CAS-004 Security Engineering Practice Question
A security engineer is configuring a wireless network for a hospital. The network must support legacy medical devices that only support WPA2-Personal with pre-shared keys (PSK) and cannot be upgraded. The hospital also wants to prevent unauthorized devices from connecting and to detect rogue access points. Which of the following should the engineer implement to BEST meet these requirements?
⚠ Common exam trap
The trap here is assuming that the most secure option (WPA3-Enterprise) is always best, but compatibility with legacy devices is a hard constraint that must be respected.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
WPA2-Personal with a strong, unique PSK and a wireless intrusion prevention system (WIPS).
WPA2-Personal with a strong PSK accommodates legacy devices that cannot use 802.1X. A WIPS monitors the airwaves for rogue access points and can detect and mitigate unauthorized devices. This combination meets the requirements without requiring device upgrades, balancing compatibility and security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
WPA2-Enterprise with 802.1X authentication and a RADIUS server.
Why it's wrong here
WPA2-Enterprise with 802.1X requires supplicant support on the devices. Legacy medical devices that only support WPA2-Personal with PSK cannot authenticate via 802.1X. Therefore, this option is not feasible for those devices, even though it offers strong security and rogue AP detection through RADIUS logs.
- ✗
Open network with a captive portal and MAC address filtering.
Why it's wrong here
An open network with a captive portal does not provide encryption, leaving data in transit vulnerable. MAC address filtering is easily bypassed by spoofing. This option fails to meet the requirement for preventing unauthorized devices and does not secure the wireless traffic, making it a poor choice for a hospital.
- ✗
WPA3-Enterprise with 192-bit mode and a RADIUS server.
Why it's wrong here
WPA3-Enterprise is not supported by legacy devices that only support WPA2-Personal. It also requires 802.1X, which these devices lack. While it provides strong security, it is incompatible with the stated constraints, making it an invalid choice for this scenario.
- ✓
WPA2-Personal with a strong, unique PSK and a wireless intrusion prevention system (WIPS).
Why this is correct
WPA2-Personal with a strong PSK accommodates legacy devices that cannot use 802.1X. A WIPS monitors the airwaves for rogue access points and can detect and mitigate unauthorized devices. This combination meets the requirements without requiring device upgrades, balancing compatibility and security.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.