Courseiva
Security Engineering →hardMultiple Choice

CAS-004 Security Engineering Practice Question

A security architect is designing a network segmentation strategy for a critical industrial control system (ICS) environment. The architect must ensure that unauthorized devices cannot communicate with the ICS network even if they gain physical access to a network port. The architect decides to implement IEEE 802.1X with MAC Authentication Bypass (MAB) as a fallback. Which of the following is the MOST significant security weakness introduced by enabling MAB?

⚠ Common exam trap

The trap here is focusing on encryption of credentials, when MAB's real weakness is that the MAC address itself is a trustable but easily forged identifier.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

MAB allows any device to authenticate by spoofing a known MAC address, bypassing 802.1X authentication controls.

MAB authenticates devices by their MAC address, which is not a secret and can be easily spoofed. In an ICS environment where physical port access might be possible, an attacker could clone a permitted MAC address and bypass 802.1X controls. This defeats the goal of preventing unauthorized devices from communicating. Certificate-based methods or strict port security would be more robust, but MAB as a fallback introduces this spoofing vulnerability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MAB transmits credentials in clear text, allowing an attacker to capture them and authenticate to the network.

    Why it's wrong here

    MAB does not transmit credentials; it uses the device's MAC address as the identity, which is sent in clear text but is not a secret credential. The weakness is not credential capture but MAC spoofing. The scenario requires preventing unauthorized devices, and while clear-text MAC addresses are observable, the primary issue is that they can be easily spoofed, not that credentials are exposed.

  • ✗

    MAB disables the use of RADIUS, forcing authentication to occur locally on the switch and reducing centralized control.

    Why it's wrong here

    MAB still relies on RADIUS for authentication; the switch sends the MAC address to the RADIUS server as the username and often a password. It does not disable RADIUS. Centralized control is maintained. This option is factually incorrect because MAB integrates with RADIUS, so it does not represent the weakness introduced by MAB.

  • ✓

    MAB allows any device to authenticate by spoofing a known MAC address, bypassing 802.1X authentication controls.

    Why this is correct

    MAB authenticates devices based on their MAC address, which is easily spoofable. An attacker with physical port access can configure a device with a permitted MAC address and gain network access without valid 802.1X credentials. This directly undermines the requirement that unauthorized devices cannot communicate, making MAB a significant weakness in this scenario.

  • ✗

    MAB requires the use of digital certificates on all endpoints, increasing administrative overhead and complexity.

    Why it's wrong here

    MAB does not require digital certificates; it uses the MAC address as the credential. Certificates are used in EAP-TLS, a different 802.1X method. The scenario mentions MAB as a fallback, so introducing certificates would be a separate design choice. This option mischaracterizes MAB and does not identify the actual security weakness.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.