A security architect is designing a network segmentation strategy for a critical industrial control system (ICS) environment. The architect must ensure that unauthorized devices cannot communicate with the ICS network even if they gain physical access to a network port. The architect decides to implement IEEE 802.1X with MAC Authentication Bypass (MAB) as a fallback. Which of the following is the MOST significant security weakness introduced by enabling MAB?
⚠ Common exam trap
The trap here is focusing on encryption of credentials, when MAB's real weakness is that the MAC address itself is a trustable but easily forged identifier.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
MAB allows any device to authenticate by spoofing a known MAC address, bypassing 802.1X authentication controls.
MAB authenticates devices by their MAC address, which is not a secret and can be easily spoofed. In an ICS environment where physical port access might be possible, an attacker could clone a permitted MAC address and bypass 802.1X controls. This defeats the goal of preventing unauthorized devices from communicating. Certificate-based methods or strict port security would be more robust, but MAB as a fallback introduces this spoofing vulnerability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAB transmits credentials in clear text, allowing an attacker to capture them and authenticate to the network.
Why it's wrong here
MAB does not transmit credentials; it uses the device's MAC address as the identity, which is sent in clear text but is not a secret credential. The weakness is not credential capture but MAC spoofing. The scenario requires preventing unauthorized devices, and while clear-text MAC addresses are observable, the primary issue is that they can be easily spoofed, not that credentials are exposed.
- ✗
MAB disables the use of RADIUS, forcing authentication to occur locally on the switch and reducing centralized control.
Why it's wrong here
MAB still relies on RADIUS for authentication; the switch sends the MAC address to the RADIUS server as the username and often a password. It does not disable RADIUS. Centralized control is maintained. This option is factually incorrect because MAB integrates with RADIUS, so it does not represent the weakness introduced by MAB.
- ✓
MAB allows any device to authenticate by spoofing a known MAC address, bypassing 802.1X authentication controls.
Why this is correct
MAB authenticates devices based on their MAC address, which is easily spoofable. An attacker with physical port access can configure a device with a permitted MAC address and gain network access without valid 802.1X credentials. This directly undermines the requirement that unauthorized devices cannot communicate, making MAB a significant weakness in this scenario.
- ✗
MAB requires the use of digital certificates on all endpoints, increasing administrative overhead and complexity.
Why it's wrong here
MAB does not require digital certificates; it uses the MAC address as the credential. Certificates are used in EAP-TLS, a different 802.1X method. The scenario mentions MAB as a fallback, so introducing certificates would be a separate design choice. This option mischaracterizes MAB and does not identify the actual security weakness.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.