Courseiva
mediumMultiple SelectObjective-mapped

CAS-004 Practice Question: A security architect is designing a secure…

A security architect is designing a secure wireless network for a government facility. Which TWO of the following measures should be implemented to ensure the highest level of security? (Select TWO.)

⚠ Common exam trap

The CAS-004 exam often tests the misconception that disabling SSID broadcast or MAC filtering provides strong security, but the trap here is that these are 'security through obscurity' measures that are easily bypassed, while WPA3-Enterprise with EAP-TLS is the only option that provides cryptographic authentication and encryption suitable for a government facility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable SSID broadcast on the access points

Disabling SSID broadcast (option C) is correct because it prevents the access point from advertising the network name in beacon frames, making the network less visible to casual scanning tools. While not a strong security control on its own (since the SSID is still discoverable via passive monitoring of probe responses and association frames), it adds a layer of obscurity that can deter low-skill attackers and is often required in government environments as part of a defense-in-depth strategy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use WPA2-PSK with a strong pre-shared key

    Why it's wrong here

    WPA2-PSK is vulnerable to brute force and not suitable for government facilities.

  • Implement a captive portal with social login

    Why it's wrong here

    Captive portals are not secure for sensitive environments; social login introduces risk.

  • Disable SSID broadcast on the access points

    Why this is correct

    Disabling SSID broadcast can deter casual discovery, though it is not a primary control.

  • Use WPA3-Enterprise with EAP-TLS for authentication

    Why this is correct

    WPA3-Enterprise with EAP-TLS provides robust encryption and certificate-based authentication.

  • Enable MAC address filtering on the access points

    Why it's wrong here

    MAC addresses can be spoofed; does not provide strong security.

About these practice questions

One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.